Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Debian Linux HIGH 7.8
CVE-2021-3560 KEVEPSS 22%

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r…

Fix: 0.119+
Fix from $1,950 2022-02-16
Cloud Foundation HIGH 7.8
CVE-2021-22042

VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privile…

Fix: 4.4+
Fix from $1,950 2022-02-16
Librenms HIGH 8.8
CVE-2022-0580

Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.

Fix: 22.2.0+
Fix from $1,950 2022-02-14
Chrome MEDIUM 6.5
CVE-2022-0309

Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a cra…

Fix: 97.0.4692.99+
Fix from $1,600 2022-02-12
Chrome MEDIUM 6.5
CVE-2022-0117

Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Fix: 97.0.4692.71+
Fix from $1,600 2022-02-12
Camera MEDIUM 5.5
CVE-2022-23998

Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(…

Fix: 9.0.6.68 / 10.5.03.77+
Fix from $1,600 2022-02-11
Drupal MEDIUM 6.5
CVE-2020-13676

The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are…

Fix: 8.9.19 / 9.1.13+
Fix from $1,600 2022-02-11
Xwiki MEDIUM 5.4
CVE-2022-23615

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT ri…

Fix: 13.0+
Fix from $1,600 2022-02-09
Archisteamfarm MEDIUM 6.8
CVE-2022-23627

ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, …

Fix: 5.2.2.5 / 5.2.3.2+
Fix from $1,600 2022-02-08
Responsive Vector Maps MEDIUM 6.5
CVE-2021-24947

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in…

Fix: 6.4.2+
Fix from $1,600 2022-02-07
Northstar Club Management MEDIUM 6.5
CVE-2021-29394

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated user…

Mitigation only
Fix from $1,600 2022-02-04
Mastodon CRITICAL 9.8
CVE-2022-24307

Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD si…

Fix: 3.3.2 / 3.4.6+
Fix from $2,300 2022-02-03
Labtools MEDIUM 6.5
CVE-2021-25097

The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authent…

Fix: after 1.0
Fix from $1,600 2022-02-01
Pulsar MEDIUM 6.5
CVE-2021-41571

In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API…

Fix: 2.6.4 / 2.7.3+
Fix from $1,600 2022-02-01
Calibre Web MEDIUM 6.5
CVE-2022-0273

Improper Access Control in Pypi calibreweb prior to 0.6.16.

Fix: 0.6.16+
Fix from $1,600 2022-01-30
Cve Services HIGH 7.2
CVE-2021-46561

controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational ad…

Patch available
Fix from $1,950 2022-01-26
Big Iq Centralized Management HIGH 7.2
CVE-2022-23009

On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-I…

Mitigation only
Fix from $1,950 2022-01-25
Keycloak HIGH 8.8
CVE-2021-4133

A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default …

Fix: 15.1.1+
Fix from $1,950 2022-01-25
Host Runtime HIGH 8.1
CVE-2022-21707

wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In vers…

Fix: 0.52.2+
Fix from $1,950 2022-01-21
Cognos Controller CRITICAL 9.8
CVE-2020-4877

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo…

Mitigation only
Fix from $2,300 2022-01-21
Istio HIGH 8.8
CVE-2022-21701

Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation a…

Mitigation only
Fix from $1,950 2022-01-19
Junos CRITICAL 9.3
CVE-2022-22157

A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep …

Mitigation only
Fix from $2,300 2022-01-19
Junos CRITICAL 9.8
CVE-2022-22167

A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep …

Mitigation only
Fix from $2,300 2022-01-19
Ax3600 Firmware HIGH 7.8
CVE-2020-14110

AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web back…

Fix: 1.0.67+
Fix from $1,950 2022-01-18
Mattermost MEDIUM 6.5
CVE-2021-37864

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte…

Fix: after 6.1
Fix from $1,600 2022-01-18
Android HIGH 7.8
CVE-2021-39630

In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. T…

Mitigation only
Fix from $1,950 2022-01-14
Bookstack MEDIUM 6.5
CVE-2021-4194

bookstack is vulnerable to Improper Access Control

Fix: 21.12.1+
Fix from $1,600 2022-01-06
Kylin HIGH 7.5
CVE-2021-45457

In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and p…

Fix: 3.1.3+
Fix from $1,950 2022-01-06
Tew 827dru Firmware CRITICAL 9.8
CVE-2021-20149

Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing…

Mitigation only
Fix from $2,300 2021-12-30
Minio HIGH 8.8
CVE-2021-43858EPSS 35%

MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTT…

Fix: 2021-12-27t07-23-18z+
Fix from $1,950 2021-12-27