Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2022-23183 Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows… Advanced Custom Fields 5.12.1+ Fix from $1,6002022-03-31 HIGH 7.8 CVE-2022-20002 In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege … Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39768 In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lea… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 5.5 CVE-2021-39742 In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disc… Android Mitigation only Fix from $1,6002022-03-30 HIGH 7.8 CVE-2021-39743 In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to loc… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39749 In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local … Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39750 In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to loca… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 5.5 CVE-2021-39751 In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to … Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39753 In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lea… Android Mitigation only Fix from $1,6002022-03-30 HIGH 7.8 CVE-2021-39758 In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to lo… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 6.5 CVE-2022-28158 A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate cr… Pipeline\ after 1.3 Fix from $1,6002022-03-29 MEDIUM 5.4 CVE-2022-28134 Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with O… Bitbucket Server Integration after 3.1.0 Fix from $1,6002022-03-29 MEDIUM 6.5 CVE-2022-28144 Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permissi… Proxmox after 0.7.0 Fix from $1,6002022-03-29 HIGH 7.5 CVE-2022-27658 Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering… Innovation Management Mitigation only Fix from $1,9502022-03-28 MEDIUM 5.3 CVE-2021-24978 The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_aj… Osmapper after 2.1.5 Fix from $1,6002022-03-28 HIGH 7.5 CVE-2021-3814 It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably b… 3scale 2.11.0+ Fix from $1,9502022-03-25 HIGH 8.8 CVE-2022-24768 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an … Argo Cd 2.1.14 / 2.2.8+ Fix from $1,9502022-03-23 MEDIUM 5.0 CVE-2022-21718 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-… Electron 13.6.6 / 14.2.4+ Fix from $1,6002022-03-22 HIGH 8.1 CVE-2022-0229 The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMet… Google Authenticator 5.5+ Fix from $1,9502022-03-21 HIGH 7.8 CVE-2021-39734 In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check… Android Mitigation only Fix from $1,9502022-03-16 HIGH 7.8 CVE-2021-39706 In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This coul… Android Patch available Fix from $1,9502022-03-16 HIGH 7.8 CVE-2021-39697 In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missi… Android Patch available Fix from $1,9502022-03-16 MEDIUM 6.5 CVE-2022-27209 A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerat… Kubernetes Continuous Deploy after 2.3.1 Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-27211 A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect … Kubernetes Continuous Deploy after 2.3.1 Fix from $1,6002022-03-15 MEDIUM 5.4 CVE-2021-24950 The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to … Insight Core No fix yet Fix from $1,6002022-03-14 MEDIUM 6.5 CVE-2022-0932 Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2. Saleor 3.1.2+ Fix from $1,6002022-03-11 CRITICAL 9.1 CVE-2022-0871 Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5. Gogs 0.12.5+ Fix from $2,3002022-03-11 MEDIUM 5.3 CVE-2021-41233 Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application… Nextcloud Server 20.0.14 / 21.0.6+ Fix from $1,6002022-03-10 MEDIUM 5.3 CVE-2022-26103 Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to … Netweaver Application Server Java Mitigation only Fix from $1,6002022-03-10 MEDIUM 5.3 CVE-2022-26104 SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthor… Financial Consolidation Mitigation only Fix from $1,6002022-03-10