Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2022-1466
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was po…
Keycloak
17.0.1+
MEDIUM 5.5
CVE-2020-14121
A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, an…
Mi App Store
Mitigation only
MEDIUM 6.5
CVE-2022-24865
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrie…
Humhub
1.9.4 / 1.10.4+
HIGH 7.5
CVE-2022-27055
ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed…
Daojia
No fix yet
HIGH 8.1
CVE-2022-24841
fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this autho…
Fleet
4.13+
MEDIUM 6.5
CVE-2020-25167
OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute.
Pi Vision
3.5.0+
MEDIUM 6.5
CVE-2022-1365
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.
Cross Fetch
3.1.5+
HIGH 7.5
CVE-2021-28505
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the …
Eos
4.26.4m / 4.27.1f+
MEDIUM 5.3
CVE-2022-29047
Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or e…
Pipeline\
2.21.3 / 566.vd0a_a_3334a_555+
HIGH 7.8
CVE-2021-39799
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local esca…
Android
Patch available
HIGH 7.8
CVE-2021-39802
In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local esca…
Android
Patch available
HIGH 7.8
CVE-2021-0694
In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due …
Android
Mitigation only
MEDIUM 5.5
CVE-2022-28542
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as G…
Galaxy Store
4.5.40.5+
HIGH 7.8
CVE-2022-27836
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a…
Android
Mitigation only
HIGH 7.5
CVE-2022-0920
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow cus…
Salon Booking System
7.6.3+
CRITICAL 9.8
CVE-2022-26676
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scri…
A\+hrd
Mitigation only
MEDIUM 6.0
CVE-2022-27608
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator pri…
One Endpoint
22.01+
MEDIUM 6.0
CVE-2022-27609
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by us…
One Endpoint
22.01+
CRITICAL 9.8
CVE-2021-32986
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not…
C0 10dd1e D Firmware
3.00+
MEDIUM 5.4
CVE-2022-0825
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's book…
Amelia
1.0.49+
MEDIUM 6.5
CVE-2022-1223
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Phpipam
1.4.6+
MEDIUM 6.5
CVE-2022-1224
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Phpipam
1.4.6+
HIGH 7.5
CVE-2021-28504
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol…
Eos
4.26.4m / 4.27.1f+
HIGH 8.8
CVE-2021-32960
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that ma…
Factorytalk Services Platform
after 6.11.00
HIGH 7.5
CVE-2021-37517
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application al…
Dolibarr Erp\/crm
Patch available
HIGH 7.1
CVE-2021-3456
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that shou…
Smart Proxy Salt
after 2.1.5
HIGH 7.8
CVE-2021-39789
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no a…
Android
Mitigation only
HIGH 7.8
CVE-2021-39790
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of …
Android
Mitigation only
HIGH 7.5
CVE-2020-24771
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
Nexusphp
No fix yet
MEDIUM 5.4
CVE-2022-0720
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's book…
Amelia
1.0.47+