Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.8 CVE-2022-39093 In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution pri… Android Mitigation only Fix from $1,9502022-12-06 HIGH 7.8 CVE-2022-39090 In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution pri… Android No fix yet Fix from $1,9502022-12-06 HIGH 7.5 CVE-2022-44009 Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V… Stackstorm Mitigation only Fix from $1,9502022-12-06 MEDIUM 6.5 CVE-2022-41807 Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the … Taskalfa 7550ci Firmware Mitigation only Fix from $1,6002022-12-05 MEDIUM 6.5 CVE-2022-32966 RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH s… Rtl8111fp Cg Firmware after 5.0.23 Fix from $1,6002022-11-29 HIGH 7.5 CVE-2022-24190 The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implem… Ourphoto No fix yet Fix from $1,9502022-11-28 MEDIUM 5.3 CVE-2022-4169 The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.2.16 due to missing capabilit… Theme And Plugin Translation For Polylang 3.2.17+ Fix from $1,6002022-11-28 HIGH 8.2 CVE-2022-41930 org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the… Xwiki 13.10.7 / 14.4.2+ Fix from $1,9502022-11-23 HIGH 8.8 CVE-2022-43685 CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take o… Ckan 2.8.12 / 2.9.7+ Fix from $1,9502022-11-22 HIGH 8.1 CVE-2022-41937 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view acce… Xwiki 13.10.8 / 14.4.3+ Fix from $1,9502022-11-22 CRITICAL 9.8 CVE-2022-41326 The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper… Micollab after 9.6.0.105 Fix from $2,3002022-11-22 HIGH 8.8 CVE-2022-43482 Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress. Appointment Booking Calendar 1.3.70+ Fix from $1,9502022-11-18 HIGH 8.8 CVE-2022-41692 Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress. Appointment Hour Booking 1.3.72+ Fix from $1,9502022-11-18 HIGH 7.5 CVE-2022-3920 HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints us… Consul after 1.13.3 Fix from $1,9502022-11-16 MEDIUM 5.3 CVE-2022-20941 A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote atta… Secure Firewall Management Center Mitigation only Fix from $1,6002022-11-15 MEDIUM 5.3 CVE-2022-45389 A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an at… Xp Dev after 1.0 Fix from $1,6002022-11-15 HIGH 7.5 CVE-2022-45385 A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger… Cloudbees Docker Hub\/registry Notification 2.6.2.1+ Fix from $1,9502022-11-15 MEDIUM 6.5 CVE-2022-3538 The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenti… Webmaster Tools Verification after 1.2 Fix from $1,6002022-11-14 CRITICAL 9.8 CVE-2022-38651 A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some… Hyperic Server Mitigation only Fix from $2,3002022-11-12 HIGH 7.5 CVE-2022-44549 The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the g… Harmonyos Mitigation only Fix from $1,9502022-11-09 HIGH 7.8 CVE-2022-20450 In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. Thi… Android Mitigation only Fix from $1,9502022-11-08 HIGH 7.8 CVE-2022-20451 In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local… Android Mitigation only Fix from $1,9502022-11-08 MEDIUM 5.3 CVE-2022-3489 The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allow… Wp Hide after 0.0.2 Fix from $1,6002022-11-07 MEDIUM 5.4 CVE-2022-36404 Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions. Simple Seo after 1.8.12 Fix from $1,6002022-11-03 MEDIUM 6.5 CVE-2022-2696 The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in… Restaurant Menu Food Ordering System Table Reservation 2.3.1+ Fix from $1,6002022-11-03 MEDIUM 5.4 CVE-2022-3096 The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users s… Wp Total Hacks after 4.7.2 Fix from $1,6002022-10-31 MEDIUM 6.5 CVE-2022-3400 The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in version… Bricks after 1.5.3 Fix from $1,6002022-10-28 HIGH 7.5 CVE-2022-3322 Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to ins… Warp Mobile Client 6.14+ Fix from $1,9502022-10-28 HIGH 8.5 CVE-2022-3337 It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflar… Warp Mobile Client 6.15+ Fix from $1,9502022-10-28 HIGH 8.8 CVE-2022-3512 Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trus… Warp 2022.8.857.0 / 2022.8.861.0+ Fix from $1,9502022-10-28