Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Chrome MEDIUM 6.5
CVE-2020-6484

Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6471

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6476

Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious e…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6469

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-13240

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file e…

No fix yet
Fix from $1,600 2020-05-20
Eluga Ray 530 Firmware CRITICAL 9.8
CVE-2020-11716

Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affec…

Fix: after 2020-04-10
Fix from $2,300 2020-05-20
Jasperreports Server CRITICAL 9.8
CVE-2020-9409

The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO Jasper…

Fix: after 7.1.1
Fix from $2,300 2020-05-20
Dragon Center HIGH 7.8
CVE-2020-13149

Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, a…

Fix: 2.6.2003.2401+
Fix from $1,950 2020-05-18
Homematic Ccu2 Firmware CRITICAL 9.8
CVE-2020-12834EPSS 11%

eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, …

Fix: after 3.51.6
Fix from $2,300 2020-05-15
Android HIGH 7.8
CVE-2020-0024

In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass. This could lead to local…

Patch available
Fix from $1,950 2020-05-14
Sterling File Gateway MEDIUM 6.5
CVE-2020-4259

IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules fro…

Fix: after 6.0.3.1
Fix from $1,600 2020-05-14
Sd6al Firmware HIGH 8.1
CVE-2019-9682

Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of …

Fix: 2019-12+
Fix from $1,950 2020-05-13
Big Ip Access Policy Manager HIGH 7.8
CVE-2020-5896

On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder permissions.

Fix: after 15.1.0.3
Fix from $1,950 2020-05-12
Managed Service Provider Patch Management Engine HIGH 7.8
CVE-2020-12608EPSS 22%

An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insec…

Fix: 1.1.15+
Fix from $1,950 2020-05-07
Copy Artifact MEDIUM 6.5
CVE-2020-2183

Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no perm…

Fix: after 1.43.1
Fix from $1,600 2020-05-06
Linux Enterprise Desktop HIGH 7.8
CVE-2020-8018

A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server …

Mitigation only
Fix from $1,950 2020-05-04
GitLab MEDIUM 5.3
CVE-2020-12277

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

Fix: 12.7.8 / 12.8.8+
Fix from $1,600 2020-04-29
800xa System HIGH 7.8
CVE-2020-8471

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…

Mitigation only
Fix from $1,950 2020-04-29
Linux Kernel HIGH 8.8
CVE-2019-15793

In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate us…

Patch available
Fix from $1,950 2020-04-24
Tss Lib HIGH 8.2
CVE-2020-12118

The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a…

Fix: 1.2.0+
Fix from $1,950 2020-04-23
Rx4 1500 Firmware MEDIUM 5.5
CVE-2020-8798

httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm e…

Fix: after 1.0.5
Fix from $1,600 2020-04-23
Data Tables Generator HIGH 8.8
CVE-2020-12075

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.

Fix: 1.9.92+
Fix from $1,950 2020-04-23
Teamcity MEDIUM 6.5
CVE-2020-11689

In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.

Fix: 2019.2.1+
Fix from $1,600 2020-04-22
Data Migration HIGH 7.8
CVE-2020-0547

Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to poten…

Fix: after 3.3
Fix from $1,950 2020-04-15
Qradar Security Information And Event Manager HIGH 7.8
CVE-2020-4270

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.

Fix: 7.3.3+
Fix from $1,950 2020-04-15
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2020-4274

IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission chec…

Fix: 7.3.3+
Fix from $1,600 2020-04-15
Andy Os HIGH 7.8
CVE-2019-14326

An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) with root privileges in the e…

Fix: after 46.11.113
Fix from $1,950 2020-04-14
Husky Rtu 6049 E70 Firmware MEDIUM 5.3
CVE-2020-7802

The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulner…

Fix: after 5.0
Fix from $1,600 2020-04-14
Chrome MEDIUM 6.5
CVE-2020-6456

Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via …

Fix: 81.0.4044.92+
Fix from $1,600 2020-04-13
Chrome HIGH 8.8
CVE-2020-6439

Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted H…

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13