Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.5 CVE-2022-38689 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne… Android Mitigation only Fix from $1,6002022-10-14 HIGH 7.8 CVE-2022-38669 In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execu… Android No fix yet Fix from $1,9502022-10-14 HIGH 7.8 CVE-2022-38670 In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execu… Android Mitigation only Fix from $1,9502022-10-14 MEDIUM 5.5 CVE-2022-38677 In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privile… Android No fix yet Fix from $1,6002022-10-14 HIGH 7.8 CVE-2022-2985 In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution pri… Android No fix yet Fix from $1,9502022-10-14 HIGH 7.8 CVE-2022-42488 OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious applicat… Openharmony 3.1.2+ Fix from $1,9502022-10-14 HIGH 8.8 CVE-2022-28866 Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for acc… Airframe Bmc Web Gui R18 Firmware 4.13.00+ Fix from $1,9502022-10-12 HIGH 7.8 CVE-2022-20430 There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p… Android No fix yet Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-20431 There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p… Android Mitigation only Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-20432 There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulti… Android Mitigation only Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-20433 There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p… Android Mitigation only Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-20434 There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p… Android Mitigation only Fix from $1,9502022-10-11 MEDIUM 5.0 CVE-2022-20394 In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due t… Android Patch available Fix from $1,6002022-10-11 HIGH 8.8 CVE-2022-31765 Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate thei… 6gk6108 4am00 2ba2 Firmware 7.1.2+ Fix from $1,9502022-10-11 MEDIUM 5.3 CVE-2022-2350 The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticate… Disable User Login after 1.0.1 Fix from $1,6002022-10-10 HIGH 7.5 CVE-2022-39289 ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log conten… Zoneminder 1.37.24+ Fix from $1,9502022-10-07 MEDIUM 6.5 CVE-2022-39222 Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clie… Dex 2.35.0+ Fix from $1,6002022-10-06 MEDIUM 5.3 CVE-2022-3124EPSS 7% The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due t… Frontend File Manager 21.3+ Fix from $1,6002022-10-03 MEDIUM 5.3 CVE-2020-15337 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15338 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 HIGH 7.5 CVE-2022-2987 The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's set… Ldap Wp Login \/ Active Directory Integration 3.0.2+ Fix from $1,9502022-09-26 HIGH 8.8 CVE-2021-24890 The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthent… Scripts Organizer 3.0+ Fix from $1,9502022-09-26 MEDIUM 5.3 CVE-2022-36340 Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress. Mailoptin after 1.2.49.0 Fix from $1,6002022-09-23 MEDIUM 6.5 CVE-2022-32220 An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from pr… Rocket.chat 5.0+ Fix from $1,6002022-09-23 HIGH 7.1 CVE-2021-41803 HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT cl… Consul 1.11.9+ Fix from $1,9502022-09-23 MEDIUM 5.3 CVE-2021-39190 The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is… System Center Configuration Manager 2.3.0+ Fix from $1,6002022-09-22 MEDIUM 6.5 CVE-2022-38512 The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allow… Dxp after 7.4.3.36 Fix from $1,6002022-09-22 MEDIUM 6.5 CVE-2022-41246 A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to conne… Worksoft Execution Manager after 10.0.3.503 Fix from $1,6002022-09-21 MEDIUM 6.5 CVE-2022-41250 A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-s… Scm Httpclient after 1.5 Fix from $1,6002022-09-21 MEDIUM 6.5 CVE-2022-41254 Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specifie… Cons3rt after 1.0.0 Fix from $1,6002022-09-21