Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.8 CVE-2022-27668 Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProute… Netweaver As Abap No fix yet Fix from $2,3002022-06-14 HIGH 7.8 CVE-2021-35112 A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, S… Apq8009w Firmware Patch available Fix from $1,9502022-06-14 HIGH 7.5 CVE-2022-33174EPSS 14% Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To ex… Basic Pdu Firmware 3.30.30+ Fix from $1,9502022-06-13 CRITICAL 9.8 CVE-2022-30308 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for po… Controller Cecc X M1 Firmware after 3.8.14 Fix from $2,3002022-06-13 CRITICAL 9.8 CVE-2022-30309 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for p… Controller Cecc X M1 Firmware after 3.8.14 Fix from $2,3002022-06-13 CRITICAL 9.8 CVE-2022-30310 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syn… Controller Cecc X M1 Firmware after 3.8.14 Fix from $2,3002022-06-13 CRITICAL 9.8 CVE-2022-30311 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syn… Controller Cecc X M1 Firmware after 3.8.14 Fix from $2,3002022-06-13 MEDIUM 6.5 CVE-2022-1935 Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions st… GitLab 14.9.5 / 14.10.4+ Fix from $1,6002022-06-06 MEDIUM 6.5 CVE-2022-1936 Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions st… GitLab 14.9.5 / 14.10.4+ Fix from $1,6002022-06-06 HIGH 7.1 CVE-2022-1944 When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9… GitLab 14.9.5 / 14.10.4+ Fix from $1,9502022-06-06 HIGH 7.5 CVE-2022-1589 The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its se… All In One Login 1.1.0+ Fix from $1,9502022-05-30 MEDIUM 5.5 CVE-2022-26767 The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application… macOS 11.6.6 / 12.4+ Fix from $1,6002022-05-26 HIGH 8.8 CVE-2022-30016 Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info. Rescue Dispatch Management System No fix yet Fix from $1,9502022-05-23 CRITICAL 9.8 CVE-2022-22978EPSS 12% In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be b… Spring Security 5.5.7 / 5.6.4+ Fix from $2,3002022-05-19 MEDIUM 5.3 CVE-2021-3956 A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting… Xclarity Controller 1.51_tgbt24l / 2.32_psi342n+ Fix from $1,6002022-05-18 MEDIUM 6.5 CVE-2022-1706 A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issu… Ignition 2.14.0+ Fix from $1,6002022-05-17 MEDIUM 6.5 CVE-2022-0574 Improper Access Control in GitHub repository publify/publify prior to 9.2.8. Publify 9.2.8+ Fix from $1,6002022-05-16 MEDIUM 6.8 CVE-2022-29854 A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker wi… Minet Firmware after 1.8.0.12 Fix from $1,6002022-05-13 HIGH 7.5 CVE-2022-27134 EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to wi… Eosio Batdappboomx No fix yet Fix from $1,9502022-05-13 HIGH 7.5 CVE-2022-29218 RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allo… Rubygems.org No fix yet Fix from $1,9502022-05-13 HIGH 8.8 CVE-2022-23139 ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent w… Zxmp M721 Firmware Mitigation only Fix from $1,9502022-05-12 MEDIUM 6.5 CVE-2022-24584 Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP suppo… Otp No fix yet Fix from $1,6002022-05-11 MEDIUM 5.5 CVE-2022-28774 Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted. Host Agent No fix yet Fix from $1,6002022-05-11 MEDIUM 6.5 CVE-2022-28601 A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone… 2 Factor Authentication No fix yet Fix from $1,6002022-05-10 MEDIUM 5.3 CVE-2022-0866 This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a… Jboss Enterprise Application Platform 26.1.1+ Fix from $1,6002022-05-10 HIGH 8.8 CVE-2022-1631EPSS 9% Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, th… Microweber 1.2.15+ Fix from $1,9502022-05-09 HIGH 7.5 CVE-2022-29176 Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any Ruby… Rubygems.org Mitigation only Fix from $1,9502022-05-05 HIGH 8.8 CVE-2021-42192EPSS 10% Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation. Konga Patch available Fix from $1,9502022-05-04 HIGH 7.5 CVE-2021-36778 A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to thei… Rancher 2.5.12 / 2.6.3+ Fix from $1,9502022-05-02 MEDIUM 6.8 CVE-2022-23822 In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading… Zynq 7000s Firmware 2022.1+ Fix from $1,6002022-04-27