Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Advanced Custom Fields MEDIUM 6.5
CVE-2022-23183

Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows…

Fix: 5.12.1+
Fix from $1,600 2022-03-31
Android HIGH 7.8
CVE-2022-20002

In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39768

In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lea…

Mitigation only
Fix from $1,950 2022-03-30
Android MEDIUM 5.5
CVE-2021-39742

In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disc…

Mitigation only
Fix from $1,600 2022-03-30
Android HIGH 7.8
CVE-2021-39743

In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to loc…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39749

In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local …

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39750

In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to loca…

Mitigation only
Fix from $1,950 2022-03-30
Android MEDIUM 5.5
CVE-2021-39751

In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to …

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39753

In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lea…

Mitigation only
Fix from $1,600 2022-03-30
Android HIGH 7.8
CVE-2021-39758

In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to lo…

Mitigation only
Fix from $1,950 2022-03-30
Pipeline\ MEDIUM 6.5
CVE-2022-28158

A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate cr…

Fix: after 1.3
Fix from $1,600 2022-03-29
Bitbucket Server Integration MEDIUM 5.4
CVE-2022-28134

Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with O…

Fix: after 3.1.0
Fix from $1,600 2022-03-29
Proxmox MEDIUM 6.5
CVE-2022-28144

Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permissi…

Fix: after 0.7.0
Fix from $1,600 2022-03-29
Innovation Management HIGH 7.5
CVE-2022-27658

Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering…

Mitigation only
Fix from $1,950 2022-03-28
Osmapper MEDIUM 5.3
CVE-2021-24978

The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_aj…

Fix: after 2.1.5
Fix from $1,600 2022-03-28
3scale HIGH 7.5
CVE-2021-3814

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably b…

Fix: 2.11.0+
Fix from $1,950 2022-03-25
Argo Cd HIGH 8.8
CVE-2022-24768

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an …

Fix: 2.1.14 / 2.2.8+
Fix from $1,950 2022-03-23
Electron MEDIUM 5.0
CVE-2022-21718

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-…

Fix: 13.6.6 / 14.2.4+
Fix from $1,600 2022-03-22
Google Authenticator HIGH 8.1
CVE-2022-0229

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMet…

Fix: 5.5+
Fix from $1,950 2022-03-21
Android HIGH 7.8
CVE-2021-39734

In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check…

Mitigation only
Fix from $1,950 2022-03-16
Android HIGH 7.8
CVE-2021-39706

In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This coul…

Patch available
Fix from $1,950 2022-03-16
Android HIGH 7.8
CVE-2021-39697

In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missi…

Patch available
Fix from $1,950 2022-03-16
Kubernetes Continuous Deploy MEDIUM 6.5
CVE-2022-27209

A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerat…

Fix: after 2.3.1
Fix from $1,600 2022-03-15
Kubernetes Continuous Deploy MEDIUM 6.5
CVE-2022-27211

A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect …

Fix: after 2.3.1
Fix from $1,600 2022-03-15
Insight Core MEDIUM 5.4
CVE-2021-24950

The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to …

No fix yet
Fix from $1,600 2022-03-14
Saleor MEDIUM 6.5
CVE-2022-0932

Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.

Fix: 3.1.2+
Fix from $1,600 2022-03-11
Gogs CRITICAL 9.1
CVE-2022-0871

Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

Fix: 0.12.5+
Fix from $2,300 2022-03-11
Nextcloud Server MEDIUM 5.3
CVE-2021-41233

Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application…

Fix: 20.0.14 / 21.0.6+
Fix from $1,600 2022-03-10
Netweaver Application Server Java MEDIUM 5.3
CVE-2022-26103

Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to …

Mitigation only
Fix from $1,600 2022-03-10
Financial Consolidation MEDIUM 5.3
CVE-2022-26104

SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthor…

Mitigation only
Fix from $1,600 2022-03-10