Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2022-1466 Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was po… Keycloak 17.0.1+ Fix from $1,6002022-04-26 MEDIUM 5.5 CVE-2020-14121 A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, an… Mi App Store Mitigation only Fix from $1,6002022-04-21 MEDIUM 6.5 CVE-2022-24865 HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrie… Humhub 1.9.4 / 1.10.4+ Fix from $1,6002022-04-20 HIGH 7.5 CVE-2022-27055 ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed… Daojia No fix yet Fix from $1,9502022-04-19 HIGH 8.1 CVE-2022-24841 fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this autho… Fleet 4.13+ Fix from $1,9502022-04-18 MEDIUM 6.5 CVE-2020-25167 OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute. Pi Vision 3.5.0+ Fix from $1,6002022-04-18 MEDIUM 6.5 CVE-2022-1365 Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5. Cross Fetch 3.1.5+ Fix from $1,6002022-04-15 HIGH 7.5 CVE-2021-28505 On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the … Eos 4.26.4m / 4.27.1f+ Fix from $1,9502022-04-14 MEDIUM 5.3 CVE-2022-29047 Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or e… Pipeline\ 2.21.3 / 566.vd0a_a_3334a_555+ Fix from $1,6002022-04-12 HIGH 7.8 CVE-2021-39799 In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local esca… Android Patch available Fix from $1,9502022-04-12 HIGH 7.8 CVE-2021-39802 In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local esca… Android Patch available Fix from $1,9502022-04-12 HIGH 7.8 CVE-2021-0694 In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due … Android Mitigation only Fix from $1,9502022-04-12 MEDIUM 5.5 CVE-2022-28542 Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as G… Galaxy Store 4.5.40.5+ Fix from $1,6002022-04-11 HIGH 7.8 CVE-2022-27836 Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a… Android Mitigation only Fix from $1,9502022-04-11 HIGH 7.5 CVE-2022-0920 The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow cus… Salon Booking System 7.6.3+ Fix from $1,9502022-04-11 CRITICAL 9.8 CVE-2022-26676 aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scri… A\+hrd Mitigation only Fix from $2,3002022-04-07 MEDIUM 6.0 CVE-2022-27608 Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator pri… One Endpoint 22.01+ Fix from $1,6002022-04-04 MEDIUM 6.0 CVE-2022-27609 Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by us… One Endpoint 22.01+ Fix from $1,6002022-04-04 CRITICAL 9.8 CVE-2021-32986 After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not… C0 10dd1e D Firmware 3.00+ Fix from $2,3002022-04-04 MEDIUM 5.4 CVE-2022-0825 The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's book… Amelia 1.0.49+ Fix from $1,6002022-04-04 MEDIUM 6.5 CVE-2022-1223 Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. Phpipam 1.4.6+ Fix from $1,6002022-04-04 MEDIUM 6.5 CVE-2022-1224 Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. Phpipam 1.4.6+ Fix from $1,6002022-04-04 HIGH 7.5 CVE-2021-28504 On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol… Eos 4.26.4m / 4.27.1f+ Fix from $1,9502022-04-01 HIGH 8.8 CVE-2021-32960 Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that ma… Factorytalk Services Platform after 6.11.00 Fix from $1,9502022-04-01 HIGH 7.5 CVE-2021-37517 An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application al… Dolibarr Erp\/crm Patch available Fix from $1,9502022-03-31 HIGH 7.1 CVE-2021-3456 An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that shou… Smart Proxy Salt after 2.1.5 Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39789 In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no a… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39790 In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of … Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.5 CVE-2020-24771 Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content. Nexusphp No fix yet Fix from $1,9502022-03-30 MEDIUM 5.4 CVE-2022-0720 The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's book… Amelia 1.0.47+ Fix from $1,6002022-03-28