Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Netweaver As Abap CRITICAL 9.8
CVE-2022-27668

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProute…

No fix yet
Fix from $2,300 2022-06-14
Apq8009w Firmware HIGH 7.8
CVE-2021-35112

A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, S…

Patch available
Fix from $1,950 2022-06-14
Basic Pdu Firmware HIGH 7.5
CVE-2022-33174EPSS 14%

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To ex…

Fix: 3.30.30+
Fix from $1,950 2022-06-13
Controller Cecc X M1 Firmware CRITICAL 9.8
CVE-2022-30308

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for po…

Fix: after 3.8.14
Fix from $2,300 2022-06-13
Controller Cecc X M1 Firmware CRITICAL 9.8
CVE-2022-30309

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for p…

Fix: after 3.8.14
Fix from $2,300 2022-06-13
Controller Cecc X M1 Firmware CRITICAL 9.8
CVE-2022-30310

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syn…

Fix: after 3.8.14
Fix from $2,300 2022-06-13
Controller Cecc X M1 Firmware CRITICAL 9.8
CVE-2022-30311

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syn…

Fix: after 3.8.14
Fix from $2,300 2022-06-13
GitLab MEDIUM 6.5
CVE-2022-1935

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions st…

Fix: 14.9.5 / 14.10.4+
Fix from $1,600 2022-06-06
GitLab MEDIUM 6.5
CVE-2022-1936

Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions st…

Fix: 14.9.5 / 14.10.4+
Fix from $1,600 2022-06-06
GitLab HIGH 7.1
CVE-2022-1944

When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9…

Fix: 14.9.5 / 14.10.4+
Fix from $1,950 2022-06-06
All In One Login HIGH 7.5
CVE-2022-1589

The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its se…

Fix: 1.1.0+
Fix from $1,950 2022-05-30
macOS MEDIUM 5.5
CVE-2022-26767

The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application…

Fix: 11.6.6 / 12.4+
Fix from $1,600 2022-05-26
Rescue Dispatch Management System HIGH 8.8
CVE-2022-30016

Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.

No fix yet
Fix from $1,950 2022-05-23
Spring Security CRITICAL 9.8
CVE-2022-22978EPSS 12%

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be b…

Fix: 5.5.7 / 5.6.4+
Fix from $2,300 2022-05-19
Xclarity Controller MEDIUM 5.3
CVE-2021-3956

A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting…

Fix: 1.51_tgbt24l / 2.32_psi342n+
Fix from $1,600 2022-05-18
Ignition MEDIUM 6.5
CVE-2022-1706

A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issu…

Fix: 2.14.0+
Fix from $1,600 2022-05-17
Publify MEDIUM 6.5
CVE-2022-0574

Improper Access Control in GitHub repository publify/publify prior to 9.2.8.

Fix: 9.2.8+
Fix from $1,600 2022-05-16
Minet Firmware MEDIUM 6.8
CVE-2022-29854

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker wi…

Fix: after 1.8.0.12
Fix from $1,600 2022-05-13
Eosio Batdappboomx HIGH 7.5
CVE-2022-27134

EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to wi…

No fix yet
Fix from $1,950 2022-05-13
Rubygems.org HIGH 7.5
CVE-2022-29218

RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allo…

No fix yet
Fix from $1,950 2022-05-13
Zxmp M721 Firmware HIGH 8.8
CVE-2022-23139

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent w…

Mitigation only
Fix from $1,950 2022-05-12
Otp MEDIUM 6.5
CVE-2022-24584

Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP suppo…

No fix yet
Fix from $1,600 2022-05-11
Host Agent MEDIUM 5.5
CVE-2022-28774

Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.

No fix yet
Fix from $1,600 2022-05-11
2 Factor Authentication MEDIUM 6.5
CVE-2022-28601

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone…

No fix yet
Fix from $1,600 2022-05-10
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2022-0866

This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a…

Fix: 26.1.1+
Fix from $1,600 2022-05-10
Microweber HIGH 8.8
CVE-2022-1631EPSS 9%

Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, th…

Fix: 1.2.15+
Fix from $1,950 2022-05-09
Rubygems.org HIGH 7.5
CVE-2022-29176

Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any Ruby…

Mitigation only
Fix from $1,950 2022-05-05
Konga HIGH 8.8
CVE-2021-42192EPSS 10%

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

Patch available
Fix from $1,950 2022-05-04
Rancher HIGH 7.5
CVE-2021-36778

A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to thei…

Fix: 2.5.12 / 2.6.3+
Fix from $1,950 2022-05-02
Zynq 7000s Firmware MEDIUM 6.8
CVE-2022-23822

In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading…

Fix: 2022.1+
Fix from $1,600 2022-04-27