Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Application Policy Infrastructure Controller CRITICAL 9.1
CVE-2021-1577

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…

Fix: 3.2 / 4.2+
Fix from $2,300 2021-08-25
Dolibarr HIGH 7.2
CVE-2021-25956

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to vali…

Fix: after 13.0.2
Fix from $1,950 2021-08-17
Workreap HIGH 8.1
CVE-2021-24500

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer…

Fix: 2.2.2+
Fix from $1,950 2021-08-09
Application Delivery Management MEDIUM 6.5
CVE-2021-22920

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Cit…

Mitigation only
Fix from $1,600 2021-08-05
Smartthings Firmware MEDIUM 5.3
CVE-2021-25446

Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in w…

Fix: 1.7.67.25+
Fix from $1,600 2021-08-05
Smartthings Firmware MEDIUM 5.3
CVE-2021-25447

Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webvie…

Fix: 1.7.67.25+
Fix from $1,600 2021-08-05
Smart Touch Call MEDIUM 5.3
CVE-2021-25448

Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.

Fix: 1.0.0.5+
Fix from $1,600 2021-08-05
Intersight Virtual Appliance HIGH 8.3
CVE-2021-1600

Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal service…

Patch available
Fix from $1,950 2021-07-22
Intersight Virtual Appliance HIGH 8.3
CVE-2021-1601

Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal service…

Patch available
Fix from $1,950 2021-07-22
Rancher CRITICAL 9.9
CVE-2021-25320

A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the clou…

Fix: 2.4.16 / 2.5.9+
Fix from $2,300 2021-07-15
Edgex Foundry MEDIUM 6.5
CVE-2021-32753

EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edi…

Fix: 2.0.0+
Fix from $1,600 2021-07-09
Factorycamerafb HIGH 7.8
CVE-2021-25440

Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an esca…

Fix: 3.4.74+
Fix from $1,950 2021-07-08
Cameralyzer MEDIUM 5.5
CVE-2021-25431

Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows untrusted a…

Fix: 3.2.1041 / 3.3.1040+
Fix from $1,600 2021-07-08
Members HIGH 7.8
CVE-2021-25438

Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and…

Fix: 2.4.85.11+
Fix from $1,950 2021-07-08
Hybrid Backup Sync CRITICAL 9.8
CVE-2021-28809EPSS 16%

An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attack…

Fix: 3.0.210506 / 3.0.210507+
Fix from $2,300 2021-07-08
Storage Manager HIGH 7.5
CVE-2021-32514

Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. The re…

Fix: 3.3.3+
Fix from $1,950 2021-07-07
Storage Manager HIGH 7.5
CVE-2021-32517

Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files using particular para…

Fix: 3.3.3+
Fix from $1,950 2021-07-07
Experience Manager HIGH 7.5
CVE-2021-21083

AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access…

Fix: 6.4.8.4 / 6.5.8.0+
Fix from $1,950 2021-06-28
B426 Firmware HIGH 8.8
CVE-2021-23845

This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovere…

Fix: 03.08 / 03.10+
Fix from $1,950 2021-06-18
Gateway MEDIUM 6.5
CVE-2020-8300

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper ac…

Fix: 11.1-65.20 / 12.1-55.238+
Fix from $1,600 2021-06-16
The Plus Addons For Elementor MEDIUM 5.3
CVE-2021-24359

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legi…

Fix: 4.1.11+
Fix from $1,600 2021-06-14
Android HIGH 7.8
CVE-2021-25412

An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity wi…

Mitigation only
Fix from $1,950 2021-06-11
Notes MEDIUM 5.5
CVE-2021-25405

An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access loc…

Fix: 4.2.04.27+
Fix from $1,600 2021-06-11
3scale Api Management MEDIUM 6.3
CVE-2020-14388

A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This f…

Mitigation only
Fix from $1,600 2021-06-02
Nextcloud Server HIGH 8.6
CVE-2021-32656

Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions prior to 19.0.11, 20.0.10, a…

Fix: 19.0.11 / 20.0.10+
Fix from $1,950 2021-06-01
Listeo MEDIUM 6.5
CVE-2021-24318

The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any …

Fix: 1.6.11+
Fix from $1,600 2021-06-01
Coldfusion HIGH 7.8
CVE-2020-10145

The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By …

Mitigation only
Fix from $1,950 2021-05-27
Workspace HIGH 7.8
CVE-2021-22907

An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2…

Fix: 19.12.4000 / 2105+
Fix from $1,950 2021-05-27
3scale MEDIUM 5.4
CVE-2020-25634

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive informa…

Fix: 2.10.0+
Fix from $1,600 2021-05-26
Qts HIGH 7.5
CVE-2021-28798

A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attac…

Fix: 4.3.3.1624 / 4.3.6.1663+
Fix from $1,950 2021-05-21