Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 10.0 CVE-2022-24783 Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where… Deno 1.20.3+ Fix from $2,3002022-03-25 MEDIUM 6.1 CVE-2021-20290 An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that … Openscap 0.9.1+ Fix from $1,6002022-03-25 HIGH 7.5 CVE-2022-24778 The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for… Fedora 1.1.4+ Fix from $1,9502022-03-25 CRITICAL 9.1 CVE-2022-26629 An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions … Soroushplus No fix yet Fix from $2,3002022-03-24 MEDIUM 6.5 CVE-2022-24730 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and … Argo Cd 2.1.11 / 2.2.6+ Fix from $1,6002022-03-23 HIGH 8.8 CVE-2022-0981 A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This fla… Quarkus 2.7.1+ Fix from $1,9502022-03-23 HIGH 8.0 CVE-2021-24905 The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX act… Advanced Cf7 Db 1.8.7+ Fix from $1,9502022-03-21 CRITICAL 9.8 CVE-2022-24755 Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 2… Bareos 19.2.12 / 20.0.6+ Fix from $2,3002022-03-15 HIGH 8.1 CVE-2022-24721 CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal usage of Oort and Seti channe… Cometd 5.0.11 / 6.0.6+ Fix from $1,9502022-03-15 HIGH 8.0 CVE-2022-24128 Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands s… Timescaledb 2.5.2+ Fix from $1,9502022-03-13 CRITICAL 9.1 CVE-2022-0860 Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2. Fedora 3.3.2+ Fix from $2,3002022-03-11 MEDIUM 5.3 CVE-2021-41233 Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application… Nextcloud Server 20.0.14 / 21.0.6+ Fix from $1,6002022-03-10 CRITICAL 9.8 CVE-2022-24609 Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrar… Luocms No fix yet Fix from $2,3002022-03-10 HIGH 7.5 CVE-2022-24748 Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possibl… Shopware 6.4.8.2+ Fix from $1,9502022-03-09 CRITICAL 9.1 CVE-2022-0482EPSS 44% Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. Easyappointments 1.4.3+ Fix from $2,3002022-03-09 MEDIUM 5.3 CVE-2022-24714 Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled … Icinga Web 2 2.8.6 / 2.9.6+ Fix from $1,6002022-03-08 MEDIUM 6.5 CVE-2021-3658 bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is … Fedora 5.61+ Fix from $1,6002022-03-02 CRITICAL 9.8 CVE-2022-24306 Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. Manageengine Sharepoint Manager Plus Mitigation only Fix from $2,3002022-03-02 HIGH 8.8 CVE-2022-0824EPSS 97% Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990. Webmin 1.990+ Fix from $1,9502022-03-02 HIGH 8.1 CVE-2022-0829 Improper Authorization in GitHub repository webmin/webmin prior to 1.990. Webmin 1.990+ Fix from $1,9502022-03-02 MEDIUM 6.5 CVE-2022-0577 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1. Debian Linux 2.6.1+ Fix from $1,6002022-03-02 CRITICAL 9.8 CVE-2022-21706 Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient acces… Zulip Server 4.10.0+ Fix from $2,3002022-02-26 HIGH 7.8 CVE-2019-25058 An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow al… Fedora 1.1.0+ Fix from $1,9502022-02-24 MEDIUM 5.4 CVE-2022-0727 Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0. Peertube 4.1.0+ Fix from $1,6002022-02-23 HIGH 7.5 CVE-2022-25335 RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This enables token manipulation, as exploited in the wild… Drago after 2022-02-17 Fix from $1,9502022-02-18 CRITICAL 9.8 CVE-2022-21141 MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does… Mimosa Management Platform 1.0.3 / 2.5.4.1+ Fix from $2,3002022-02-18 HIGH 8.8 CVE-2020-25722 Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause… Debian Linux 4.13.14 / 4.14.10+ Fix from $1,9502022-02-18 MEDIUM 6.5 CVE-2022-0451 Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be e… Dart Software Development Kit 2.16.0+ Fix from $1,6002022-02-18 MEDIUM 6.5 CVE-2022-0633 The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a… Updraftplus 1.22.3 / 2.22.3+ Fix from $1,6002022-02-17 MEDIUM 6.5 CVE-2022-25270 The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" perm… Drupal 9.2.13 / 9.3.6+ Fix from $1,6002022-02-17