Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.5 CVE-2022-20206 In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclos… Android Mitigation only Fix from $1,6002022-06-15 MEDIUM 5.5 CVE-2022-20172 In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local informati… Android Mitigation only Fix from $1,6002022-06-15 HIGH 7.8 CVE-2022-20138 In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVIS… Android Mitigation only Fix from $1,9502022-06-15 HIGH 7.3 CVE-2022-20126 In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permissio… Android Mitigation only Fix from $1,9502022-06-15 HIGH 7.8 CVE-2022-20133 In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead t… Android Mitigation only Fix from $1,9502022-06-15 HIGH 7.3 CVE-2022-20137 In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permissi… Android Patch available Fix from $1,9502022-06-15 HIGH 8.8 CVE-2022-31595 SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of pri… Adaptive Server Enterprise Mitigation only Fix from $1,9502022-06-14 HIGH 7.5 CVE-2022-32560 An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings. Couchbase Server 7.0.4+ Fix from $1,9502022-06-13 MEDIUM 5.5 CVE-2022-31752 Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality. Emui No fix yet Fix from $1,6002022-06-13 HIGH 8.8 CVE-2022-1777 The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticate… Filr 1.2.2.1+ Fix from $1,9502022-06-13 MEDIUM 6.5 CVE-2022-0745 The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with… Like Button Rating 2.6.45+ Fix from $1,6002022-06-13 CRITICAL 9.8 CVE-2022-0885EPSS 9% The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing … Member Hero after 1.0.9 Fix from $2,3002022-06-13 MEDIUM 6.5 CVE-2021-25116 The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure … Enqueue Anything after 1.0.1 Fix from $1,6002022-06-13 MEDIUM 6.5 CVE-2022-1570 The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any … Files Download Delay 1.0.7+ Fix from $1,6002022-06-08 HIGH 7.5 CVE-2022-30746 Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface AP… Smartthings 1.7.85.12+ Fix from $1,9502022-06-07 MEDIUM 5.5 CVE-2022-30731 Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files applica… My Files 13.1.00.193+ Fix from $1,6002022-06-07 MEDIUM 5.5 CVE-2022-21748 In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User… Android Mitigation only Fix from $1,6002022-06-06 MEDIUM 5.5 CVE-2022-21749 In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a… Android Mitigation only Fix from $1,6002022-06-06 CRITICAL 9.1 CVE-2020-4926 A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection… Elastic Storage System 5.1.3.0 / 6.1.3.0+ Fix from $2,3002022-05-24 CRITICAL 9.8 CVE-2022-28993 Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request. Multi Store Inventory Management System No fix yet Fix from $2,3002022-05-20 HIGH 8.8 CVE-2022-1423 Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9… GitLab 14.8.6 / 14.9.4+ Fix from $1,9502022-05-19 MEDIUM 5.3 CVE-2021-42848 An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrie… A1 Firmware 5.3.6.t1 / 5.3.6.a1+ Fix from $1,6002022-05-18 MEDIUM 5.3 CVE-2021-42851 A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account. A1 Firmware 5.3.6.t1 / 5.3.6.a1+ Fix from $1,6002022-05-18 MEDIUM 6.5 CVE-2022-30959 A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified … Ssh after 2.6.1 Fix from $1,6002022-05-17 HIGH 8.8 CVE-2022-30951 Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing… Wmi Windows Agents 1.8.1+ Fix from $1,9502022-05-17 MEDIUM 6.5 CVE-2022-30954 Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read perm… Blue Ocean after 1.25.3 Fix from $1,6002022-05-17 MEDIUM 6.5 CVE-2022-30955 Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to … GitLab after 1.5.31 Fix from $1,6002022-05-17 HIGH 7.5 CVE-2021-33013 mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information. Mypro 8.20.0+ Fix from $1,9502022-05-13 HIGH 7.8 CVE-2022-30594 The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting… Linux Kernel 4.19.238 / 5.4.189+ Fix from $1,9502022-05-12 HIGH 8.8 CVE-2022-29611 SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in esc… Netweaver Application Server Abap Mitigation only Fix from $1,9502022-05-11