Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8193 KEVEPSS 88%

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Prestashop MEDIUM 5.4
CVE-2020-15079

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions.…

Fix: 1.7.6.6+
Fix from $1,600 2020-07-02
Helpdesk MEDIUM 6.5
CVE-2020-2500

This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive dat…

Fix: 3.0.1+
Fix from $1,600 2020-07-01
Em2400 Firmware MEDIUM 6.1
CVE-2020-12024

Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to the USB inte…

Mitigation only
Fix from $1,600 2020-06-29
Conjur Oss Helm Chart CRITICAL 9.0
CVE-2020-4062

In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with…

Fix: 2.0.0+
Fix from $2,300 2020-06-22
Ios Xr MEDIUM 5.3
CVE-2020-3364

A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could all…

Mitigation only
Fix from $1,600 2020-06-18
Smart Software Manager On Prem MEDIUM 5.3
CVE-2020-3245

A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to creat…

Fix: 8-202004+
Fix from $1,600 2020-06-18
Cpu Ls4000 Firmware CRITICAL 10.0
CVE-2020-12493

An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access contro…

Mitigation only
Fix from $2,300 2020-05-29
Recording Station Firmware HIGH 8.8
CVE-2020-6774

Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk M…

Mitigation only
Fix from $1,950 2020-05-27
Kantech Entrapass HIGH 7.8
CVE-2020-9046

A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level pri…

Fix: after 8.22
Fix from $1,950 2020-05-26
Runtime HIGH 8.8
CVE-2020-2025

Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can o…

Fix: 1.11.0+
Fix from $1,950 2020-05-19
Softpac Project CRITICAL 9.1
CVE-2020-10612

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open with…

Fix: after 9.6
Fix from $2,300 2020-05-14
Group Folders HIGH 8.1
CVE-2020-8153

Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.

Fix: 4.0.4+
Fix from $1,950 2020-05-12
Secure Firewall Management Center HIGH 7.5
CVE-2020-3312

A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attac…

Mitigation only
Fix from $1,950 2020-05-06
Secure Firewall Threat Defense MEDIUM 5.3
CVE-2020-3186

A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a…

Fix: 6.3.0.6 / 6.4.0.7+
Fix from $1,600 2020-05-06
Secure Firewall Threat Defense MEDIUM 6.7
CVE-2020-3253

A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access…

Fix: 6.5.0+
Fix from $1,600 2020-05-06
Unifi Cloud Key Gen2 Firmware MEDIUM 6.8
CVE-2020-8157

UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through …

Fix: after 1.1.10
Fix from $1,600 2020-05-02
WordPress HIGH 7.5
CVE-2020-11028

In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of…

Fix: 5.4.1+
Fix from $1,950 2020-04-30
Ignition Gateway HIGH 7.5
CVE-2020-10641

An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This res…

Fix: 8.0.10+
Fix from $1,950 2020-04-28
Prestashop MEDIUM 6.5
CVE-2020-5287

In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Prestashop MEDIUM 6.5
CVE-2020-5288

"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5.

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Prestashop MEDIUM 6.5
CVE-2020-5293

In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific pr…

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Prestashop MEDIUM 6.5
CVE-2020-5279

In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-d…

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Endpoint Security MEDIUM 6.5
CVE-2020-7278

Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to…

Mitigation only
Fix from $1,600 2020-04-15
Mh Wikibot MEDIUM 6.5
CVE-2020-5302

MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access the steward commands on the IRC…

Fix: 2020-04-06+
Fix from $1,600 2020-04-07
Webaccess HIGH 7.5
CVE-2019-3942

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vu…

Mitigation only
Fix from $1,950 2020-04-01
Nextcloud Server MEDIUM 6.5
CVE-2020-8139

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /do…

Fix: 16.0.9 / 17.0.4+
Fix from $1,600 2020-03-20
Valvelink HIGH 7.8
CVE-2020-6971

In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate p…

Fix: after 13.4.118
Fix from $1,950 2020-03-05
Awk 3131a Firmware HIGH 8.8
CVE-2019-5162

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13…

No fix yet
Fix from $1,950 2020-02-25
Awk 3131a Firmware HIGH 8.8
CVE-2019-5136

An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially cra…

No fix yet
Fix from $1,950 2020-02-25