Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
GitLab HIGH 7.5
CVE-2022-4167

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows g…

Fix: 15.5.7 / 15.6.4+
Fix from $1,950 2023-01-12
Windows 10 1607 MEDIUM 6.6
CVE-2023-21560

Windows Boot Manager Security Feature Bypass Vulnerability

No fix yet
Fix from $1,600 2023-01-10
Chrome MEDIUM 6.5
CVE-2023-0133

Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main ori…

Fix: 109.0.5414.74+
Fix from $1,600 2023-01-10
Merlinsboard MEDIUM 6.5
CVE-2015-10033

A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. …

Fix: 2015-03-19+
Fix from $1,600 2023-01-09
Enterprise Server MEDIUM 6.5
CVE-2022-46258

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to …

Fix: 3.3.16 / 3.4.11+
Fix from $1,600 2023-01-09
Easy Test HIGH 8.8
CVE-2022-43438

The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit th…

Fix: 22i26+
Fix from $1,950 2023-01-03
Alpine HIGH 7.5
CVE-2022-23553

Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4.…

Fix: 1.10.4+
Fix from $1,950 2022-12-28
Webpanel CRITICAL 9.8
CVE-2021-45466EPSS 55%

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an aut…

Fix: 0.9.8.1107+
Fix from $2,300 2022-12-26
Planet Estream CRITICAL 9.1
CVE-2022-45891

Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content …

Fix: 6.72.10.07+
Fix from $2,300 2022-12-25
Firefox MEDIUM 6.5
CVE-2022-38475

An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not …

Fix: 104.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22754

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grant…

Fix: 91.6 / 97.0+
Fix from $1,600 2022-12-22
Chat HIGH 8.8
CVE-2020-36625

A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocket.Upgrader of the file main.g…

Patch available
Fix from $1,950 2022-12-22
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3188

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authent…

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Pyambic Pentameter HIGH 8.8
CVE-2021-4275

A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation lea…

Patch available
Fix from $1,950 2022-12-21
Azure Ad Pod Identity MEDIUM 5.3
CVE-2022-23551

aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI comp…

Fix: 1.8.13+
Fix from $1,600 2022-12-21
Phpredisadmin HIGH 8.8
CVE-2021-4268

A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads t…

Fix: 1.18.0+
Fix from $1,950 2022-12-21
Bienlein MEDIUM 6.5
CVE-2020-36622

A vulnerability was found in sah-comp bienlein and classified as problematic. This issue affects some unknown processing. The manipulation leads to c…

Fix: 2020-09-28+
Fix from $1,600 2022-12-21
Pengu MEDIUM 6.5
CVE-2020-36623

A vulnerability was found in Pengu. It has been declared as problematic. Affected by this vulnerability is the function runApp of the file src/index.…

Fix: 2020-11-02+
Fix from $1,600 2022-12-21
Financial Transaction Manager MEDIUM 5.3
CVE-2022-43872

IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical …

Patch available
Fix from $1,600 2022-12-20
Dir 869ax Firmware HIGH 7.5
CVE-2022-46076

D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.

No fix yet
Fix from $1,950 2022-12-20
Bigbluebutton HIGH 7.5
CVE-2022-23488

BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Da…

Fix: 2.4+
Fix from $1,950 2022-12-17
Enterprise Server HIGH 7.2
CVE-2022-23741

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full ad…

Fix: 3.3.17 / 3.4.12+
Fix from $1,950 2022-12-14
Disclosure Management MEDIUM 6.5
CVE-2022-41274

SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive d…

Mitigation only
Fix from $1,600 2022-12-13
Car Dealer MEDIUM 6.5
CVE-2022-3879

The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX ac…

Fix: 3.05+
Fix from $1,600 2022-12-12
Antihacker MEDIUM 6.5
CVE-2022-3880

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper auth…

Fix: 4.20+
Fix from $1,600 2022-12-12
Wptools MEDIUM 5.7
CVE-2022-3881

The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.4…

Fix: 3.43+
Fix from $1,600 2022-12-12
Wp Memory MEDIUM 6.5
CVE-2022-3882

The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and…

Fix: 2.46+
Fix from $1,600 2022-12-12
Stopbadbots MEDIUM 6.5
CVE-2022-3883

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation an…

Fix: 7.24+
Fix from $1,600 2022-12-12
Boa MEDIUM 5.3
CVE-2022-45956

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass …

No fix yet
Fix from $1,600 2022-12-12
Sens HIGH 8.8
CVE-2022-45760

SENS v1.0 is vulnerable to Incorrect Access Control vulnerability.

No fix yet
Fix from $1,950 2022-12-12