Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2021-25018
The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allo…
Ppom For Woocommerce
24.0+
HIGH 7.8
CVE-2021-39662
In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing pe…
Android
Patch available
HIGH 7.5
CVE-2022-24317
A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Produ…
Interactive Graphical Scada System Data Server
after 15.0.0.22020
MEDIUM 6.5
CVE-2022-22535
SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees …
Erp Human Capital Management
Mitigation only
HIGH 7.8
CVE-2022-20041
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…
Android
Mitigation only
HIGH 7.8
CVE-2022-20043
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…
Android
Mitigation only
HIGH 7.8
CVE-2022-20024
In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no …
Android
Mitigation only
MEDIUM 6.5
CVE-2022-23617
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit righ…
Xwiki
after 12.10.5
HIGH 8.1
CVE-2022-21660
Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privile…
Gin Vue Admin
after 2.4.6
HIGH 8.8
CVE-2022-24450
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "d…
Nats Server
0.24.1 / 2.7.2+
HIGH 7.1
CVE-2021-25095
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_ru…
Country Blocker
2.26.5+
MEDIUM 6.5
CVE-2021-24993
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any a…
Ultimate Product Catalog
5.0.26+
HIGH 7.5
CVE-2021-24839
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthe…
Supportcandy
2.2.5+
MEDIUM 6.1
CVE-2022-0218EPSS 71%
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings d…
Wordpress Email Template Designer
after 3.0.9
HIGH 7.5
CVE-2021-25093
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arb…
Link Library
7.2.8+
MEDIUM 5.3
CVE-2021-44795
Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulner…
Single Connect
2.16+
MEDIUM 5.3
CVE-2021-44792
Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to acc…
Single Connect
2.16+
HIGH 8.6
CVE-2021-44793
Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to ac…
Single Connect
2.16+
MEDIUM 5.3
CVE-2021-44794
Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability t…
Single Connect
2.16+
MEDIUM 5.3
CVE-2022-0203
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
Crater
6.0.2+
CRITICAL 9.1
CVE-2022-23944EPSS 79%
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Patch available
HIGH 7.5
CVE-2022-23945
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Shenyu
Patch available
MEDIUM 6.5
CVE-2021-25013
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure…
Qubely
1.7.8+
HIGH 7.5
CVE-2021-24906
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthentic…
Protect Wp Admin
3.6.2+
MEDIUM 5.7
CVE-2021-24968
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_…
Ultimate Faq
2.1.2+
HIGH 8.1
CVE-2022-21707
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In vers…
Host Runtime
0.52.2+
HIGH 7.5
CVE-2021-38789
Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which …
Android Q Sdk
Mitigation only
MEDIUM 6.5
CVE-2022-0152
An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all…
GitLab
14.4.5 / 14.5.3+
HIGH 7.5
CVE-2022-0236
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing ca…
Wp Import Export
after 3.9.15
MEDIUM 5.4
CVE-2021-4074
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/brid…
Whmcs Bridge
after 6.1