Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Ppom For Woocommerce MEDIUM 5.4
CVE-2021-25018

The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allo…

Fix: 24.0+
Fix from $1,600 2022-02-14
Android HIGH 7.8
CVE-2021-39662

In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing pe…

Patch available
Fix from $1,950 2022-02-11
Interactive Graphical Scada System Data Server HIGH 7.5
CVE-2022-24317

A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Produ…

Fix: after 15.0.0.22020
Fix from $1,950 2022-02-09
Erp Human Capital Management MEDIUM 6.5
CVE-2022-22535

SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees …

Mitigation only
Fix from $1,600 2022-02-09
Android HIGH 7.8
CVE-2022-20041

In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…

Mitigation only
Fix from $1,950 2022-02-09
Android HIGH 7.8
CVE-2022-20043

In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…

Mitigation only
Fix from $1,950 2022-02-09
Android HIGH 7.8
CVE-2022-20024

In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no …

Mitigation only
Fix from $1,950 2022-02-09
Xwiki MEDIUM 6.5
CVE-2022-23617

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit righ…

Fix: after 12.10.5
Fix from $1,600 2022-02-09
Gin Vue Admin HIGH 8.1
CVE-2022-21660

Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privile…

Fix: after 2.4.6
Fix from $1,950 2022-02-09
Nats Server HIGH 8.8
CVE-2022-24450

NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "d…

Fix: 0.24.1 / 2.7.2+
Fix from $1,950 2022-02-08
Country Blocker HIGH 7.1
CVE-2021-25095

The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_ru…

Fix: 2.26.5+
Fix from $1,950 2022-02-07
Ultimate Product Catalog MEDIUM 6.5
CVE-2021-24993

The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any a…

Fix: 5.0.26+
Fix from $1,600 2022-02-07
Supportcandy HIGH 7.5
CVE-2021-24839

The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthe…

Fix: 2.2.5+
Fix from $1,950 2022-02-07
Wordpress Email Template Designer MEDIUM 6.1
CVE-2022-0218EPSS 71%

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings d…

Fix: after 3.0.9
Fix from $1,600 2022-02-04
Link Library HIGH 7.5
CVE-2021-25093

The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arb…

Fix: 7.2.8+
Fix from $1,950 2022-02-01
Single Connect MEDIUM 5.3
CVE-2021-44795

Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulner…

Fix: 2.16+
Fix from $1,600 2022-01-27
Single Connect MEDIUM 5.3
CVE-2021-44792

Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to acc…

Fix: 2.16+
Fix from $1,600 2022-01-27
Single Connect HIGH 8.6
CVE-2021-44793

Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to ac…

Fix: 2.16+
Fix from $1,950 2022-01-27
Single Connect MEDIUM 5.3
CVE-2021-44794

Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability t…

Fix: 2.16+
Fix from $1,600 2022-01-27
Crater MEDIUM 5.3
CVE-2022-0203

Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

Fix: 6.0.2+
Fix from $1,600 2022-01-26
Shenyu CRITICAL 9.1
CVE-2022-23944EPSS 79%

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $2,300 2022-01-25
Shenyu HIGH 7.5
CVE-2022-23945

Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $1,950 2022-01-25
Qubely MEDIUM 6.5
CVE-2021-25013

The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure…

Fix: 1.7.8+
Fix from $1,600 2022-01-24
Protect Wp Admin HIGH 7.5
CVE-2021-24906

The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthentic…

Fix: 3.6.2+
Fix from $1,950 2022-01-24
Ultimate Faq MEDIUM 5.7
CVE-2021-24968

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_…

Fix: 2.1.2+
Fix from $1,600 2022-01-24
Host Runtime HIGH 8.1
CVE-2022-21707

wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In vers…

Fix: 0.52.2+
Fix from $1,950 2022-01-21
Android Q Sdk HIGH 7.5
CVE-2021-38789

Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which …

Mitigation only
Fix from $1,950 2022-01-19
GitLab MEDIUM 6.5
CVE-2022-0152

An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all…

Fix: 14.4.5 / 14.5.3+
Fix from $1,600 2022-01-18
Wp Import Export HIGH 7.5
CVE-2022-0236

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing ca…

Fix: after 3.9.15
Fix from $1,950 2022-01-18
Whmcs Bridge MEDIUM 5.4
CVE-2021-4074

The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/brid…

Fix: after 6.1
Fix from $1,600 2022-01-18