Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Keycloak MEDIUM 6.5
CVE-2022-1466

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was po…

Fix: 17.0.1+
Fix from $1,600 2022-04-26
Mi App Store MEDIUM 5.5
CVE-2020-14121

A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, an…

Mitigation only
Fix from $1,600 2022-04-21
Humhub MEDIUM 6.5
CVE-2022-24865

HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrie…

Fix: 1.9.4 / 1.10.4+
Fix from $1,600 2022-04-20
Daojia HIGH 7.5
CVE-2022-27055

ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed…

No fix yet
Fix from $1,950 2022-04-19
Fleet HIGH 8.1
CVE-2022-24841

fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this autho…

Fix: 4.13+
Fix from $1,950 2022-04-18
Pi Vision MEDIUM 6.5
CVE-2020-25167

OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute.

Fix: 3.5.0+
Fix from $1,600 2022-04-18
Cross Fetch MEDIUM 6.5
CVE-2022-1365

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.

Fix: 3.1.5+
Fix from $1,600 2022-04-15
Eos HIGH 7.5
CVE-2021-28505

On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the …

Fix: 4.26.4m / 4.27.1f+
Fix from $1,950 2022-04-14
Pipeline\ MEDIUM 5.3
CVE-2022-29047

Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or e…

Fix: 2.21.3 / 566.vd0a_a_3334a_555+
Fix from $1,600 2022-04-12
Android HIGH 7.8
CVE-2021-39799

In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local esca…

Patch available
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-39802

In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local esca…

Patch available
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-0694

In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due …

Mitigation only
Fix from $1,950 2022-04-12
Galaxy Store MEDIUM 5.5
CVE-2022-28542

Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as G…

Fix: 4.5.40.5+
Fix from $1,600 2022-04-11
Android HIGH 7.8
CVE-2022-27836

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a…

Mitigation only
Fix from $1,950 2022-04-11
Salon Booking System HIGH 7.5
CVE-2022-0920

The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow cus…

Fix: 7.6.3+
Fix from $1,950 2022-04-11
A\+hrd CRITICAL 9.8
CVE-2022-26676

aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scri…

Mitigation only
Fix from $2,300 2022-04-07
One Endpoint MEDIUM 6.0
CVE-2022-27608

Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator pri…

Fix: 22.01+
Fix from $1,600 2022-04-04
One Endpoint MEDIUM 6.0
CVE-2022-27609

Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by us…

Fix: 22.01+
Fix from $1,600 2022-04-04
C0 10dd1e D Firmware CRITICAL 9.8
CVE-2021-32986

After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not…

Fix: 3.00+
Fix from $2,300 2022-04-04
Amelia MEDIUM 5.4
CVE-2022-0825

The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's book…

Fix: 1.0.49+
Fix from $1,600 2022-04-04
Phpipam MEDIUM 6.5
CVE-2022-1223

Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

Fix: 1.4.6+
Fix from $1,600 2022-04-04
Phpipam MEDIUM 6.5
CVE-2022-1224

Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

Fix: 1.4.6+
Fix from $1,600 2022-04-04
Eos HIGH 7.5
CVE-2021-28504

On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol…

Fix: 4.26.4m / 4.27.1f+
Fix from $1,950 2022-04-01
Factorytalk Services Platform HIGH 8.8
CVE-2021-32960

Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that ma…

Fix: after 6.11.00
Fix from $1,950 2022-04-01
Dolibarr Erp\/crm HIGH 7.5
CVE-2021-37517

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application al…

Patch available
Fix from $1,950 2022-03-31
Smart Proxy Salt HIGH 7.1
CVE-2021-3456

An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that shou…

Fix: after 2.1.5
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39789

In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no a…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39790

In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of …

Mitigation only
Fix from $1,950 2022-03-30
Nexusphp HIGH 7.5
CVE-2020-24771

Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.

No fix yet
Fix from $1,950 2022-03-30
Amelia MEDIUM 5.4
CVE-2022-0720

The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's book…

Fix: 1.0.47+
Fix from $1,600 2022-03-28