Vulnerabilities (CVE)

Filtered by CWE-284
Total 7826 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-41690 1 Intel 1 Retail Edge Program 2026-06-17 N/A 7.1 HIGH
Improper access control in the Intel(R) Retail Edge Mobile iOS application before version 3.4.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-41689 1 Intel 1 In-band Manageability 2026-06-17 N/A 7.3 HIGH
Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-41677 1 Bosch 12 Cpp13, Cpp13 Firmware, Cpp14 and 9 more 2026-06-17 N/A 5.3 MEDIUM
An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the device, disclosing possibly internal network settings if the device is connected to the internet.
CVE-2022-41659 1 Intel 1 Unison 2026-06-17 N/A 1.9 LOW
Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.
CVE-2022-41654 1 Ghost 1 Ghost 2026-06-17 N/A 4.3 MEDIUM
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-41652 1 Expresstech 1 Quiz And Survey Master 2026-06-17 N/A 6.5 MEDIUM
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
CVE-2022-41621 1 Intel 1 Quickassist Technology 2026-06-17 N/A 3.3 LOW
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2022-41324 2026-06-17 N/A 6.5 MEDIUM
Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.
CVE-2022-41261 2 Microsoft, Sap 2 Windows, Solution Manager 2026-06-17 N/A 6.0 MEDIUM
SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files. Successful exploitation can make the attacker access files and systems for which he/she is not authorized.
CVE-2022-41235 1 Jenkins 1 Wildfly Deployer 2026-06-17 N/A 5.3 MEDIUM
Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.
CVE-2022-41155 1 Webence 1 Iq Block Country 2026-06-17 N/A 5.3 MEDIUM
Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
CVE-2022-41135 1 Wpchill 1 Customizable Wordpress Gallery Plugin - Modula Image Gallery 2026-06-17 N/A 6.5 MEDIUM
Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.
CVE-2022-40972 1 Intel 1 Quickassist Technology 2026-06-17 N/A 6.7 MEDIUM
Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-40964 3 Debian, Fedoraproject, Intel 17 Debian Linux, Fedora, Killer and 14 more 2026-06-17 N/A 7.9 HIGH
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2022-40798 1 Ocomon Project 1 Ocomon 2026-06-17 N/A 7.5 HIGH
OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover.
CVE-2022-40539 1 Qualcomm 50 Qam8295p, Qam8295p Firmware, Qca6574au and 47 more 2026-06-17 N/A 8.4 HIGH
Memory corruption in Automotive Android OS due to improper validation of array index.
CVE-2022-40529 1 Qualcomm 392 Aqt1000, Aqt1000 Firmware, Ar8031 and 389 more 2026-06-17 N/A 7.1 HIGH
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
CVE-2022-40216 1 Wordplus 1 Better Messages 2026-06-17 N/A 4.3 MEDIUM
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
CVE-2022-40207 1 Intel 1 System Usage Report 2026-06-17 N/A 8.2 HIGH
Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-40036 1 Blog-ssm Project 1 Blog-ssm 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component.