Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Acrobat HIGH 8.2
CVE-2021-21045

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an im…

Fix: after 20.013.20074
Fix from $1,950 2021-02-11
Magento MEDIUM 5.3
CVE-2021-21020

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the …

Fix: 2.3.6+
Fix from $1,600 2021-02-11
Simatic Process Control System Neo HIGH 7.8
CVE-2020-25238

A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain …

Fix: 3.1+
Fix from $1,950 2021-02-09
Ios Xr MEDIUM 6.5
CVE-2021-1389

A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthentic…

Fix: 6.6.3+
Fix from $1,600 2021-02-04
Ios Xr HIGH 7.5
CVE-2021-1243

A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR So…

Fix: 6.6.4 / 7.0.2+
Fix from $1,950 2021-02-04
Ac2100 Firmware MEDIUM 6.5
CVE-2020-27873

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 rout…

Fix: 1.2.0.76+
Fix from $1,600 2021-02-04
Helpdesk CRITICAL 9.8
CVE-2020-2506 KEV

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attacker…

Fix: 3.0.3+
Fix from $2,300 2021-02-03
Q90 Junior Gps Horloge Firmware HIGH 7.5
CVE-2019-20470

An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used …

Mitigation only
Fix from $1,950 2021-02-01
Q90 Junior Gps Horloge Firmware MEDIUM 6.8
CVE-2019-20473

An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device cannot have a PIN configured. If a…

Mitigation only
Fix from $1,600 2021-02-01
Artemis HIGH 7.5
CVE-2021-26118

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 …

Mitigation only
Fix from $1,950 2021-01-27
Junos MEDIUM 5.8
CVE-2021-0205

When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or …

Mitigation only
Fix from $1,600 2021-01-15
Qts CRITICAL 9.1
CVE-2018-19945

A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restri…

Fix: 4.3.4.0899 / 4.3.6.0895+
Fix from $2,300 2020-12-31
Qes HIGH 7.5
CVE-2020-2504

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues…

Fix: 2.1.1+
Fix from $1,950 2020-12-24
Odoo MEDIUM 6.5
CVE-2018-15645

Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users …

Fix: after 12.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.5
CVE-2019-11782

Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to con…

Fix: after 14.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.5
CVE-2019-11783

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote auth…

Fix: after 14.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.5
CVE-2019-11784

Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authent…

Fix: after 14.0
Fix from $1,600 2020-12-22
Virtualization MEDIUM 6.5
CVE-2020-35497

A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email an…

Fix: after 4.4.3
Fix from $1,600 2020-12-21
Reflect HIGH 7.8
CVE-2020-10143

Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service tha…

Fix: 7.3.5281+
Fix from $1,950 2020-12-09
Moodle HIGH 8.8
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some …

Fix: 3.5.14 / 3.7.8+
Fix from $1,950 2020-12-08
Ecostruxure Energy Expert HIGH 7.2
CVE-2020-7545

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notificat…

Mitigation only
Fix from $1,950 2020-12-01
Ecostruxure Energy Expert HIGH 8.8
CVE-2020-7547

A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notifica…

Mitigation only
Fix from $1,950 2020-12-01
Debian Linux HIGH 7.2
CVE-2020-25654

An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication wi…

Fix: 1.1.23 / 2.0.3+
Fix from $1,950 2020-11-24
Webreports MEDIUM 6.5
CVE-2020-7573

A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker be…

Fix: after 3.1
Fix from $1,600 2020-11-19
Easergy T300 Firmware CRITICAL 9.8
CVE-2020-7561

A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide ra…

Fix: after 2.7
Fix from $2,300 2020-11-19
Moodle HIGH 7.5
CVE-2020-25698

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them …

Fix: after 3.9.2
Fix from $1,950 2020-11-19
Moodle MEDIUM 5.3
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneousl…

Fix: after 3.9.2
Fix from $1,600 2020-11-19
Social MEDIUM 5.3
CVE-2020-8278

Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.

No fix yet
Fix from $1,600 2020-11-19
Expressway MEDIUM 6.5
CVE-2020-3482

A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote …

Mitigation only
Fix from $1,600 2020-11-18
Iot Field Network Director HIGH 8.7
CVE-2020-26072

A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify informat…

Fix: 4.6.1+
Fix from $1,950 2020-11-18