Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Zend Blog 2 MEDIUM 6.5
CVE-2022-4397

A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file applicati…

Patch available
Fix from $1,600 2022-12-10
Duxcms HIGH 8.0
CVE-2020-36610

A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation lead…

No fix yet
Fix from $1,950 2022-12-08
Pwn MEDIUM 6.8
CVE-2022-4349

A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation le…

No fix yet
Fix from $1,600 2022-12-08
Graphql Engine HIGH 8.8
CVE-2022-46792

Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2…

Fix: 2.10.2 / 2.11.3+
Fix from $1,950 2022-12-08
Colibri Firmware CRITICAL 9.8
CVE-2022-44039

Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker ca…

No fix yet
Fix from $2,300 2022-12-05
Cacti CRITICAL 9.8
CVE-2022-46169 KEVEPSS 100%

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected …

Fix: 1.2.23+
Fix from $2,300 2022-12-05
Frontend CRITICAL 9.8
CVE-2022-43515

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this w…

Fix: after 6.2.4
Fix from $2,300 2022-12-05
Capsule HIGH 8.8
CVE-2022-46167

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when g…

Fix: 0.1.3+
Fix from $1,950 2022-12-02
Nextcloud Server MEDIUM 5.3
CVE-2022-41970

Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through …

Fix: 24.0.7+
Fix from $1,600 2022-12-01
Ourphoto MEDIUM 6.5
CVE-2022-24189

The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value causes all …

No fix yet
Fix from $1,600 2022-11-28
Stock Management System HIGH 8.8
CVE-2022-4090

A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_…

No fix yet
Fix from $1,950 2022-11-24
Spring Security Core CRITICAL 9.8
CVE-2022-41923

Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targe…

Fix: 3.3.2 / 4.0.5+
Fix from $2,300 2022-11-23
G Integrated Access Device4 Firmware HIGH 7.5
CVE-2022-36785

D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at…

Mitigation only
Fix from $1,950 2022-11-17
Hospital Management Center HIGH 8.8
CVE-2022-4013

A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the …

No fix yet
Fix from $1,950 2022-11-16
Opensearch MEDIUM 6.3
CVE-2022-41918

OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access cont…

Fix: 1.3.7 / 2.4.0+
Fix from $1,600 2022-11-15
Adaptive Security Appliance Software MEDIUM 5.8
CVE-2022-20928

A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower T…

Mitigation only
Fix from $1,600 2022-11-15
Support Core MEDIUM 6.5
CVE-2022-45383

An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission…

Fix: 1206.1208.v9b_7a_1d48db_0f+
Fix from $1,600 2022-11-15
Confluence Data Center HIGH 7.5
CVE-2022-42978

In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on…

Fix: 1.3.5+
Fix from $1,950 2022-11-15
Discourse MEDIUM 6.5
CVE-2022-39385

Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several privat…

Fix: 2.8.10+
Fix from $1,600 2022-11-14
Windows 10 1507 MEDIUM 5.4
CVE-2022-41091 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Fix: 10.0.10240.19567 / 10.0.14393.5501+
Fix from $1,600 2022-11-09
Openfga CRITICAL 9.8
CVE-2022-39352

OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization by…

Fix: 0.2.5+
Fix from $2,300 2022-11-08
Asyncos MEDIUM 6.5
CVE-2022-20942

A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure W…

Fix: 12.0.5-011 / 12.5.4-005+
Fix from $1,600 2022-11-04
macOS MEDIUM 5.5
CVE-2022-42788

A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Ventura 13. A malicious appli…

Fix: 13.0+
Fix from $1,600 2022-11-01
Keystone CRITICAL 9.8
CVE-2022-39322

@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, u…

Fix: 2.3.1+
Fix from $2,300 2022-10-25
Commerce HIGH 8.8
CVE-2022-42344

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerabili…

Fix: 2.3.7 / 2.4.3+
Fix from $1,950 2022-10-20
Phoenix HIGH 7.5
CVE-2022-42975

socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of th…

Fix: 1.6.14+
Fix from $1,950 2022-10-17
Ree6 MEDIUM 5.4
CVE-2022-39302

Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a …

Fix: 1.9.9+
Fix from $1,600 2022-10-14
Enterprise HIGH 7.5
CVE-2022-41574

An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emai…

Fix: 2022.3.2+
Fix from $1,950 2022-10-07
Zkbiosecurity V5000 HIGH 8.8
CVE-2022-36634

An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.

Mitigation only
Fix from $1,950 2022-10-07
Smart Evision MEDIUM 6.5
CVE-2022-39029

Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privilege, who is not explicitly auth…

Fix: after 2022.02.21
Fix from $1,600 2022-09-28