Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Catalyst Pon Switch Cgp Ont 1p Firmware CRITICAL 9.8
CVE-2021-34795

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Te…

Fix: 1.1.1.14 / 1.1.3.17+
Fix from $2,300 2021-11-04
Catalyst Pon Switch Cgp Ont 1p Firmware HIGH 7.5
CVE-2021-40112

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Te…

Fix: 1.1.1.14 / 1.1.3.17+
Fix from $1,950 2021-11-04
Catalyst Pon Switch Cgp Ont 1p Firmware CRITICAL 9.8
CVE-2021-40113

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Te…

Fix: 1.1.1.14 / 1.1.3.17+
Fix from $2,300 2021-11-04
Hashthemes Demo Importer HIGH 8.1
CVE-2021-39333

The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-i…

Fix: after 1.1.1
Fix from $1,950 2021-11-01
First Use Authenticator CRITICAL 9.8
CVE-2021-41194

FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is us…

Fix: 1.0.0+
Fix from $2,300 2021-10-28
Secure Firewall Threat Defense MEDIUM 5.3
CVE-2021-34794

A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) …

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,600 2021-10-27
Secure Firewall Management Center HIGH 7.5
CVE-2021-34754

Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software …

Fix: 6.4.0.13 / 6.6.5.1+
Fix from $1,950 2021-10-27
Parallels Desktop HIGH 8.8
CVE-2021-34864

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must firs…

Mitigation only
Fix from $1,950 2021-10-25
PHP HIGH 7.0
CVE-2021-21703

In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process r…

Fix: 7.4.25 / 8.0.12+
Fix from $1,950 2021-10-25
Versiondog CRITICAL 9.8
CVE-2021-38457

The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing …

Fix: 8.0.0+
Fix from $2,300 2021-10-22
Catch Scroll Progress Bar MEDIUM 5.7
CVE-2021-24752

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authentic…

Fix: 1.4 / 1.6+
Fix from $1,600 2021-10-18
Mxview CRITICAL 10.0
CVE-2021-38454EPSS 16%

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite crit…

Fix: after 3.2.2
Fix from $2,300 2021-10-12
Openoffice HIGH 7.8
CVE-2021-28129

While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupi…

Mitigation only
Fix from $1,950 2021-10-07
Zoom Latitude Pogrammer\/recorder\/monitor 3120 Firmware HIGH 7.6
CVE-2021-38392

A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region an…

Mitigation only
Fix from $1,950 2021-10-04
Multipass HIGH 8.8
CVE-2021-3626

The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the ope…

Fix: 1.7.0+
Fix from $1,950 2021-10-01
Ecs Router Controller Ecs Firmware HIGH 8.8
CVE-2021-41298

ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on use…

Mitigation only
Fix from $1,950 2021-09-30
Wireless 1410 Gateway Firmware CRITICAL 10.0
CVE-2020-12030

There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN se…

Fix: after 4.7.84
Fix from $2,300 2021-09-29
Sma 200 Firmware CRITICAL 9.1
CVE-2021-20034EPSS 81%

An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitra…

Fix: after 10.2.1.0-17sv
Fix from $2,300 2021-09-27
Sharefile Storagezones Controller CRITICAL 9.8
CVE-2021-22941 KEVEPSS 54%

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the …

Fix: 5.11.20+
Fix from $2,300 2021-09-23
Ios Xe Sd Wan MEDIUM 6.0
CVE-2021-34724

A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code…

Fix: after 17.3.1a
Fix from $1,600 2021-09-23
Ios Xe MEDIUM 5.8
CVE-2021-34696

A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthen…

Fix: after 17.3.2
Fix from $1,600 2021-09-23
Ios Xe MEDIUM 5.8
CVE-2021-1625

A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zon…

Fix: 17.3.2+
Fix from $1,600 2021-09-23
Aironet 1542d Firmware HIGH 7.8
CVE-2021-1419

A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files…

Patch available
Fix from $1,950 2021-09-23
Visual Link Preview MEDIUM 5.4
CVE-2021-24635

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all…

Fix: 2.2.3+
Fix from $1,600 2021-09-20
Sinema Remote Connect Server MEDIUM 6.5
CVE-2021-37183

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software allows sending send-to-sleep not…

Fix: 3.0+
Fix from $1,600 2021-09-14
Orion Platform HIGH 8.8
CVE-2021-35213

An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a gues…

Fix: after 2020.2.5
Fix from $1,950 2021-08-31
Orion Platform HIGH 8.1
CVE-2021-35221

Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings p…

Fix: 2020.2.6+
Fix from $1,950 2021-08-31
Nx Os MEDIUM 5.3
CVE-2021-1591

A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to by…

Patch available
Fix from $1,600 2021-08-25
Application Policy Infrastructure Controller HIGH 7.2
CVE-2021-1580

Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow…

Fix: 3.2 / 4.2+
Fix from $1,950 2021-08-25
Application Policy Infrastructure Controller CRITICAL 9.1
CVE-2021-1581

Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow…

Fix: 3.2 / 4.2+
Fix from $2,300 2021-08-25