Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Next Auth CRITICAL 9.1
CVE-2022-35924

NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in…

Fix: 3.29.10 / 4.10.3+
Fix from $2,300 2022-08-02
Dspace MEDIUM 5.3
CVE-2022-31190

DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace…

Fix: 6.4+
Fix from $1,600 2022-08-01
Urbancode Deploy MEDIUM 6.5
CVE-2022-35716

IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an au…

Fix: 6.2.7.17 / 7.0.5.12+
Fix from $1,600 2022-08-01
Chrome MEDIUM 6.3
CVE-2022-1499

Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via …

Fix: 101.0.4951.41+
Fix from $1,600 2022-07-26
Ceph Storage CRITICAL 9.1
CVE-2022-0670

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste…

Fix: 5.2 / 15.2.17+
Fix from $2,300 2022-07-25
Chrome CRITICAL 9.6
CVE-2022-1309

Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox…

Fix: 100.0.4896.88+
Fix from $2,300 2022-07-25
Shareaholic MEDIUM 5.3
CVE-2022-0594

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the A…

Fix: 9.7.6+
Fix from $1,600 2022-07-25
Chrome MEDIUM 6.1
CVE-2022-1132

Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation r…

Fix: 100.0.4896.60+
Fix from $1,600 2022-07-23
Zulip HIGH 8.8
CVE-2022-31168

Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could cr…

Fix: 5.5+
Fix from $1,950 2022-07-22
Wn533a8 Firmware HIGH 7.5
CVE-2022-34046EPSS 20%

An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sy…

No fix yet
Fix from $1,950 2022-07-20
Eagleeye Director Ii Firmware CRITICAL 9.8
CVE-2022-26479

An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes …

Fix: 2.2.2.1+
Fix from $2,300 2022-07-17
Ignition HIGH 7.2
CVE-2022-36126

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to ex…

Fix: 7.9.20 / 8.1.17+
Fix from $1,950 2022-07-16
Ignition CRITICAL 9.8
CVE-2022-35890

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. …

Fix: 7.9.20 / 8.1.17+
Fix from $2,300 2022-07-15
Contracts MEDIUM 6.5
CVE-2022-31153

OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vul…

Patch available
Fix from $1,600 2022-07-15
Grafana HIGH 7.5
CVE-2022-31107

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a mal…

Fix: 8.3.10 / 8.4.10+
Fix from $1,950 2022-07-15
Windows 10 HIGH 7.4
CVE-2022-30203

Windows Boot Manager Security Feature Bypass Vulnerability

Mitigation only
Fix from $1,950 2022-07-12
Businessobjects Business Intelligence Platform MEDIUM 6.5
CVE-2022-29619

Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify …

Mitigation only
Fix from $1,600 2022-07-12
Unsafe Accessor HIGH 7.5
CVE-2022-31139

UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data …

Fix: 1.7.0+
Fix from $1,950 2022-07-11
Collaboration CRITICAL 9.8
CVE-2022-32294

Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible i…

Patch available
Fix from $2,300 2022-07-11
Ingredient Stock Management System CRITICAL 9.8
CVE-2022-32310

An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/cl…

No fix yet
Fix from $2,300 2022-07-05
Nagios Xi MEDIUM 6.5
CVE-2022-29271

In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This a…

Fix: after 5.8.5
Fix from $1,600 2022-06-29
Shiro CRITICAL 9.8
CVE-2022-32532EPSS 26%

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…

Fix: 1.9.1+
Fix from $2,300 2022-06-29
Debian Linux HIGH 7.8
CVE-2022-31087

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Greenlight MEDIUM 5.3
CVE-2022-31039

Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though t…

Fix: 2.12.6+
Fix from $1,600 2022-06-27
Imagecast X HIGH 7.6
CVE-2022-1746

The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cry…

No fix yet
Fix from $1,950 2022-06-24
Embeddable Build Status HIGH 7.5
CVE-2022-34180

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides …

Fix: after 2.0.3
Fix from $1,950 2022-06-23
Salt HIGH 8.8
CVE-2022-22967

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previou…

Fix: 3002.9 / 3003.5+
Fix from $1,950 2022-06-23
Adminer Login HIGH 7.8
CVE-2017-20066

A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads …

No fix yet
Fix from $1,950 2022-06-20
Control Center MEDIUM 6.5
CVE-2022-26668

ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform pa…

Mitigation only
Fix from $1,600 2022-06-20
Erp Financial Accounting MEDIUM 6.5
CVE-2022-31589

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than need…

Mitigation only
Fix from $1,600 2022-06-14