Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.5 CVE-2022-48166 An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and … Wl Wn530hg4 Firmware No fix yet Fix from $1,9502023-02-06 HIGH 8.8 CVE-2021-36225 Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads an… My Cloud Os 5.02.104+ Fix from $1,9502023-02-06 MEDIUM 5.3 CVE-2023-0678EPSS 37% Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1. Phpipam 1.5.1+ Fix from $1,6002023-02-04 MEDIUM 5.4 CVE-2022-42909 WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This c… Print Away Mitigation only Fix from $1,6002023-02-03 HIGH 7.5 CVE-2023-25014 An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit… Femanager 5.5.3 / 6.3.4+ Fix from $1,9502023-02-02 MEDIUM 6.5 CVE-2023-0619 The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in ver… Kraken.io Image Optimizer after 2.6.8 Fix from $1,6002023-02-01 MEDIUM 6.5 CVE-2023-22737 wire-server provides back end services for Wire, a team communication and collaboration platform. Prior to version 2022-12-09, every member of a Conv… Wire 2022-12-09+ Fix from $1,6002023-01-28 MEDIUM 6.5 CVE-2023-0556 The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to… Contentstudio 1.2.6+ Fix from $1,6002023-01-27 CRITICAL 9.1 CVE-2022-39811 Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not ve… Netmatch S Ci No fix yet Fix from $2,3002023-01-27 HIGH 8.1 CVE-2023-0555 The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in version… Quick Restaurant Menu 2.1.0+ Fix from $1,9502023-01-27 MEDIUM 6.5 CVE-2023-24459 A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec… Bearychat after 3.0.2 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24448 A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacke… Rabbitmq Consumer after 2.8 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24453 A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi… Testquality Updater after 1.3 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24433 Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permission to connect to an attacke… Orka By Macstadium 1.32+ Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24435 A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect … Github Pull Request Builder after 1.42.2 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24438 A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with Overall/Read permission to c… Jira Pipeline Steps after 2.0.165.v8846cf59f3db Fix from $1,6002023-01-26 MEDIUM 5.4 CVE-2023-23611 LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and … Xblock Lti Consumer 7.2.2+ Fix from $1,6002023-01-26 HIGH 8.5 CVE-2023-22736 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6… Argo Cd 2.5.8+ Fix from $1,9502023-01-26 HIGH 7.8 CVE-2023-20912 In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check… Android Mitigation only Fix from $1,9502023-01-26 HIGH 7.8 CVE-2023-20916 In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starting activities from the backgr… Android Mitigation only Fix from $1,9502023-01-26 MEDIUM 5.3 CVE-2022-3482 An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 all… GitLab 15.4.6 / 15.5.5+ Fix from $1,6002023-01-26 MEDIUM 5.4 CVE-2023-0404 The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJA… Events Made Easy after 2.3.16 Fix from $1,6002023-01-19 MEDIUM 5.4 CVE-2023-0402 The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions u… Social Warfare after 4.3.0 Fix from $1,6002023-01-19 HIGH 8.8 CVE-2023-0242 Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th… Velociraptor 0.6.7-5+ Fix from $1,9502023-01-18 CRITICAL 9.8 CVE-2022-41417 BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/. Blogengine.net Patch available Fix from $2,3002023-01-18 MEDIUM 6.8 CVE-2020-22007 OS Command Injection vulnerability in OKER G955V1 v1.03.02.20161128, allows physical attackers to interrupt the boot sequence and execute arbitrary c… G955v1 Firmware No fix yet Fix from $1,6002023-01-18 HIGH 7.5 CVE-2023-22478 KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in… Kubepi 1.6.4+ Fix from $1,9502023-01-14 MEDIUM 5.4 CVE-2023-22488 Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access check… Flarum 1.6.3+ Fix from $1,6002023-01-12 MEDIUM 5.5 CVE-2022-44438 In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio… Android Mitigation only Fix from $1,6002023-01-04 MEDIUM 5.5 CVE-2022-44439 In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional executio… Android Mitigation only Fix from $1,6002023-01-04