Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2022-4397 A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file applicati… Zend Blog 2 Patch available Fix from $1,6002022-12-10 HIGH 8.0 CVE-2020-36610 A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation lead… Duxcms No fix yet Fix from $1,9502022-12-08 MEDIUM 6.8 CVE-2022-4349 A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation le… Pwn No fix yet Fix from $1,6002022-12-08 HIGH 8.8 CVE-2022-46792 Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2… Graphql Engine 2.10.2 / 2.11.3+ Fix from $1,9502022-12-08 CRITICAL 9.8 CVE-2022-44039 Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker ca… Colibri Firmware No fix yet Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-46169 KEVEPSS 100% Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected … Cacti 1.2.23+ Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-43515 Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this w… Frontend after 6.2.4 Fix from $2,3002022-12-05 HIGH 8.8 CVE-2022-46167 Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when g… Capsule 0.1.3+ Fix from $1,9502022-12-02 MEDIUM 5.3 CVE-2022-41970 Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through … Nextcloud Server 24.0.7+ Fix from $1,6002022-12-01 MEDIUM 6.5 CVE-2022-24189 The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value causes all … Ourphoto No fix yet Fix from $1,6002022-11-28 HIGH 8.8 CVE-2022-4090 A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_… Stock Management System No fix yet Fix from $1,9502022-11-24 CRITICAL 9.8 CVE-2022-41923 Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targe… Spring Security Core 3.3.2 / 4.0.5+ Fix from $2,3002022-11-23 HIGH 7.5 CVE-2022-36785 D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at… G Integrated Access Device4 Firmware Mitigation only Fix from $1,9502022-11-17 HIGH 8.8 CVE-2022-4013 A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the … Hospital Management Center No fix yet Fix from $1,9502022-11-16 MEDIUM 6.3 CVE-2022-41918 OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access cont… Opensearch 1.3.7 / 2.4.0+ Fix from $1,6002022-11-15 MEDIUM 5.8 CVE-2022-20928 A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower T… Adaptive Security Appliance Software Mitigation only Fix from $1,6002022-11-15 MEDIUM 6.5 CVE-2022-45383 An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission… Support Core 1206.1208.v9b_7a_1d48db_0f+ Fix from $1,6002022-11-15 HIGH 7.5 CVE-2022-42978 In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on… Confluence Data Center 1.3.5+ Fix from $1,9502022-11-15 MEDIUM 6.5 CVE-2022-39385 Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several privat… Discourse 2.8.10+ Fix from $1,6002022-11-14 MEDIUM 5.4 CVE-2022-41091 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19567 / 10.0.14393.5501+ Fix from $1,6002022-11-09 CRITICAL 9.8 CVE-2022-39352 OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization by… Openfga 0.2.5+ Fix from $2,3002022-11-08 MEDIUM 6.5 CVE-2022-20942 A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure W… Asyncos 12.0.5-011 / 12.5.4-005+ Fix from $1,6002022-11-04 MEDIUM 5.5 CVE-2022-42788 A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Ventura 13. A malicious appli… macOS 13.0+ Fix from $1,6002022-11-01 CRITICAL 9.8 CVE-2022-39322 @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, u… Keystone 2.3.1+ Fix from $2,3002022-10-25 HIGH 8.8 CVE-2022-42344 Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerabili… Commerce 2.3.7 / 2.4.3+ Fix from $1,9502022-10-20 HIGH 7.5 CVE-2022-42975 socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of th… Phoenix 1.6.14+ Fix from $1,9502022-10-17 MEDIUM 5.4 CVE-2022-39302 Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a … Ree6 1.9.9+ Fix from $1,6002022-10-14 HIGH 7.5 CVE-2022-41574 An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emai… Enterprise 2022.3.2+ Fix from $1,9502022-10-07 HIGH 8.8 CVE-2022-36634 An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request. Zkbiosecurity V5000 Mitigation only Fix from $1,9502022-10-07 MEDIUM 6.5 CVE-2022-39029 Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privilege, who is not explicitly auth… Smart Evision after 2022.02.21 Fix from $1,6002022-09-28