Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2022-41228 A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permiss… Ns Nd Integration Performance Publisher 4.8.0.130+ Fix from $1,9502022-09-21 HIGH 8.8 CVE-2022-41234 Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permissi… Rundeck after 3.6.11 Fix from $1,9502022-09-21 CRITICAL 9.8 CVE-2022-41238 A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to th… Dotci after 2.40.00 Fix from $2,3002022-09-21 MEDIUM 5.4 CVE-2022-41242 A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information a… Extreme Feedback after 1.7 Fix from $1,6002022-09-21 MEDIUM 5.3 CVE-2022-39960EPSS 26% The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to expo… Group Export 1.0.3+ Fix from $1,6002022-09-17 HIGH 7.8 CVE-2022-40673 KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache. Fedora 3.1.0+ Fix from $1,9502022-09-14 HIGH 7.8 CVE-2022-39119 In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges nee… Android Mitigation only Fix from $1,9502022-09-09 HIGH 7.5 CVE-2022-36091 XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of… Xwiki 13.10.4 / 14.2+ Fix from $1,9502022-09-08 MEDIUM 6.5 CVE-2022-31167 XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.… Xwiki 12.10.11 / 13.4.6+ Fix from $1,6002022-09-07 MEDIUM 5.3 CVE-2022-2461 The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, an… Transposh Wordpress Translation after 1.0.8.1 Fix from $1,6002022-09-06 MEDIUM 5.3 CVE-2022-38367 The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to expor… User Export For Jira 2.0.6+ Fix from $1,6002022-09-05 MEDIUM 5.3 CVE-2022-2376 The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any au… Directorist 7.3.1+ Fix from $1,6002022-09-05 MEDIUM 6.1 CVE-2022-2543 The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoint… Visual Portfolio\, Photo Gallery \& Post Grid 2.18.0+ Fix from $1,6002022-09-05 HIGH 7.5 CVE-2022-38370 Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users… Iotdb Mitigation only Fix from $1,9502022-09-05 CRITICAL 9.8 CVE-2022-36642EPSS 10% A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users… Omnia Mpx Node Firmware 1.5.0+ Fix from $2,3002022-09-02 MEDIUM 5.3 CVE-2022-2373 The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retri… Simply Schedule Appointments 1.5.7.7+ Fix from $1,6002022-08-29 HIGH 7.2 CVE-2022-36226 SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx. Siteservercms after 5.0.0 Fix from $1,9502022-08-26 MEDIUM 5.0 CVE-2022-32769 Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A s… Avideo Mitigation only Fix from $1,6002022-08-22 MEDIUM 5.3 CVE-2022-2552EPSS 11% The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve… Duplicator 1.4.7.1+ Fix from $1,6002022-08-22 MEDIUM 6.5 CVE-2022-25810 The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab … Transposh Wordpress Translation after 1.0.8 Fix from $1,6002022-08-22 MEDIUM 6.5 CVE-2022-36024 py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are ad… Pycord Patch available Fix from $1,6002022-08-18 HIGH 7.5 CVE-2022-2379 The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information r… Easy Student Results after 2.2.8 Fix from $1,9502022-08-15 MEDIUM 6.5 CVE-2022-38183 In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any i… Gitea 1.16.9+ Fix from $1,6002022-08-12 MEDIUM 5.5 CVE-2022-20341 In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information dis… Android Mitigation only Fix from $1,6002022-08-12 MEDIUM 5.5 CVE-2022-20312 In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local i… Android Mitigation only Fix from $1,6002022-08-12 MEDIUM 5.5 CVE-2022-20322 In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosur… Android Mitigation only Fix from $1,6002022-08-12 MEDIUM 5.5 CVE-2022-20323 In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclo… Android Mitigation only Fix from $1,6002022-08-12 MEDIUM 5.5 CVE-2022-20326 In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure wi… Android Mitigation only Fix from $1,6002022-08-12 HIGH 7.8 CVE-2022-20329 In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privile… Android Mitigation only Fix from $1,9502022-08-12 MEDIUM 5.5 CVE-2022-20294 In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local infor… Android Mitigation only Fix from $1,6002022-08-12