Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.4 CVE-2021-25018 The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allo… Ppom For Woocommerce 24.0+ Fix from $1,6002022-02-14 HIGH 7.8 CVE-2021-39662 In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing pe… Android Patch available Fix from $1,9502022-02-11 HIGH 7.5 CVE-2022-24317 A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Produ… Interactive Graphical Scada System Data Server after 15.0.0.22020 Fix from $1,9502022-02-09 MEDIUM 6.5 CVE-2022-22535 SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees … Erp Human Capital Management Mitigation only Fix from $1,6002022-02-09 HIGH 7.8 CVE-2022-20041 In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no… Android Mitigation only Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-20043 In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no… Android Mitigation only Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-20024 In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no … Android Mitigation only Fix from $1,9502022-02-09 MEDIUM 6.5 CVE-2022-23617 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit righ… Xwiki after 12.10.5 Fix from $1,6002022-02-09 HIGH 8.1 CVE-2022-21660 Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privile… Gin Vue Admin after 2.4.6 Fix from $1,9502022-02-09 HIGH 8.8 CVE-2022-24450 NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "d… Nats Server 0.24.1 / 2.7.2+ Fix from $1,9502022-02-08 HIGH 7.1 CVE-2021-25095 The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_ru… Country Blocker 2.26.5+ Fix from $1,9502022-02-07 MEDIUM 6.5 CVE-2021-24993 The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any a… Ultimate Product Catalog 5.0.26+ Fix from $1,6002022-02-07 HIGH 7.5 CVE-2021-24839 The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthe… Supportcandy 2.2.5+ Fix from $1,9502022-02-07 MEDIUM 6.1 CVE-2022-0218EPSS 71% The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings d… Wordpress Email Template Designer after 3.0.9 Fix from $1,6002022-02-04 HIGH 7.5 CVE-2021-25093 The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arb… Link Library 7.2.8+ Fix from $1,9502022-02-01 MEDIUM 5.3 CVE-2021-44795 Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulner… Single Connect 2.16+ Fix from $1,6002022-01-27 MEDIUM 5.3 CVE-2021-44792 Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to acc… Single Connect 2.16+ Fix from $1,6002022-01-27 HIGH 8.6 CVE-2021-44793 Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to ac… Single Connect 2.16+ Fix from $1,9502022-01-27 MEDIUM 5.3 CVE-2021-44794 Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability t… Single Connect 2.16+ Fix from $1,6002022-01-27 MEDIUM 5.3 CVE-2022-0203 Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. Crater 6.0.2+ Fix from $1,6002022-01-26 CRITICAL 9.1 CVE-2022-23944EPSS 79% User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Patch available Fix from $2,3002022-01-25 HIGH 7.5 CVE-2022-23945 Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Patch available Fix from $1,9502022-01-25 MEDIUM 6.5 CVE-2021-25013 The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure… Qubely 1.7.8+ Fix from $1,6002022-01-24 HIGH 7.5 CVE-2021-24906 The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthentic… Protect Wp Admin 3.6.2+ Fix from $1,9502022-01-24 MEDIUM 5.7 CVE-2021-24968 The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_… Ultimate Faq 2.1.2+ Fix from $1,6002022-01-24 HIGH 8.1 CVE-2022-21707 wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In vers… Host Runtime 0.52.2+ Fix from $1,9502022-01-21 HIGH 7.5 CVE-2021-38789 Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which … Android Q Sdk Mitigation only Fix from $1,9502022-01-19 MEDIUM 6.5 CVE-2022-0152 An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all… GitLab 14.4.5 / 14.5.3+ Fix from $1,6002022-01-18 HIGH 7.5 CVE-2022-0236 The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing ca… Wp Import Export after 3.9.15 Fix from $1,9502022-01-18 MEDIUM 5.4 CVE-2021-4074 The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/brid… Whmcs Bridge after 6.1 Fix from $1,6002022-01-18