Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2022-20206
In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclos…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-20172
In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local informati…
Android
Mitigation only
HIGH 7.8
CVE-2022-20138
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVIS…
Android
Mitigation only
HIGH 7.3
CVE-2022-20126
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permissio…
Android
Mitigation only
HIGH 7.8
CVE-2022-20133
In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead t…
Android
Mitigation only
HIGH 7.3
CVE-2022-20137
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permissi…
Android
Patch available
HIGH 8.8
CVE-2022-31595
SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of pri…
Adaptive Server Enterprise
Mitigation only
HIGH 7.5
CVE-2022-32560
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
Couchbase Server
7.0.4+
MEDIUM 5.5
CVE-2022-31752
Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality.
Emui
No fix yet
HIGH 8.8
CVE-2022-1777
The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticate…
Filr
1.2.2.1+
MEDIUM 6.5
CVE-2022-0745
The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with…
Like Button Rating
2.6.45+
CRITICAL 9.8
CVE-2022-0885EPSS 9%
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing …
Member Hero
after 1.0.9
MEDIUM 6.5
CVE-2021-25116
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure …
Enqueue Anything
after 1.0.1
MEDIUM 6.5
CVE-2022-1570
The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any …
Files Download Delay
1.0.7+
HIGH 7.5
CVE-2022-30746
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface AP…
Smartthings
1.7.85.12+
MEDIUM 5.5
CVE-2022-30731
Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files applica…
My Files
13.1.00.193+
MEDIUM 5.5
CVE-2022-21748
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-21749
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a…
Android
Mitigation only
CRITICAL 9.1
CVE-2020-4926
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection…
Elastic Storage System
5.1.3.0 / 6.1.3.0+
CRITICAL 9.8
CVE-2022-28993
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
Multi Store Inventory Management System
No fix yet
HIGH 8.8
CVE-2022-1423
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9…
GitLab
14.8.6 / 14.9.4+
MEDIUM 5.3
CVE-2021-42848
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrie…
A1 Firmware
5.3.6.t1 / 5.3.6.a1+
MEDIUM 5.3
CVE-2021-42851
A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.
A1 Firmware
5.3.6.t1 / 5.3.6.a1+
MEDIUM 6.5
CVE-2022-30959
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified …
Ssh
after 2.6.1
HIGH 8.8
CVE-2022-30951
Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing…
Wmi Windows Agents
1.8.1+
MEDIUM 6.5
CVE-2022-30954
Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read perm…
Blue Ocean
after 1.25.3
MEDIUM 6.5
CVE-2022-30955
Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to …
GitLab
after 1.5.31
HIGH 7.5
CVE-2021-33013
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
Mypro
8.20.0+
HIGH 7.8
CVE-2022-30594
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting…
Linux Kernel
4.19.238 / 5.4.189+
HIGH 8.8
CVE-2022-29611
SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in esc…
Netweaver Application Server Abap
Mitigation only