Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.1 CVE-2022-35924 NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in… Next Auth 3.29.10 / 4.10.3+ Fix from $2,3002022-08-02 MEDIUM 5.3 CVE-2022-31190 DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace… Dspace 6.4+ Fix from $1,6002022-08-01 MEDIUM 6.5 CVE-2022-35716 IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an au… Urbancode Deploy 6.2.7.17 / 7.0.5.12+ Fix from $1,6002022-08-01 MEDIUM 6.3 CVE-2022-1499 Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via … Chrome 101.0.4951.41+ Fix from $1,6002022-07-26 CRITICAL 9.1 CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste… Ceph Storage 5.2 / 15.2.17+ Fix from $2,3002022-07-25 CRITICAL 9.6 CVE-2022-1309 Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox… Chrome 100.0.4896.88+ Fix from $2,3002022-07-25 MEDIUM 5.3 CVE-2022-0594 The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the A… Shareaholic 9.7.6+ Fix from $1,6002022-07-25 MEDIUM 6.1 CVE-2022-1132 Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation r… Chrome 100.0.4896.60+ Fix from $1,6002022-07-23 HIGH 8.8 CVE-2022-31168 Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could cr… Zulip 5.5+ Fix from $1,9502022-07-22 HIGH 7.5 CVE-2022-34046EPSS 20% An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sy… Wn533a8 Firmware No fix yet Fix from $1,9502022-07-20 CRITICAL 9.8 CVE-2022-26479 An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes … Eagleeye Director Ii Firmware 2.2.2.1+ Fix from $2,3002022-07-17 HIGH 7.2 CVE-2022-36126 An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to ex… Ignition 7.9.20 / 8.1.17+ Fix from $1,9502022-07-16 CRITICAL 9.8 CVE-2022-35890 An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. … Ignition 7.9.20 / 8.1.17+ Fix from $2,3002022-07-15 MEDIUM 6.5 CVE-2022-31153 OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vul… Contracts Patch available Fix from $1,6002022-07-15 HIGH 7.5 CVE-2022-31107 Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a mal… Grafana 8.3.10 / 8.4.10+ Fix from $1,9502022-07-15 HIGH 7.4 CVE-2022-30203 Windows Boot Manager Security Feature Bypass Vulnerability Windows 10 Mitigation only Fix from $1,9502022-07-12 MEDIUM 6.5 CVE-2022-29619 Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002022-07-12 HIGH 7.5 CVE-2022-31139 UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data … Unsafe Accessor 1.7.0+ Fix from $1,9502022-07-11 CRITICAL 9.8 CVE-2022-32294 Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible i… Collaboration Patch available Fix from $2,3002022-07-11 CRITICAL 9.8 CVE-2022-32310 An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/cl… Ingredient Stock Management System No fix yet Fix from $2,3002022-07-05 MEDIUM 6.5 CVE-2022-29271 In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This a… Nagios Xi after 5.8.5 Fix from $1,6002022-06-29 CRITICAL 9.8 CVE-2022-32532EPSS 26% Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch… Shiro 1.9.1+ Fix from $2,3002022-06-29 HIGH 7.8 CVE-2022-31087 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,9502022-06-27 MEDIUM 5.3 CVE-2022-31039 Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though t… Greenlight 2.12.6+ Fix from $1,6002022-06-27 HIGH 7.6 CVE-2022-1746 The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cry… Imagecast X No fix yet Fix from $1,9502022-06-24 HIGH 7.5 CVE-2022-34180 Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides … Embeddable Build Status after 2.0.3 Fix from $1,9502022-06-23 HIGH 8.8 CVE-2022-22967 An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previou… Salt 3002.9 / 3003.5+ Fix from $1,9502022-06-23 HIGH 7.8 CVE-2017-20066 A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads … Adminer Login No fix yet Fix from $1,9502022-06-20 MEDIUM 6.5 CVE-2022-26668 ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform pa… Control Center Mitigation only Fix from $1,6002022-06-20 MEDIUM 6.5 CVE-2022-31589 Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than need… Erp Financial Accounting Mitigation only Fix from $1,6002022-06-14