Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.5 CVE-2022-20121 In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This could lead to local information… Android Mitigation only Fix from $1,6002022-05-10 HIGH 7.8 CVE-2021-39738 In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation … Android Mitigation only Fix from $1,9502022-05-10 MEDIUM 5.5 CVE-2022-20011 In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead … Android Patch available Fix from $1,6002022-05-10 MEDIUM 5.5 CVE-2022-20115 In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due … Android Patch available Fix from $1,6002022-05-10 HIGH 7.5 CVE-2022-1442EPSS 9% The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file whi… Metform Elementor Contact Form Builder 2.1.4+ Fix from $1,9502022-05-10 HIGH 7.8 CVE-2022-20004 In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to loca… Android Patch available Fix from $1,9502022-05-10 HIGH 7.5 CVE-2022-29176 Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any Ruby… Rubygems.org Mitigation only Fix from $1,9502022-05-05 CRITICAL 9.8 CVE-2021-44055 An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote … Video Station 5.1.8 / 5.3.13+ Fix from $2,3002022-05-05 MEDIUM 5.5 CVE-2022-28789 Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper per… Voice Note 21.3.51.11+ Fix from $1,6002022-05-03 HIGH 7.8 CVE-2022-20084 In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalatio… Android Mitigation only Fix from $1,9502022-05-03 HIGH 7.8 CVE-2022-20093 In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of pri… Android Mitigation only Fix from $1,9502022-05-03 HIGH 8.8 CVE-2022-0952EPSS 11% The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does … Sitemap 1.0.36+ Fix from $1,9502022-05-02 HIGH 7.5 CVE-2021-25002 The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated use… Tipsacarrier 1.5.0.5+ Fix from $1,9502022-05-02 CRITICAL 9.8 CVE-2021-43938 Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or auth… Scada Server Mitigation only Fix from $2,3002022-04-29 HIGH 8.8 CVE-2021-44595EPSS 21% Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to th… Dr.fone Mitigation only Fix from $1,9502022-04-29 CRITICAL 9.8 CVE-2022-29906 The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the q… Mediawiki after 1.37.2 Fix from $2,3002022-04-29 MEDIUM 6.5 CVE-2022-1511 Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4. Snipe It 5.4.4+ Fix from $1,6002022-04-28 MEDIUM 5.4 CVE-2022-0398 The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links… Thirstyaffiliates Affiliate Link Manager 3.10.5+ Fix from $1,6002022-04-25 HIGH 8.1 CVE-2022-25342 An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not pr… D Color Mf3555 Firmware No fix yet Fix from $1,9502022-04-20 HIGH 8.8 CVE-2022-1384 Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an auth… Mattermost Server 6.5.0+ Fix from $1,9502022-04-19 HIGH 8.8 CVE-2022-1329EPSS 93% The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check … Website Builder after 3.6.2 Fix from $1,9502022-04-19 CRITICAL 9.8 CVE-2022-1020EPSS 26% The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update… Woo Product Table 3.1.2+ Fix from $2,3002022-04-18 MEDIUM 5.3 CVE-2022-1054 The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the exp… Rsvp And Event Management 2.7.8+ Fix from $1,6002022-04-18 HIGH 7.5 CVE-2022-27669 An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access … Netweaver Application Server For Java Mitigation only Fix from $1,9502022-04-12 HIGH 7.8 CVE-2021-39808 In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due… Android Patch available Fix from $1,9502022-04-12 HIGH 7.5 CVE-2022-27480 A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do no… Sicam A8000 Cp 8031 Firmware 4.80+ Fix from $1,9502022-04-12 MEDIUM 5.3 CVE-2022-0919 The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthent… Salon Booking System 7.6.3+ Fix from $1,6002022-04-11 MEDIUM 6.5 CVE-2022-0404 The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param b… Material Design For Contact Form 7 after 2.6.4 Fix from $1,6002022-04-04 MEDIUM 5.4 CVE-2022-0837 The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid tes… Amelia 1.0.48+ Fix from $1,6002022-04-04 CRITICAL 9.1 CVE-2022-26546 Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the … Hospital Management System No fix yet Fix from $2,3002022-03-31