Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Wap125 Firmware HIGH 7.2
CVE-2021-1401

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-06
Content Security Management Appliance MEDIUM 6.7
CVE-2021-1447

A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authentic…

Fix: 12.8.1-002 / 13.8.1-068+
Fix from $1,600 2021-05-06
Exim HIGH 7.8
CVE-2020-28008

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), a…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim MEDIUM 6.1
CVE-2020-28014

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service becau…

Fix: 4.94.2+
Fix from $1,600 2021-05-06
Wap125 Firmware HIGH 8.8
CVE-2021-1400

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could …

Fix: after 1.1.2.4
Fix from $1,950 2021-05-06
Windscribe HIGH 7.8
CVE-2020-27518

All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component.…

Fix: after 2.02.10
Fix from $1,950 2021-05-04
Pritunl Client Electron HIGH 7.8
CVE-2020-27519

Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious ope…

Patch available
Fix from $1,950 2021-04-30
Junos HIGH 7.8
CVE-2021-0255

A local privilege escalation vulnerability in ethtraceroute of Juniper Networks Junos OS may allow a locally authenticated user with shell access to …

Mitigation only
Fix from $1,950 2021-04-22
Junos MEDIUM 5.5
CVE-2021-0256

A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow a locally authenticated user …

Mitigation only
Fix from $1,600 2021-04-22
Xscreensaver HIGH 7.8
CVE-2021-31523

The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows loca…

Patch available
Fix from $1,950 2021-04-21
Enterprise Linux MEDIUM 6.1
CVE-2021-20208

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credent…

Fix: 6.13+
Fix from $1,600 2021-04-19
Vmware Nsx T Data Center HIGH 7.8
CVE-2021-21981

VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment. Successful exploita…

Patch available
Fix from $1,950 2021-04-19
A12n Server MEDIUM 6.5
CVE-2021-29452

a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0…

Fix: 0.18.2+
Fix from $1,600 2021-04-16
Mendix HIGH 8.8
CVE-2021-27394

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions…

Fix: 7.23.19 / 8.6.9+
Fix from $1,950 2021-04-16
Data Loss Prevention Endpoint HIGH 7.8
CVE-2021-23887

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attack…

Fix: 11.6.100.41+
Fix from $1,950 2021-04-15
Zulip Server MEDIUM 5.3
CVE-2021-30479

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being a…

Fix: 3.4+
Fix from $1,600 2021-04-15
Pi Hole HIGH 7.8
CVE-2021-29449

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discover…

Fix: after 5.2.4
Fix from $1,950 2021-04-14
Visual Studio HIGH 7.8
CVE-2021-28322

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

Fix: after 16.9
Fix from $1,950 2021-04-13
Visual Studio HIGH 7.8
CVE-2021-28313

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

Fix: after 16.9
Fix from $1,950 2021-04-13
Pega Platform CRITICAL 9.8
CVE-2020-15390

pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.

No fix yet
Fix from $2,300 2021-04-12
Experience Service HIGH 7.8
CVE-2021-25377

Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to …

Fix: after 10.8.0.4
Fix from $1,950 2021-04-09
Android MEDIUM 6.1
CVE-2021-25362

An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.

Mitigation only
Fix from $1,600 2021-04-09
Android MEDIUM 6.1
CVE-2021-25363

An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete …

Mitigation only
Fix from $1,600 2021-04-09
Android HIGH 7.8
CVE-2021-25365

An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.

Mitigation only
Fix from $1,950 2021-04-09
Email Security CRITICAL 9.8
CVE-2021-20021 KEVEPSS 83%

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP req…

Fix: 10.0.9.6103 / 10.0.9.6105+
Fix from $2,300 2021-04-09
Openlitespeed HIGH 8.8
CVE-2021-26758

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute comma…

No fix yet
Fix from $1,950 2021-04-07
Compass HIGH 7.8
CVE-2021-20334

A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges …

Fix: 1.25.0+
Fix from $1,950 2021-04-06
Orbit Fox MEDIUM 6.5
CVE-2021-24158

Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the …

Fix: 2.10.3+
Fix from $1,600 2021-04-05
Mac Os X HIGH 7.8
CVE-2021-1802

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Up…

Fix: 10.14.6 / 10.15.7+
Fix from $1,950 2021-04-02
Ipados HIGH 7.8
CVE-2021-1787

Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 202…

Fix: 7.3 / 10.14.6+
Fix from $1,950 2021-04-02