Vulnerabilities (CVE)

Filtered by CWE-862
Total 8950 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45813 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3.
CVE-2022-45811 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in WeyHan Ng Post Teaser.This issue affects Post Teaser: from n/a through 4.1.5.
CVE-2022-45806 1 Strategy11 1 Formidable Forms 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.
CVE-2022-45803 1 Gutenbergforms 1 Gutenberg Forms 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plugin – Gutenberg Forms: from n/a through 2.2.8.3.
CVE-2022-45636 1 Megafeis 1 Bofei Dbd\+ 2026-06-17 N/A 8.1 HIGH
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.
CVE-2022-45410 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2026-06-17 N/A 6.5 MEDIUM
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
CVE-2022-45399 1 Jenkins 1 Cluster Statistics 2026-06-17 N/A 4.3 MEDIUM
A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.
CVE-2022-45394 1 Jenkins 1 Delete Log 2026-06-17 N/A 4.3 MEDIUM
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.
CVE-2022-45390 1 Jenkins 1 Loader.io 2026-06-17 N/A 4.3 MEDIUM
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2022-45389 1 Jenkins 1 Xp-dev 2026-06-17 N/A 5.3 MEDIUM
A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.
CVE-2022-45385 1 Jenkins 1 Cloudbees Docker Hub\/registry Notification 2026-06-17 N/A 7.5 HIGH
A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.
CVE-2022-45356 1 Muffingroup 1 Betheme 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
CVE-2022-45352 1 Muffingroup 1 Betheme 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
CVE-2022-45351 1 Muffingroup 1 Betheme 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
CVE-2022-45349 1 Muffingroup 1 Betheme 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
CVE-2022-45070 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3.
CVE-2022-44633 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in YITH YITH WooCommerce Gift Cards Premium.This issue affects YITH WooCommerce Gift Cards Premium: from n/a through 3.23.1.
CVE-2022-44626 1 Squirrly 1 Seo Plugin By Squirrly Seo 2026-06-17 N/A 6.3 MEDIUM
Missing Authorization vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.1.20.
CVE-2022-44578 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Pierre JEHAN Owl Carousel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Owl Carousel: from n/a through 0.5.3.
CVE-2022-44549 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 7.5 HIGH
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.