Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2022-39030 smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, who is not explicitly authorize… Smart Evision Mitigation only Fix from $1,9502022-09-28 MEDIUM 5.3 CVE-2022-39031 Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit this vulnerability to acquire… Smart Evision Mitigation only Fix from $1,6002022-09-28 MEDIUM 6.5 CVE-2022-40816 Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see… Zammad 5.2.2+ Fix from $1,6002022-09-27 MEDIUM 6.8 CVE-2022-3048 Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscre… Chrome 105.0.5195.52+ Fix from $1,6002022-09-26 MEDIUM 5.4 CVE-2022-3024 The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated user… Simple Bitcoin Faucets after 1.7.0 Fix from $1,6002022-09-26 CRITICAL 9.8 CVE-2022-39955 The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field t… Fedora 3.2.2 / 3.3.3+ Fix from $2,3002022-09-20 CRITICAL 9.8 CVE-2022-39956 The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a ch… Fedora 3.2.2 / 3.3.3+ Fix from $2,3002022-09-20 HIGH 7.5 CVE-2022-39958 The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by… Fedora 3.2.2 / 3.3.3+ Fix from $1,9502022-09-20 CRITICAL 9.8 CVE-2022-0143 When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connecto… Ldap Connector 1.5.20.9+ Fix from $2,3002022-09-19 HIGH 7.5 CVE-2022-36074 Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to st… Nextcloud Enterprise Server 22.2.11 / 23.0.7+ Fix from $1,9502022-09-15 HIGH 8.8 CVE-2022-36103 Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepted into the Talos cluster. Due… Talos Linux 1.2.2+ Fix from $1,9502022-09-13 HIGH 7.1 CVE-2022-2989 An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data … Openshift Container Platform Patch available Fix from $1,9502022-09-13 HIGH 7.1 CVE-2022-2990 An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data… Openshift Container Platform 1.27.1+ Fix from $1,9502022-09-13 CRITICAL 9.8 CVE-2022-37767 Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disp… Pebble Templates No fix yet Fix from $2,3002022-09-12 MEDIUM 6.3 CVE-2022-36109 Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary gro… Fedora 20.10.18+ Fix from $1,6002022-09-09 HIGH 8.1 CVE-2022-23451 An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, mo… Openstack Platform 14.0.0+ Fix from $1,9502022-09-06 MEDIUM 5.4 CVE-2022-2597 The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoint… Visual Portfolio\, Photo Gallery \& Post Grid 2.19.0+ Fix from $1,6002022-09-05 HIGH 8.8 CVE-2022-36051 ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the API and **1.56.0** for Consol… Zitadel 1.87.1 / 2.2.0+ Fix from $1,9502022-08-31 HIGH 7.4 CVE-2021-3563 A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password co… Debian Linux No fix yet Fix from $1,9502022-08-26 MEDIUM 5.3 CVE-2022-35692 Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerabili… Commerce 2.4.4+ Fix from $1,6002022-08-19 HIGH 8.8 CVE-2022-36009 gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power… Dendrite after 0.9.2 Fix from $1,9502022-08-19 HIGH 7.8 CVE-2021-37409 Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalat… Wireless Ac 9560 Firmware 3.1122.1105 / 22.120+ Fix from $1,9502022-08-18 HIGH 7.5 CVE-2022-1401EPSS 18% Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticate… Cmdb 18.01.00+ Fix from $1,9502022-08-17 HIGH 8.8 CVE-2022-34255 Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerabili… Commerce 2.3.7 / 2.4.3+ Fix from $1,9502022-08-16 HIGH 8.8 CVE-2020-14321EPSS 16% In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course. Moodle 3.5.13 / 3.7.7+ Fix from $1,9502022-08-16 HIGH 7.2 CVE-2022-2354 The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installati… Wp Dbmanager 2.80.8+ Fix from $1,9502022-08-15 HIGH 7.5 CVE-2022-35487 Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abu… Zammad Mitigation only Fix from $1,9502022-08-08 HIGH 7.5 CVE-2022-2501 An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows… GitLab 15.0.5 / 15.1.4+ Fix from $1,9502022-08-05 HIGH 8.1 CVE-2022-2326 An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starti… GitLab 15.0.5 / 15.1.4+ Fix from $1,9502022-08-05 MEDIUM 6.5 CVE-2022-27551 HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. Hcl Launch 7.0.5.12 / 7.1.2.8+ Fix from $1,6002022-08-03