Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Eos CRITICAL 9.1
CVE-2021-28506

An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially…

Fix: after 4.26.2f
Fix from $2,300 2022-01-14
Android HIGH 7.8
CVE-2021-39622

In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privi…

Mitigation only
Fix from $1,950 2022-01-14
Android MEDIUM 5.3
CVE-2021-1037

The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for i…

Mitigation only
Fix from $1,600 2022-01-14
Snipe It MEDIUM 5.4
CVE-2022-0178

Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.

Fix: 5.3.8+
Fix from $1,600 2022-01-13
Trusted Firmware M MEDIUM 5.9
CVE-2021-40327

Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) …

Patch available
Fix from $1,600 2022-01-13
Publish Over Ssh MEDIUM 6.5
CVE-2022-23112

A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-sp…

Fix: after 1.22
Fix from $1,600 2022-01-12
Snipe It MEDIUM 5.4
CVE-2022-0179

snipe-it is vulnerable to Missing Authorization

Fix: 5.3.7+
Fix from $1,600 2022-01-12
Capabilities CRITICAL 9.8
CVE-2021-25032EPSS 7%

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation …

Fix: 2.3.1+
Fix from $2,300 2022-01-10
Vehicle Service Management System HIGH 7.2
CVE-2021-46075

A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resourc…

Fix: after 1.0
Fix from $1,950 2022-01-06
Daybyday Crm HIGH 8.8
CVE-2022-22111

In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled…

Patch available
Fix from $1,950 2022-01-05
Tab HIGH 7.5
CVE-2021-24831

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated att…

Fix: 1.3.2+
Fix from $1,950 2022-01-03
Yappli HIGH 8.1
CVE-2021-20873

Yappli is an application development platform which provides the function to access a requested URL using Custom URL Scheme. When Android apps are de…

Fix: 9.30.0+
Fix from $1,950 2021-12-28
Wp Rss Aggregator MEDIUM 5.4
CVE-2021-24988

The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which…

Fix: 4.19.3+
Fix from $1,600 2021-12-27
Wp Guppy MEDIUM 6.5
CVE-2021-24997

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could …

Fix: 1.3+
Fix from $1,600 2021-12-27
Mt7603e Firmware HIGH 7.5
CVE-2021-37572

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT76…

Mitigation only
Fix from $1,950 2021-12-26
Humhub MEDIUM 6.5
CVE-2021-43847

HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to bec…

Fix: 1.9.3 / 1.10.3+
Fix from $1,600 2021-12-20
Gim HIGH 7.2
CVE-2021-40853

TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to a…

Mitigation only
Fix from $1,950 2021-12-17
Android HIGH 7.8
CVE-2021-0673

In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2021-12-17
Mediawiki MEDIUM 6.5
CVE-2021-44857

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by …

Fix: 1.35.5 / 1.36.3+
Fix from $1,600 2021-12-17
Ipvpn Firmware HIGH 7.5
CVE-2021-27857

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…

Mitigation only
Fix from $1,950 2021-12-15
Ipvpn Firmware MEDIUM 5.3
CVE-2021-27858

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…

Mitigation only
Fix from $1,600 2021-12-15
Ipvpn Firmware HIGH 8.8
CVE-2021-27859

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…

Mitigation only
Fix from $1,950 2021-12-15
Ipvpn Firmware HIGH 8.8
CVE-2021-27855

FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privilege…

Mitigation only
Fix from $1,950 2021-12-15
Android MEDIUM 6.8
CVE-2021-39639

In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege w…

Patch available
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-39651

In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead…

Patch available
Fix from $1,950 2021-12-15
Android MEDIUM 5.5
CVE-2021-1025

In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, du…

Mitigation only
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-0999

In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permis…

Patch available
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-1004

In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to…

Mitigation only
Fix from $1,950 2021-12-15
Android MEDIUM 5.5
CVE-2021-1010

In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no addit…

Mitigation only
Fix from $1,600 2021-12-15
Android MEDIUM 5.5
CVE-2021-1011

In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no…

Mitigation only
Fix from $1,600 2021-12-15