Vulnerabilities (CVE)

Filtered by CWE-862
Total 8948 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-41228 1 Jenkins 1 Ns-nd Integration Performance Publisher 2026-06-17 N/A 8.8 HIGH
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.
CVE-2022-40975 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Aazztech Post Slider.This issue affects Post Slider: from n/a through 1.6.7.
CVE-2022-40702 1 Zorem 1 Advanced Local Pickup For Woocommerce 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.5.2.
CVE-2022-40673 2 Fedoraproject, Kdiskmark Project 2 Fedora, Kdiskmark 2026-06-17 N/A 7.8 HIGH
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
CVE-2022-40316 2 Fedoraproject, Moodle 3 Extra Packages For Enterprise Linux, Fedora, Moodle 2026-06-17 N/A 4.3 MEDIUM
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
CVE-2022-40223 1 Searchwp 1 Searchwp 2026-06-17 N/A 5.4 MEDIUM
Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.
CVE-2022-40218 1 Themehunk 1 Advance Product Search 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.1.4.
CVE-2022-40203 1 Algolplus 1 Advanced Dynamic Pricing For Woocommerce 2026-06-17 N/A 6.3 MEDIUM
Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.
CVE-2022-3999 1 Dpdgroup 1 Woocommerce Shipping 2026-06-17 N/A 8.1 HIGH
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.
CVE-2022-3961 1 Wpwax 1 Directorist 2026-06-17 N/A 6.5 MEDIUM
The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.
CVE-2022-3946 1 Welcart 1 Welcart E-commerce 2026-06-17 N/A 6.5 MEDIUM
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.
CVE-2022-3920 1 Hashicorp 1 Consul 2026-06-17 N/A 5.3 MEDIUM
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
CVE-2022-3622 1 Adenion 1 Blog2social 2026-06-17 N/A 4.1 MEDIUM
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only.
CVE-2022-3538 1 Webmaster Tools Verification Project 1 Webmaster Tools Verification 2026-06-17 N/A 6.5 MEDIUM
The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins
CVE-2022-3501 1 Otrs 1 Otrs 2026-06-17 N/A 3.5 LOW
Article template contents with sensitive data could be accessed from agents without permissions.
CVE-2022-3489 1 Weberge 1 Wp Hide 2026-06-17 N/A 5.3 MEDIUM
The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request
CVE-2022-3482 1 Gitlab 1 Gitlab 2026-06-17 N/A 5.3 MEDIUM
An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only
CVE-2022-3451 1 Addify 1 Product Stock Manager 2026-06-17 N/A 4.3 MEDIUM
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options
CVE-2022-3400 1 Bricksbuilder 1 Bricks 2026-06-17 N/A 6.5 MEDIUM
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.
CVE-2022-3337 1 Cloudflare 1 Warp Mobile Client 2026-06-17 N/A 6.7 MEDIUM
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.