Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-41228
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permiss…
Ns Nd Integration Performance Publisher
4.8.0.130+
HIGH 8.8
CVE-2022-41234
Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permissi…
Rundeck
after 3.6.11
CRITICAL 9.8
CVE-2022-41238
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to th…
Dotci
after 2.40.00
MEDIUM 5.4
CVE-2022-41242
A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information a…
Extreme Feedback
after 1.7
MEDIUM 5.3
CVE-2022-39960EPSS 26%
The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to expo…
Group Export
1.0.3+
HIGH 7.8
CVE-2022-40673
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
Fedora
3.1.0+
HIGH 7.8
CVE-2022-39119
In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges nee…
Android
Mitigation only
HIGH 7.5
CVE-2022-36091
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of…
Xwiki
13.10.4 / 14.2+
MEDIUM 6.5
CVE-2022-31167
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.…
Xwiki
12.10.11 / 13.4.6+
MEDIUM 5.3
CVE-2022-2461
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, an…
Transposh Wordpress Translation
after 1.0.8.1
MEDIUM 5.3
CVE-2022-38367
The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to expor…
User Export For Jira
2.0.6+
MEDIUM 5.3
CVE-2022-2376
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any au…
Directorist
7.3.1+
MEDIUM 6.1
CVE-2022-2543
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoint…
Visual Portfolio\, Photo Gallery \& Post Grid
2.18.0+
HIGH 7.5
CVE-2022-38370
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users…
Iotdb
Mitigation only
CRITICAL 9.8
CVE-2022-36642EPSS 10%
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users…
Omnia Mpx Node Firmware
1.5.0+
MEDIUM 5.3
CVE-2022-2373
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retri…
Simply Schedule Appointments
1.5.7.7+
HIGH 7.2
CVE-2022-36226
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
Siteservercms
after 5.0.0
MEDIUM 5.0
CVE-2022-32769
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A s…
Avideo
Mitigation only
MEDIUM 5.3
CVE-2022-2552EPSS 11%
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…
Duplicator
1.4.7.1+
MEDIUM 6.5
CVE-2022-25810
The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab …
Transposh Wordpress Translation
after 1.0.8
MEDIUM 6.5
CVE-2022-36024
py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are ad…
Pycord
Patch available
HIGH 7.5
CVE-2022-2379
The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information r…
Easy Student Results
after 2.2.8
MEDIUM 6.5
CVE-2022-38183
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any i…
Gitea
1.16.9+
MEDIUM 5.5
CVE-2022-20341
In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information dis…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-20312
In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local i…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-20322
In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosur…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-20323
In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclo…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-20326
In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure wi…
Android
Mitigation only
HIGH 7.8
CVE-2022-20329
In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privile…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-20294
In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local infor…
Android
Mitigation only