Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2022-20121
In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This could lead to local information…
Android
Mitigation only
HIGH 7.8
CVE-2021-39738
In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation …
Android
Mitigation only
MEDIUM 5.5
CVE-2022-20011
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead …
Android
Patch available
MEDIUM 5.5
CVE-2022-20115
In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due …
Android
Patch available
HIGH 7.5
CVE-2022-1442EPSS 9%
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file whi…
Metform Elementor Contact Form Builder
2.1.4+
HIGH 7.8
CVE-2022-20004
In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to loca…
Android
Patch available
HIGH 7.5
CVE-2022-29176
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any Ruby…
Rubygems.org
Mitigation only
CRITICAL 9.8
CVE-2021-44055
An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote …
Video Station
5.1.8 / 5.3.13+
MEDIUM 5.5
CVE-2022-28789
Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper per…
Voice Note
21.3.51.11+
HIGH 7.8
CVE-2022-20084
In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalatio…
Android
Mitigation only
HIGH 7.8
CVE-2022-20093
In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of pri…
Android
Mitigation only
HIGH 8.8
CVE-2022-0952EPSS 11%
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does …
Sitemap
1.0.36+
HIGH 7.5
CVE-2021-25002
The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated use…
Tipsacarrier
1.5.0.5+
CRITICAL 9.8
CVE-2021-43938
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or auth…
Scada Server
Mitigation only
HIGH 8.8
CVE-2021-44595EPSS 21%
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to th…
Dr.fone
Mitigation only
CRITICAL 9.8
CVE-2022-29906
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the q…
Mediawiki
after 1.37.2
MEDIUM 6.5
CVE-2022-1511
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
Snipe It
5.4.4+
MEDIUM 5.4
CVE-2022-0398
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links…
Thirstyaffiliates Affiliate Link Manager
3.10.5+
HIGH 8.1
CVE-2022-25342
An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not pr…
D Color Mf3555 Firmware
No fix yet
HIGH 8.8
CVE-2022-1384
Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an auth…
Mattermost Server
6.5.0+
HIGH 8.8
CVE-2022-1329EPSS 93%
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check …
Website Builder
after 3.6.2
CRITICAL 9.8
CVE-2022-1020EPSS 26%
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update…
Woo Product Table
3.1.2+
MEDIUM 5.3
CVE-2022-1054
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the exp…
Rsvp And Event Management
2.7.8+
HIGH 7.5
CVE-2022-27669
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access …
Netweaver Application Server For Java
Mitigation only
HIGH 7.8
CVE-2021-39808
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due…
Android
Patch available
HIGH 7.5
CVE-2022-27480
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do no…
Sicam A8000 Cp 8031 Firmware
4.80+
MEDIUM 5.3
CVE-2022-0919
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthent…
Salon Booking System
7.6.3+
MEDIUM 6.5
CVE-2022-0404
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option mentioned in the notice param b…
Material Design For Contact Form 7
after 2.6.4
MEDIUM 5.4
CVE-2022-0837
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid tes…
Amelia
1.0.48+
CRITICAL 9.1
CVE-2022-26546
Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the …
Hospital Management System
No fix yet