Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.1 CVE-2021-28506 An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially… Eos after 4.26.2f Fix from $2,3002022-01-14 HIGH 7.8 CVE-2021-39622 In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privi… Android Mitigation only Fix from $1,9502022-01-14 MEDIUM 5.3 CVE-2021-1037 The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for i… Android Mitigation only Fix from $1,6002022-01-14 MEDIUM 5.4 CVE-2022-0178 Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8. Snipe It 5.3.8+ Fix from $1,6002022-01-13 MEDIUM 5.9 CVE-2021-40327 Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) … Trusted Firmware M Patch available Fix from $1,6002022-01-13 MEDIUM 6.5 CVE-2022-23112 A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-sp… Publish Over Ssh after 1.22 Fix from $1,6002022-01-12 MEDIUM 5.4 CVE-2022-0179 snipe-it is vulnerable to Missing Authorization Snipe It 5.3.7+ Fix from $1,6002022-01-12 CRITICAL 9.8 CVE-2021-25032EPSS 7% The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation … Capabilities 2.3.1+ Fix from $2,3002022-01-10 HIGH 7.2 CVE-2021-46075 A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resourc… Vehicle Service Management System after 1.0 Fix from $1,9502022-01-06 HIGH 8.8 CVE-2022-22111 In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled… Daybyday Crm Patch available Fix from $1,9502022-01-05 HIGH 7.5 CVE-2021-24831 All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated att… Tab 1.3.2+ Fix from $1,9502022-01-03 HIGH 8.1 CVE-2021-20873 Yappli is an application development platform which provides the function to access a requested URL using Custom URL Scheme. When Android apps are de… Yappli 9.30.0+ Fix from $1,9502021-12-28 MEDIUM 5.4 CVE-2021-24988 The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which… Wp Rss Aggregator 4.19.3+ Fix from $1,6002021-12-27 MEDIUM 6.5 CVE-2021-24997 The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could … Wp Guppy 1.3+ Fix from $1,6002021-12-27 HIGH 7.5 CVE-2021-37572 MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT76… Mt7603e Firmware Mitigation only Fix from $1,9502021-12-26 MEDIUM 6.5 CVE-2021-43847 HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to bec… Humhub 1.9.3 / 1.10.3+ Fix from $1,6002021-12-20 HIGH 7.2 CVE-2021-40853 TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to a… Gim Mitigation only Fix from $1,9502021-12-17 HIGH 7.8 CVE-2021-0673 In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,9502021-12-17 MEDIUM 6.5 CVE-2021-44857 An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by … Mediawiki 1.35.5 / 1.36.3+ Fix from $1,6002021-12-17 HIGH 7.5 CVE-2021-27857 A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1… Ipvpn Firmware Mitigation only Fix from $1,9502021-12-15 MEDIUM 5.3 CVE-2021-27858 A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1… Ipvpn Firmware Mitigation only Fix from $1,6002021-12-15 HIGH 8.8 CVE-2021-27859 A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1… Ipvpn Firmware Mitigation only Fix from $1,9502021-12-15 HIGH 8.8 CVE-2021-27855 FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privilege… Ipvpn Firmware Mitigation only Fix from $1,9502021-12-15 MEDIUM 6.8 CVE-2021-39639 In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege w… Android Patch available Fix from $1,6002021-12-15 HIGH 7.8 CVE-2021-39651 In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead… Android Patch available Fix from $1,9502021-12-15 MEDIUM 5.5 CVE-2021-1025 In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, du… Android Mitigation only Fix from $1,6002021-12-15 HIGH 7.8 CVE-2021-0999 In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permis… Android Patch available Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-1004 In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to… Android Mitigation only Fix from $1,9502021-12-15 MEDIUM 5.5 CVE-2021-1010 In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no addit… Android Mitigation only Fix from $1,6002021-12-15 MEDIUM 5.5 CVE-2021-1011 In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no… Android Mitigation only Fix from $1,6002021-12-15