Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Prestashop HIGH 7.5
CVE-2020-26224

In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function th…

Fix: 1.7.6.9+
Fix from $1,950 2020-11-16
Acrobat Reader MEDIUM 5.5
CVE-2020-24441

Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could…

Fix: after 20.6.2
Fix from $1,600 2020-11-12
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2020-3592

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…

Fix: after 20.1.12
Fix from $1,600 2020-11-06
A9k Rsp880 Se Firmware CRITICAL 9.8
CVE-2020-3284

A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remo…

Fix: 1.12 / 1.21+
Fix from $2,300 2020-11-06
Enterprise Linux MEDIUM 6.5
CVE-2020-25662

A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of s…

Mitigation only
Fix from $1,600 2020-11-05
Acrobat HIGH 7.8
CVE-2020-24433EPSS 16%

Adobe Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a local …

Fix: after 20.012.20048
Fix from $1,950 2020-11-05
Winston Firmware MEDIUM 6.8
CVE-2020-16261

Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.

No fix yet
Fix from $1,600 2020-10-28
Adaptive Security Appliance MEDIUM 5.3
CVE-2020-3564

A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co…

Fix: 6.3.0.6 / 6.4.0.10+
Fix from $1,600 2020-10-21
Secure Firewall Threat Defense MEDIUM 5.8
CVE-2020-3565

A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…

Fix: 6.4.0.8 / 6.5.0.4+
Fix from $1,600 2020-10-21
Cyber Backup HIGH 7.8
CVE-2020-10138

Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins…

Fix: 12.5 / 15+
Fix from $1,950 2020-10-21
True Image HIGH 7.8
CVE-2020-10139

Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True …

Mitigation only
Fix from $1,950 2020-10-21
Junos Os Evolved MEDIUM 6.6
CVE-2020-1666

The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the …

Mitigation only
Fix from $1,600 2020-10-16
Deck HIGH 8.0
CVE-2020-8182

Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.

No fix yet
Fix from $1,950 2020-10-05
Ios Xe Rom Monitor MEDIUM 6.8
CVE-2020-3524

A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cisco ASR 920 Series Aggregation…

Fix: 15.6 / 16.2+
Fix from $1,600 2020-09-24
Ios Xe MEDIUM 6.0
CVE-2020-3503

A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access …

Mitigation only
Fix from $1,600 2020-09-24
Ios Xe HIGH 7.2
CVE-2020-3396

A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical …

Mitigation only
Fix from $1,950 2020-09-24
Reset Password CRITICAL 9.8
CVE-2020-15181

The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the sy…

Fix: 1.2.0+
Fix from $2,300 2020-09-18
Salt Netapi Client CRITICAL 9.3
CVE-2020-8028

A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy …

Fix: 0.16.0-4.14.1 / 0.17.0-3.3.2+
Fix from $2,300 2020-09-17
Scadapack 7x Remote Connect HIGH 7.8
CVE-2020-7531

A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place execut…

Fix: after 3.6.3.574
Fix from $1,950 2020-09-16
Data Center Network Manager MEDIUM 6.3
CVE-2020-3522

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attac…

Fix: 11.4+
Fix from $1,600 2020-08-26
Cyber Vision Center MEDIUM 5.8
CVE-2020-3448

A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authen…

Fix: 3.0.4+
Fix from $1,600 2020-08-17
Gemfire HIGH 8.8
CVE-2020-5396

VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed…

Fix: 1.10.2 / 1.11.1+
Fix from $1,950 2020-07-31
Openstack Platform CRITICAL 9.9
CVE-2020-10731

A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw cause…

Mitigation only
Fix from $2,300 2020-07-31
R6700 Firmware MEDIUM 6.5
CVE-2020-10930

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 r…

Mitigation only
Fix from $1,600 2020-07-28
Workspace HIGH 8.8
CVE-2020-8207

Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic upd…

Mitigation only
Fix from $1,950 2020-07-24
Dashboard Products MEDIUM 6.5
CVE-2020-15102

In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The …

Fix: 2.1.0+
Fix from $1,600 2020-07-21
Rv110w Firmware CRITICAL 9.8
CVE-2020-3144

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction …

Fix: 1.0.3.55 / 1.2.2.8+
Fix from $2,300 2020-07-16
Robotware CRITICAL 9.8
CVE-2020-10288

IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can inpu…

Mitigation only
Fix from $2,300 2020-07-15
Iview HIGH 7.5
CVE-2020-14499

Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an att…

Fix: after 5.6
Fix from $1,950 2020-07-15
Opcenter Execution Core HIGH 8.1
CVE-2020-7578

A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users…

Fix: 8.2+
Fix from $1,950 2020-07-14