Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-27668
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProute…
Netweaver As Abap
No fix yet
HIGH 7.8
CVE-2021-35112
A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, S…
Apq8009w Firmware
Patch available
HIGH 7.5
CVE-2022-33174EPSS 14%
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To ex…
Basic Pdu Firmware
3.30.30+
CRITICAL 9.8
CVE-2022-30308
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for po…
Controller Cecc X M1 Firmware
after 3.8.14
CRITICAL 9.8
CVE-2022-30309
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for p…
Controller Cecc X M1 Firmware
after 3.8.14
CRITICAL 9.8
CVE-2022-30310
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syn…
Controller Cecc X M1 Firmware
after 3.8.14
CRITICAL 9.8
CVE-2022-30311
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syn…
Controller Cecc X M1 Firmware
after 3.8.14
MEDIUM 6.5
CVE-2022-1935
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions st…
GitLab
14.9.5 / 14.10.4+
MEDIUM 6.5
CVE-2022-1936
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions st…
GitLab
14.9.5 / 14.10.4+
HIGH 7.1
CVE-2022-1944
When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9…
GitLab
14.9.5 / 14.10.4+
HIGH 7.5
CVE-2022-1589
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its se…
All In One Login
1.1.0+
MEDIUM 5.5
CVE-2022-26767
The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application…
macOS
11.6.6 / 12.4+
HIGH 8.8
CVE-2022-30016
Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.
Rescue Dispatch Management System
No fix yet
CRITICAL 9.8
CVE-2022-22978EPSS 12%
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be b…
Spring Security
5.5.7 / 5.6.4+
MEDIUM 5.3
CVE-2021-3956
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting…
Xclarity Controller
1.51_tgbt24l / 2.32_psi342n+
MEDIUM 6.5
CVE-2022-1706
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issu…
Ignition
2.14.0+
MEDIUM 6.5
CVE-2022-0574
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
Publify
9.2.8+
MEDIUM 6.8
CVE-2022-29854
A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker wi…
Minet Firmware
after 1.8.0.12
HIGH 7.5
CVE-2022-27134
EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to wi…
Eosio Batdappboomx
No fix yet
HIGH 7.5
CVE-2022-29218
RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allo…
Rubygems.org
No fix yet
HIGH 8.8
CVE-2022-23139
ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent w…
Zxmp M721 Firmware
Mitigation only
MEDIUM 6.5
CVE-2022-24584
Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP suppo…
Otp
No fix yet
MEDIUM 5.5
CVE-2022-28774
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.
Host Agent
No fix yet
MEDIUM 6.5
CVE-2022-28601
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone…
2 Factor Authentication
No fix yet
MEDIUM 5.3
CVE-2022-0866
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a…
Jboss Enterprise Application Platform
26.1.1+
HIGH 8.8
CVE-2022-1631EPSS 9%
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, th…
Microweber
1.2.15+
HIGH 7.5
CVE-2022-29176
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any Ruby…
Rubygems.org
Mitigation only
HIGH 8.8
CVE-2021-42192EPSS 10%
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.
Konga
Patch available
HIGH 7.5
CVE-2021-36778
A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to thei…
Rancher
2.5.12 / 2.6.3+
MEDIUM 6.8
CVE-2022-23822
In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading…
Zynq 7000s Firmware
2022.1+