Total
2747 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-43581 | 1 Ibm | 1 Content Navigator | 2023-11-07 | N/A | 8.8 HIGH |
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805. | |||||
CVE-2022-42782 | 2 Google, Unisoc | 14 Android, S8000, Sc7731e and 11 more | 2023-11-07 | N/A | 5.5 MEDIUM |
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure. | |||||
CVE-2022-42766 | 2 Google, Unisoc | 14 Android, S8011, Sc7731e and 11 more | 2023-11-07 | N/A | 5.5 MEDIUM |
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure. | |||||
CVE-2022-41272 | 1 Sap | 1 Netweaver Process Integration | 2023-11-07 | N/A | 8.6 HIGH |
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data across the entire system. This allows the attacker to have full read access to user data, make limited modifications to user data, and degrade the performance of the system, leading to a high impact on confidentiality and a limited impact on the availability and integrity of the application. | |||||
CVE-2022-41271 | 1 Sap | 1 Netweaver Process Integration | 2023-11-07 | N/A | 9.4 CRITICAL |
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized operations. The vulnerability affects local users and data, leading to a considerable impact on confidentiality as well as availability and a limited impact on the integrity of the application. These operations can be used to: * Read any information * Modify sensitive information * Denial of Service attacks (DoS) * SQL Injection | |||||
CVE-2022-40673 | 2 Fedoraproject, Kdiskmark Project | 2 Fedora, Kdiskmark | 2023-11-07 | N/A | 7.8 HIGH |
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache. | |||||
CVE-2022-3999 | 1 Dpdgroup | 1 Woocommerce Shipping | 2023-11-07 | N/A | 8.1 HIGH |
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable. | |||||
CVE-2022-3961 | 1 Wpwax | 1 Directorist | 2023-11-07 | N/A | 6.5 MEDIUM |
The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information. | |||||
CVE-2022-3946 | 1 Collne | 1 Welcart E-commerce | 2023-11-07 | N/A | 6.5 MEDIUM |
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods. | |||||
CVE-2022-3923 | 1 Activecampaign | 1 Activecampaign For Woocommerce | 2023-11-07 | N/A | 4.3 MEDIUM |
The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs. | |||||
CVE-2022-3911 | 1 Iubenda | 1 Iubenda-cookie-law-solution | 2023-11-07 | N/A | 8.8 HIGH |
The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users, such as subscriber can grant themselves any privileges, such as edit_plugins etc | |||||
CVE-2022-3622 | 1 Adenion | 1 Blog2social | 2023-11-07 | N/A | 4.3 MEDIUM |
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only. | |||||
CVE-2022-3512 | 1 Cloudflare | 1 Warp | 2023-11-07 | N/A | 8.8 HIGH |
Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint. | |||||
CVE-2022-3400 | 1 Bricksbuilder | 1 Bricks | 2023-11-07 | N/A | 6.5 MEDIUM |
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website. | |||||
CVE-2022-3337 | 1 Cloudflare | 1 Warp Mobile Client | 2023-11-07 | N/A | 8.5 HIGH |
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform. | |||||
CVE-2022-3322 | 1 Cloudflare | 1 Warp Mobile Client | 2023-11-07 | N/A | 7.5 HIGH |
Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action. | |||||
CVE-2022-3321 | 1 Cloudflare | 1 Warp Mobile Client | 2023-11-07 | N/A | 8.2 HIGH |
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused the WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform. | |||||
CVE-2022-3320 | 1 Cloudflare | 1 Warp | 2023-11-07 | N/A | 9.8 CRITICAL |
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint caused the WARP Client to disconnect and allowed bypassing administrative restrictions on a Zero Trust enrolled endpoint. | |||||
CVE-2022-3082 | 1 Miniorange | 1 Discord Integration | 2023-11-07 | N/A | 6.5 MEDIUM |
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example | |||||
CVE-2022-36404 | 1 Coleds | 1 Simple Seo | 2023-11-07 | N/A | 5.4 MEDIUM |
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions. |