Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.8 CVE-2021-3560 KEVEPSS 22% It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r… Debian Linux 0.119+ Fix from $1,9502022-02-16 HIGH 7.8 CVE-2021-22042 VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privile… Cloud Foundation 4.4+ Fix from $1,9502022-02-16 HIGH 8.8 CVE-2022-0580 Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0. Librenms 22.2.0+ Fix from $1,9502022-02-14 MEDIUM 6.5 CVE-2022-0309 Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a cra… Chrome 97.0.4692.99+ Fix from $1,6002022-02-12 MEDIUM 6.5 CVE-2022-0117 Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Chrome 97.0.4692.71+ Fix from $1,6002022-02-12 MEDIUM 5.5 CVE-2022-23998 Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(… Camera 9.0.6.68 / 10.5.03.77+ Fix from $1,6002022-02-11 MEDIUM 6.5 CVE-2020-13676 The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are… Drupal 8.9.19 / 9.1.13+ Fix from $1,6002022-02-11 MEDIUM 5.4 CVE-2022-23615 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT ri… Xwiki 13.0+ Fix from $1,6002022-02-09 MEDIUM 6.8 CVE-2022-23627 ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, … Archisteamfarm 5.2.2.5 / 5.2.3.2+ Fix from $1,6002022-02-08 MEDIUM 6.5 CVE-2021-24947 The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in… Responsive Vector Maps 6.4.2+ Fix from $1,6002022-02-07 MEDIUM 6.5 CVE-2021-29394 Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated user… Northstar Club Management Mitigation only Fix from $1,6002022-02-04 CRITICAL 9.8 CVE-2022-24307 Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD si… Mastodon 3.3.2 / 3.4.6+ Fix from $2,3002022-02-03 MEDIUM 6.5 CVE-2021-25097 The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authent… Labtools after 1.0 Fix from $1,6002022-02-01 MEDIUM 6.5 CVE-2021-41571 In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API… Pulsar 2.6.4 / 2.7.3+ Fix from $1,6002022-02-01 MEDIUM 6.5 CVE-2022-0273 Improper Access Control in Pypi calibreweb prior to 0.6.16. Calibre Web 0.6.16+ Fix from $1,6002022-01-30 HIGH 7.2 CVE-2021-46561 controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational ad… Cve Services Patch available Fix from $1,9502022-01-26 HIGH 7.2 CVE-2022-23009 On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-I… Big Iq Centralized Management Mitigation only Fix from $1,9502022-01-25 HIGH 8.8 CVE-2021-4133 A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default … Keycloak 15.1.1+ Fix from $1,9502022-01-25 HIGH 8.1 CVE-2022-21707 wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In vers… Host Runtime 0.52.2+ Fix from $1,9502022-01-21 CRITICAL 9.8 CVE-2020-4877 IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Fo… Cognos Controller Mitigation only Fix from $2,3002022-01-21 HIGH 8.8 CVE-2022-21701 Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation a… Istio Mitigation only Fix from $1,9502022-01-19 CRITICAL 9.3 CVE-2022-22157 A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep … Junos Mitigation only Fix from $2,3002022-01-19 CRITICAL 9.8 CVE-2022-22167 A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep … Junos Mitigation only Fix from $2,3002022-01-19 HIGH 7.8 CVE-2020-14110 AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web back… Ax3600 Firmware 1.0.67+ Fix from $1,9502022-01-18 MEDIUM 6.5 CVE-2021-37864 Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte… Mattermost after 6.1 Fix from $1,6002022-01-18 HIGH 7.8 CVE-2021-39630 In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. T… Android Mitigation only Fix from $1,9502022-01-14 MEDIUM 6.5 CVE-2021-4194 bookstack is vulnerable to Improper Access Control Bookstack 21.12.1+ Fix from $1,6002022-01-06 HIGH 7.5 CVE-2021-45457 In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and p… Kylin 3.1.3+ Fix from $1,9502022-01-06 CRITICAL 9.8 CVE-2021-20149 Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing… Tew 827dru Firmware Mitigation only Fix from $2,3002021-12-30 HIGH 8.8 CVE-2021-43858EPSS 35% MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTT… Minio 2021-12-27t07-23-18z+ Fix from $1,9502021-12-27