Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Artifactory MEDIUM 5.4
CVE-2021-45074

JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth …

Fix: 6.23.38 / 7.29.3+
Fix from $1,600 2022-03-02
Webmin HIGH 8.8
CVE-2022-0824EPSS 97%

Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

Fix: 1.990+
Fix from $1,950 2022-03-02
Zulip HIGH 8.8
CVE-2021-3967

Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

Fix: 4.10+
Fix from $1,950 2022-02-26
Zulip Server CRITICAL 9.8
CVE-2022-21706

Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient acces…

Fix: 4.10.0+
Fix from $2,300 2022-02-26
1734 Aentr Point I\/o Dual Port Network Adaptor Series B Firmware MEDIUM 5.3
CVE-2020-14504

The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can sen…

Fix: after 5.017
Fix from $1,600 2022-02-24
Copy9 HIGH 7.5
CVE-2022-0732

The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating …

Mitigation only
Fix from $1,950 2022-02-24
Dolibarr Erp\/crm MEDIUM 6.5
CVE-2022-0731

Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

Fix: 16.0.0+
Fix from $1,600 2022-02-23
Peertube MEDIUM 5.4
CVE-2022-0727

Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

Fix: 4.1.0+
Fix from $1,600 2022-02-23
Access Management CRITICAL 9.8
CVE-2021-4201

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s…

Patch available
Fix from $2,300 2022-02-14
Livewallpaperservice MEDIUM 5.3
CVE-2022-24924

An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper perm…

Fix: 3.0.9.0+
Fix from $1,600 2022-02-11
Reminder MEDIUM 5.3
CVE-2022-23433

Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in …

Fix: 11.6.08.6000 / 12.2.05.6000+
Fix from $1,600 2022-02-11
Drupal CRITICAL 9.8
CVE-2020-13675

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which cause…

Fix: 8.9.19 / 9.1.13+
Fix from $2,300 2022-02-11
Drupal MEDIUM 6.5
CVE-2020-13676

The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are…

Fix: 8.9.19 / 9.1.13+
Fix from $1,600 2022-02-11
Drupal HIGH 7.5
CVE-2020-13677

Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access…

Fix: 8.9.19 / 9.1.13+
Fix from $1,950 2022-02-11
Workspace HIGH 7.8
CVE-2022-21825

An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacke…

Fix: 2112+
Fix from $1,950 2022-02-09
Cloud Gaming Guest MEDIUM 6.1
CVE-2022-21813

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges …

No fix yet
Fix from $1,600 2022-02-07
Cloud Gaming Virtual Gpu MEDIUM 5.5
CVE-2022-21816

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on…

Fix: 8.10 / 11.7+
Fix from $1,600 2022-02-07
Seaconnect 370w Firmware HIGH 7.4
CVE-2021-21964

A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-craft…

No fix yet
Fix from $1,950 2022-02-04
Seaconnect 370w Firmware CRITICAL 9.3
CVE-2021-21965

A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Speciall…

No fix yet
Fix from $2,300 2022-02-04
Calibre Web MEDIUM 6.5
CVE-2022-0273

Improper Access Control in Pypi calibreweb prior to 0.6.16.

Fix: 0.6.16+
Fix from $1,600 2022-01-30
Rlc 410w Firmware HIGH 8.8
CVE-2021-40416

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Al…

No fix yet
Fix from $1,950 2022-01-28
Rlc 410w Firmware MEDIUM 6.5
CVE-2021-40404

An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted H…

No fix yet
Fix from $1,600 2022-01-28
Rlc 410w Firmware HIGH 7.1
CVE-2021-40413

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Th…

No fix yet
Fix from $1,950 2022-01-28
Rlc 410w Firmware HIGH 7.1
CVE-2021-40414

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Th…

No fix yet
Fix from $1,950 2022-01-28
Rlc 410w Firmware MEDIUM 6.5
CVE-2021-40415

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In…

No fix yet
Fix from $1,600 2022-01-28
Crater MEDIUM 5.3
CVE-2022-0203

Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

Fix: 6.0.2+
Fix from $1,600 2022-01-26
Bored Agent HIGH 8.8
CVE-2022-0270

Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.

Fix: 0.6.1+
Fix from $1,950 2022-01-25
Agilia Partner Maintenance Software CRITICAL 9.8
CVE-2021-23233

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. …

Fix: 3.0+
Fix from $2,300 2022-01-21
Debian Linux MEDIUM 5.3
CVE-2022-21305

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21291

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19