Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Deno CRITICAL 10.0
CVE-2022-24783

Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where…

Fix: 1.20.3+
Fix from $2,300 2022-03-25
Openscap MEDIUM 6.1
CVE-2021-20290

An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that …

Fix: 0.9.1+
Fix from $1,600 2022-03-25
Fedora HIGH 7.5
CVE-2022-24778

The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for…

Fix: 1.1.4+
Fix from $1,950 2022-03-25
Soroushplus CRITICAL 9.1
CVE-2022-26629

An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions …

No fix yet
Fix from $2,300 2022-03-24
Argo Cd MEDIUM 6.5
CVE-2022-24730

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and …

Fix: 2.1.11 / 2.2.6+
Fix from $1,600 2022-03-23
Quarkus HIGH 8.8
CVE-2022-0981

A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This fla…

Fix: 2.7.1+
Fix from $1,950 2022-03-23
Advanced Cf7 Db HIGH 8.0
CVE-2021-24905

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX act…

Fix: 1.8.7+
Fix from $1,950 2022-03-21
Bareos CRITICAL 9.8
CVE-2022-24755

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 2…

Fix: 19.2.12 / 20.0.6+
Fix from $2,300 2022-03-15
Cometd HIGH 8.1
CVE-2022-24721

CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal usage of Oort and Seti channe…

Fix: 5.0.11 / 6.0.6+
Fix from $1,950 2022-03-15
Timescaledb HIGH 8.0
CVE-2022-24128

Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands s…

Fix: 2.5.2+
Fix from $1,950 2022-03-13
Fedora CRITICAL 9.1
CVE-2022-0860

Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

Fix: 3.3.2+
Fix from $2,300 2022-03-11
Nextcloud Server MEDIUM 5.3
CVE-2021-41233

Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application…

Fix: 20.0.14 / 21.0.6+
Fix from $1,600 2022-03-10
Luocms CRITICAL 9.8
CVE-2022-24609

Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrar…

No fix yet
Fix from $2,300 2022-03-10
Shopware HIGH 7.5
CVE-2022-24748

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possibl…

Fix: 6.4.8.2+
Fix from $1,950 2022-03-09
Easyappointments CRITICAL 9.1
CVE-2022-0482EPSS 44%

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

Fix: 1.4.3+
Fix from $2,300 2022-03-09
Icinga Web 2 MEDIUM 5.3
CVE-2022-24714

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled …

Fix: 2.8.6 / 2.9.6+
Fix from $1,600 2022-03-08
Fedora MEDIUM 6.5
CVE-2021-3658

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is …

Fix: 5.61+
Fix from $1,600 2022-03-02
Manageengine Sharepoint Manager Plus CRITICAL 9.8
CVE-2022-24306

Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.

Mitigation only
Fix from $2,300 2022-03-02
Webmin HIGH 8.8
CVE-2022-0824EPSS 97%

Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

Fix: 1.990+
Fix from $1,950 2022-03-02
Webmin HIGH 8.1
CVE-2022-0829

Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

Fix: 1.990+
Fix from $1,950 2022-03-02
Debian Linux MEDIUM 6.5
CVE-2022-0577

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.

Fix: 2.6.1+
Fix from $1,600 2022-03-02
Zulip Server CRITICAL 9.8
CVE-2022-21706

Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient acces…

Fix: 4.10.0+
Fix from $2,300 2022-02-26
Fedora HIGH 7.8
CVE-2019-25058

An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow al…

Fix: 1.1.0+
Fix from $1,950 2022-02-24
Peertube MEDIUM 5.4
CVE-2022-0727

Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

Fix: 4.1.0+
Fix from $1,600 2022-02-23
Drago HIGH 7.5
CVE-2022-25335

RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This enables token manipulation, as exploited in the wild…

Fix: after 2022-02-17
Fix from $1,950 2022-02-18
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21141

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Debian Linux HIGH 8.8
CVE-2020-25722

Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause…

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-02-18
Dart Software Development Kit MEDIUM 6.5
CVE-2022-0451

Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be e…

Fix: 2.16.0+
Fix from $1,600 2022-02-18
Updraftplus MEDIUM 6.5
CVE-2022-0633

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a…

Fix: 1.22.3 / 2.22.3+
Fix from $1,600 2022-02-17
Drupal MEDIUM 6.5
CVE-2022-25270

The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" perm…

Fix: 9.2.13 / 9.3.6+
Fix from $1,600 2022-02-17