Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2022-4167 Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows g… GitLab 15.5.7 / 15.6.4+ Fix from $1,9502023-01-12 MEDIUM 6.6 CVE-2023-21560 Windows Boot Manager Security Feature Bypass Vulnerability Windows 10 1607 No fix yet Fix from $1,6002023-01-10 MEDIUM 6.5 CVE-2023-0133 Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main ori… Chrome 109.0.5414.74+ Fix from $1,6002023-01-10 MEDIUM 6.5 CVE-2015-10033 A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. … Merlinsboard 2015-03-19+ Fix from $1,6002023-01-09 MEDIUM 6.5 CVE-2022-46258 An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to … Enterprise Server 3.3.16 / 3.4.11+ Fix from $1,6002023-01-09 HIGH 8.8 CVE-2022-43438 The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit th… Easy Test 22i26+ Fix from $1,9502023-01-03 HIGH 7.5 CVE-2022-23553 Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4.… Alpine 1.10.4+ Fix from $1,9502022-12-28 CRITICAL 9.8 CVE-2021-45466EPSS 55% In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an aut… Webpanel 0.9.8.1107+ Fix from $2,3002022-12-26 CRITICAL 9.1 CVE-2022-45891 Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content … Planet Estream 6.72.10.07+ Fix from $2,3002022-12-25 MEDIUM 6.5 CVE-2022-38475 An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not … Firefox 104.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-22754 If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grant… Firefox 91.6 / 97.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2020-36625 A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocket.Upgrader of the file main.g… Chat Patch available Fix from $1,9502022-12-22 MEDIUM 5.3 CVE-2022-3188 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authent… Iboot Pdu4 N20 Firmware 1.42.06162022+ Fix from $1,6002022-12-21 HIGH 8.8 CVE-2021-4275 A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation lea… Pyambic Pentameter Patch available Fix from $1,9502022-12-21 MEDIUM 5.3 CVE-2022-23551 aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI comp… Azure Ad Pod Identity 1.8.13+ Fix from $1,6002022-12-21 HIGH 8.8 CVE-2021-4268 A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads t… Phpredisadmin 1.18.0+ Fix from $1,9502022-12-21 MEDIUM 6.5 CVE-2020-36622 A vulnerability was found in sah-comp bienlein and classified as problematic. This issue affects some unknown processing. The manipulation leads to c… Bienlein 2020-09-28+ Fix from $1,6002022-12-21 MEDIUM 6.5 CVE-2020-36623 A vulnerability was found in Pengu. It has been declared as problematic. Affected by this vulnerability is the function runApp of the file src/index.… Pengu 2020-11-02+ Fix from $1,6002022-12-21 MEDIUM 5.3 CVE-2022-43872 IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical … Financial Transaction Manager Patch available Fix from $1,6002022-12-20 HIGH 7.5 CVE-2022-46076 D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi. Dir 869ax Firmware No fix yet Fix from $1,9502022-12-20 HIGH 7.5 CVE-2022-23488 BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Da… Bigbluebutton 2.4+ Fix from $1,9502022-12-17 HIGH 7.2 CVE-2022-23741 An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full ad… Enterprise Server 3.3.17 / 3.4.12+ Fix from $1,9502022-12-14 MEDIUM 6.5 CVE-2022-41274 SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive d… Disclosure Management Mitigation only Fix from $1,6002022-12-13 MEDIUM 6.5 CVE-2022-3879 The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX ac… Car Dealer 3.05+ Fix from $1,6002022-12-12 MEDIUM 6.5 CVE-2022-3880 The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper auth… Antihacker 4.20+ Fix from $1,6002022-12-12 MEDIUM 5.7 CVE-2022-3881 The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.4… Wptools 3.43+ Fix from $1,6002022-12-12 MEDIUM 6.5 CVE-2022-3882 The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and… Wp Memory 2.46+ Fix from $1,6002022-12-12 MEDIUM 6.5 CVE-2022-3883 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation an… Stopbadbots 7.24+ Fix from $1,6002022-12-12 MEDIUM 5.3 CVE-2022-45956 Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass … Boa No fix yet Fix from $1,6002022-12-12 HIGH 8.8 CVE-2022-45760 SENS v1.0 is vulnerable to Incorrect Access Control vulnerability. Sens No fix yet Fix from $1,9502022-12-12