Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Shield Experience HIGH 7.8
CVE-2021-34401

NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to …

Fix: 9.0+
Fix from $1,950 2022-01-18
Shield Experience MEDIUM 6.7
CVE-2021-34402

NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memor…

Fix: 9.0+
Fix from $1,600 2022-01-18
Mattermost MEDIUM 6.5
CVE-2021-37864

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte…

Fix: after 6.1
Fix from $1,600 2022-01-18
Eos HIGH 7.1
CVE-2021-28507

An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RE…

Fix: after 4.26.2f
Fix from $1,950 2022-01-14
Fedora HIGH 7.3
CVE-2022-23132

During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix …

Fix: after 5.4.8
Fix from $1,950 2022-01-13
Fedora MEDIUM 5.3
CVE-2022-23134 KEVEPSS 85%

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M…

Fix: after 5.4.8
Fix from $1,600 2022-01-13
Cp 8000 Master Module With I\/o 25\/\+70 Firmware HIGH 7.5
CVE-2021-45034

A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (Al…

Fix: 16.20+
Fix from $1,950 2022-01-11
Peertube HIGH 7.5
CVE-2022-0133

peertube is vulnerable to Improper Access Control

Fix: 2022-01-06+
Fix from $1,950 2022-01-10
Bookstack MEDIUM 6.5
CVE-2021-4194

bookstack is vulnerable to Improper Access Control

Fix: 21.12.1+
Fix from $1,600 2022-01-06
Ifme HIGH 7.3
CVE-2021-25991

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to …

Fix: after 7.32
Fix from $1,950 2021-12-29
Sma 100 Firmware HIGH 7.5
CVE-2021-20050

An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, pot…

Fix: 10.0.0.0+
Fix from $1,950 2021-12-23
Sentinel Protection Installer MEDIUM 6.7
CVE-2021-42808

Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.

Fix: 7.7.1+
Fix from $1,600 2021-12-20
Bookstack CRITICAL 9.8
CVE-2021-4119EPSS 27%

bookstack is vulnerable to Improper Access Control

Fix: after 21.11.2
Fix from $2,300 2021-12-15
Image Hover Effects CRITICAL 9.8
CVE-2021-36888EPSS 7%

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6…

Fix: 9.6.1+
Fix from $2,300 2021-12-15
Improved Include Page MEDIUM 6.5
CVE-2021-24845

The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve…

Fix: after 1.2
Fix from $1,600 2021-12-13
Exposure Notification Verification Server MEDIUM 6.5
CVE-2021-22565

An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to genera…

Fix: 1.1.2+
Fix from $1,600 2021-12-09
Avalanche HIGH 8.8
CVE-2021-42124

An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a …

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Serv U MEDIUM 6.8
CVE-2021-35245

When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.

Fix: 15.2.4+
Fix from $1,600 2021-12-06
Omnipod Insulin Management System Firmware HIGH 8.1
CVE-2020-10627

Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manu…

Mitigation only
Fix from $1,950 2021-12-01
Amd Uprof CRITICAL 9.9
CVE-2021-26334

The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation an…

Fix: 3.4.494 / 3.4.502+
Fix from $2,300 2021-12-01
Kimai2 MEDIUM 6.5
CVE-2021-3992

kimai2 is vulnerable to Improper Access Control

Fix: 1.16.2+
Fix from $1,600 2021-12-01
Hide My Wp HIGH 7.5
CVE-2021-36917

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can th…

Fix: after 6.2.3
Fix from $1,950 2021-11-24
Endpoint Security Tools CRITICAL 10.0
CVE-2021-3554

Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows…

Fix: 6.6.27.390 / 6.24.1-1+
Fix from $2,300 2021-11-24
Wp Reset Pro HIGH 8.1
CVE-2021-36909

Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the enti…

Fix: after 5.98
Fix from $1,950 2021-11-18
Counterparty Settlements And Billing HIGH 7.1
CVE-2021-35528

Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlemen…

Fix: after 5.7.3
Fix from $1,950 2021-11-17
Starter Templates MEDIUM 5.4
CVE-2021-42360

On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contrib…

Fix: after 2.7.0
Fix from $1,600 2021-11-17
Epyc 7f72 Firmware HIGH 7.5
CVE-2021-26338

Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting i…

Mitigation only
Fix from $1,950 2021-11-16
Pan Os HIGH 8.8
CVE-2021-3062

An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to co…

Fix: 8.1.20 / 9.0.14+
Fix from $1,950 2021-11-10
Jovi Smart Scene MEDIUM 5.5
CVE-2020-12488

The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without reques…

Fix: 6.2.2.52+
Fix from $1,600 2021-11-10
Wp Dsgvo Tools CRITICAL 9.1
CVE-2021-42359

WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available …

Fix: after 3.1.23
Fix from $2,300 2021-11-05