Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Music Station HIGH 8.8
CVE-2020-36197EPSS 18%

An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attac…

Fix: 5.1.14 / 5.2.10+
Fix from $1,950 2021-05-13
Hosted Collaboration Mediation Fulfillment MEDIUM 6.5
CVE-2021-1478

A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communicatio…

Fix: 12.6+
Fix from $1,600 2021-05-06
Catalyst Sd Wan Manager HIGH 8.8
CVE-2021-1284

A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to by…

Fix: 20.3.1 / 20.4.1+
Fix from $1,950 2021-05-06
Equinox Conferencing HIGH 7.5
CVE-2020-7038

A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker…

Fix: 9.1.11+
Fix from $1,950 2021-04-28
Cscape HIGH 7.8
CVE-2021-22682

Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write a…

Fix: 9.90+
Fix from $1,950 2021-04-23
Automox MEDIUM 5.3
CVE-2021-26909

Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an …

Fix: 31+
Fix from $1,600 2021-04-23
Findeo MEDIUM 6.5
CVE-2021-24238

The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user maki…

Fix: 1.2.4 / 1.3.1+
Fix from $1,600 2021-04-22
Fedora HIGH 7.4
CVE-2021-0232

An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific informatio…

Fix: 2.35.6 / 2.36.2+
Fix from $1,950 2021-04-22
Genuine Service HIGH 7.8
CVE-2020-9668

Adobe Genuine Service version 6.6 (and earlier) is affected by an Improper Access control vulnerability when handling symbolic links. An unauthentica…

Fix: after 6.6
Fix from $1,950 2021-04-16
Orion Platform CRITICAL 9.8
CVE-2021-27258

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…

Mitigation only
Fix from $2,300 2021-04-14
Ampache HIGH 7.5
CVE-2021-21399

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the …

Fix: 4.4.1+
Fix from $1,950 2021-04-13
Netweaver Application Server Java MEDIUM 5.3
CVE-2021-27598

SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ…

Mitigation only
Fix from $1,600 2021-04-13
Controlled Admin Access CRITICAL 9.8
CVE-2021-24215EPSS 10%

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the webs…

Fix: 1.5.2+
Fix from $2,300 2021-04-12
Focusblog MEDIUM 5.3
CVE-2021-24219

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin be…

Fix: 2.0.0+
Fix from $1,600 2021-04-12
Wpdatatables HIGH 8.1
CVE-2021-24197

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that v…

Fix: 3.4.2+
Fix from $1,950 2021-04-12
Wpdatatables HIGH 8.1
CVE-2021-24198

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that v…

Fix: 3.4.2+
Fix from $1,950 2021-04-12
Channelmgnt HIGH 8.1
CVE-2021-21431

sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot usin…

Fix: 2.0.1+
Fix from $1,950 2021-04-09
Grav Plugin Admin CRITICAL 9.8
CVE-2021-21425EPSS 81%

Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an una…

Fix: 1.10.8+
Fix from $2,300 2021-04-07
Slow Motion Editor HIGH 7.8
CVE-2021-25349

Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijackin…

Fix: 3.5.18.5+
Fix from $1,950 2021-03-25
Aironet Access Point Software MEDIUM 6.7
CVE-2021-1449

A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time.…

Fix: 8.5.171.0 / 8.10.150.0+
Fix from $1,600 2021-03-24
Openshift Container Platform HIGH 7.2
CVE-2019-10200

A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloa…

Patch available
Fix from $1,950 2021-03-19
PostgreSQL HIGH 7.8
CVE-2019-10128

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down th…

Fix: 9.4.22 / 9.5.17+
Fix from $1,950 2021-03-19
PostgreSQL HIGH 8.8
CVE-2019-10127

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL …

Fix: 9.4.22 / 9.5.17+
Fix from $1,950 2021-03-19
Modern Events Calendar Lite HIGH 7.5
CVE-2021-24146EPSS 31%

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp…

Fix: 5.16.5+
Fix from $1,950 2021-03-18
Forgot Password HIGH 8.8
CVE-2021-25672

A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does no…

Fix: 3.2.1+
Fix from $1,950 2021-03-15
Sitemanager Firmware HIGH 7.2
CVE-2020-29020

Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the c…

Fix: 9.4.620527004+
Fix from $1,950 2021-03-05
Nextcloud Server MEDIUM 6.5
CVE-2021-22877

A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration whe…

Fix: 20.0.6+
Fix from $1,600 2021-03-03
Nx Os MEDIUM 6.5
CVE-2021-1228

A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastr…

Mitigation only
Fix from $1,600 2021-02-24
Airflow MEDIUM 6.5
CVE-2021-26559

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur…

Mitigation only
Fix from $1,600 2021-02-17
Hr Portal MEDIUM 5.4
CVE-2021-22853

The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific…

Mitigation only
Fix from $1,600 2021-02-17