Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Netweaver Application Server Abap MEDIUM 5.4
CVE-2022-26102

Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to acc…

Mitigation only
Fix from $1,600 2022-03-10
Android HIGH 7.8
CVE-2022-20054

In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no …

Mitigation only
Fix from $1,950 2022-03-10
Android HIGH 7.8
CVE-2022-20053

In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2022-03-10
Android MEDIUM 6.7
CVE-2022-20049

In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e…

Mitigation only
Fix from $1,600 2022-03-10
Gitea HIGH 7.1
CVE-2022-0905

Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.

Fix: 1.16.4+
Fix from $1,950 2022-03-10
Nextcloud Server MEDIUM 5.3
CVE-2021-41239

Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user…

Fix: 20.0.14 / 21.0.6+
Fix from $1,600 2022-03-08
Suitecrm MEDIUM 6.5
CVE-2022-0756

Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

Fix: 7.12.5+
Fix from $1,600 2022-03-07
Download Manager HIGH 7.5
CVE-2021-25087

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticate…

Fix: 3.2.35+
Fix from $1,950 2022-03-07
Smart Forms MEDIUM 6.5
CVE-2022-0163

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authentic…

Fix: 2.6.71+
Fix from $1,600 2022-03-07
Linux Kernel HIGH 8.8
CVE-2021-3656

A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control bl…

Fix: 4.14.245 / 4.19.205+
Fix from $1,950 2022-03-04
Linux Kernel HIGH 7.8
CVE-2022-0492 KEVEPSS 6%

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circum…

Fix: 4.9.301 / 4.14.266+
Fix from $1,950 2022-03-03
Rundeck HIGH 8.1
CVE-2021-41112

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users cou…

Fix: 3.4.5+
Fix from $1,950 2022-02-28
Use Any Font MEDIUM 6.1
CVE-2021-24977

The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthen…

Fix: 6.2.1+
Fix from $1,600 2022-02-28
Wp Google Map MEDIUM 5.7
CVE-2021-25011

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which co…

Fix: 1.8.1+
Fix from $1,600 2022-02-28
Visitor Statistics MEDIUM 5.4
CVE-2021-25042

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX act…

Fix: 5.5+
Fix from $1,600 2022-02-28
Waline MEDIUM 5.3
CVE-2022-24594

In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.

Patch available
Fix from $1,600 2022-02-25
Peertube MEDIUM 5.4
CVE-2022-0726

Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

Fix: 4.1.0+
Fix from $1,600 2022-02-23
Sourcegraph HIGH 8.8
CVE-2022-23642EPSS 74%

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` servi…

Fix: 3.37+
Fix from $1,950 2022-02-18
Redis CRITICAL 10.0
CVE-2022-0543 KEVEPSS 99%

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which c…

Patch available
Fix from $2,300 2022-02-18
Fedora HIGH 8.8
CVE-2020-25718

A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would all…

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-02-18
Snipe It HIGH 8.8
CVE-2022-0611

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.

Fix: 5.3.11+
Fix from $1,950 2022-02-16
Dbcharts HIGH 8.8
CVE-2022-25206

A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified databa…

Fix: after 0.5.2
Fix from $1,950 2022-02-15
Chef Sinatra HIGH 8.8
CVE-2022-25208

A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP…

Fix: after 1.20
Fix from $1,950 2022-02-15
Swamp HIGH 8.8
CVE-2022-25211

A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifie…

Fix: after 1.2.6
Fix from $1,950 2022-02-15
Snow Commander MEDIUM 6.5
CVE-2022-25193

Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission to connect to an attacker-sp…

Fix: after 1.10
Fix from $1,600 2022-02-15
Scp Publisher HIGH 8.8
CVE-2022-25199

A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-sp…

Fix: after 1.8
Fix from $1,950 2022-02-15
Checkmarx MEDIUM 6.5
CVE-2022-25201

Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-spe…

Fix: after 2022.1.2
Fix from $1,600 2022-02-15
Librenms MEDIUM 6.5
CVE-2022-0588

Missing Authorization in Packagist librenms/librenms prior to 22.2.0.

Fix: 22.2.0+
Fix from $1,600 2022-02-15
Snipe It MEDIUM 6.5
CVE-2022-0579

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.

Fix: 5.3.9+
Fix from $1,600 2022-02-14
Hospital\'s Patient Records Management System HIGH 8.8
CVE-2022-22854

An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attackers to escalate privileges via …

No fix yet
Fix from $1,950 2022-02-14