Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Smart Evision HIGH 7.5
CVE-2022-39030

smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, who is not explicitly authorize…

Mitigation only
Fix from $1,950 2022-09-28
Smart Evision MEDIUM 5.3
CVE-2022-39031

Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit this vulnerability to acquire…

Mitigation only
Fix from $1,600 2022-09-28
Zammad MEDIUM 6.5
CVE-2022-40816

Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see…

Fix: 5.2.2+
Fix from $1,600 2022-09-27
Chrome MEDIUM 6.8
CVE-2022-3048

Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscre…

Fix: 105.0.5195.52+
Fix from $1,600 2022-09-26
Simple Bitcoin Faucets MEDIUM 5.4
CVE-2022-3024

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated user…

Fix: after 1.7.0
Fix from $1,600 2022-09-26
Fedora CRITICAL 9.8
CVE-2022-39955

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field t…

Fix: 3.2.2 / 3.3.3+
Fix from $2,300 2022-09-20
Fedora CRITICAL 9.8
CVE-2022-39956

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a ch…

Fix: 3.2.2 / 3.3.3+
Fix from $2,300 2022-09-20
Fedora HIGH 7.5
CVE-2022-39958

The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by…

Fix: 3.2.2 / 3.3.3+
Fix from $1,950 2022-09-20
Ldap Connector CRITICAL 9.8
CVE-2022-0143

When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connecto…

Fix: 1.5.20.9+
Fix from $2,300 2022-09-19
Nextcloud Enterprise Server HIGH 7.5
CVE-2022-36074

Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to st…

Fix: 22.2.11 / 23.0.7+
Fix from $1,950 2022-09-15
Talos Linux HIGH 8.8
CVE-2022-36103

Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepted into the Talos cluster. Due…

Fix: 1.2.2+
Fix from $1,950 2022-09-13
Openshift Container Platform HIGH 7.1
CVE-2022-2989

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data …

Patch available
Fix from $1,950 2022-09-13
Openshift Container Platform HIGH 7.1
CVE-2022-2990

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data…

Fix: 1.27.1+
Fix from $1,950 2022-09-13
Pebble Templates CRITICAL 9.8
CVE-2022-37767

Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disp…

No fix yet
Fix from $2,300 2022-09-12
Fedora MEDIUM 6.3
CVE-2022-36109

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary gro…

Fix: 20.10.18+
Fix from $1,600 2022-09-09
Openstack Platform HIGH 8.1
CVE-2022-23451

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, mo…

Fix: 14.0.0+
Fix from $1,950 2022-09-06
Visual Portfolio\, Photo Gallery \& Post Grid MEDIUM 5.4
CVE-2022-2597

The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoint…

Fix: 2.19.0+
Fix from $1,600 2022-09-05
Zitadel HIGH 8.8
CVE-2022-36051

ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the API and **1.56.0** for Consol…

Fix: 1.87.1 / 2.2.0+
Fix from $1,950 2022-08-31
Debian Linux HIGH 7.4
CVE-2021-3563

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password co…

No fix yet
Fix from $1,950 2022-08-26
Commerce MEDIUM 5.3
CVE-2022-35692

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerabili…

Fix: 2.4.4+
Fix from $1,600 2022-08-19
Dendrite HIGH 8.8
CVE-2022-36009

gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power…

Fix: after 0.9.2
Fix from $1,950 2022-08-19
Wireless Ac 9560 Firmware HIGH 7.8
CVE-2021-37409

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalat…

Fix: 3.1122.1105 / 22.120+
Fix from $1,950 2022-08-18
Cmdb HIGH 7.5
CVE-2022-1401EPSS 18%

Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticate…

Fix: 18.01.00+
Fix from $1,950 2022-08-17
Commerce HIGH 8.8
CVE-2022-34255

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerabili…

Fix: 2.3.7 / 2.4.3+
Fix from $1,950 2022-08-16
Moodle HIGH 8.8
CVE-2020-14321EPSS 16%

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

Fix: 3.5.13 / 3.7.7+
Fix from $1,950 2022-08-16
Wp Dbmanager HIGH 7.2
CVE-2022-2354

The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installati…

Fix: 2.80.8+
Fix from $1,950 2022-08-15
Zammad HIGH 7.5
CVE-2022-35487

Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abu…

Mitigation only
Fix from $1,950 2022-08-08
GitLab HIGH 7.5
CVE-2022-2501

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows…

Fix: 15.0.5 / 15.1.4+
Fix from $1,950 2022-08-05
GitLab HIGH 8.1
CVE-2022-2326

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starti…

Fix: 15.0.5 / 15.1.4+
Fix from $1,950 2022-08-05
Hcl Launch MEDIUM 6.5
CVE-2022-27551

HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.

Fix: 7.0.5.12 / 7.1.2.8+
Fix from $1,600 2022-08-03