Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Buddypress HIGH 7.5
CVE-2020-5244

In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. Th…

Fix: 5.1.2+
Fix from $1,950 2020-02-24
Openhab HIGH 8.8
CVE-2020-5242

openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary comma…

Fix: 2.5.2+
Fix from $1,950 2020-02-20
Asset Suite HIGH 7.1
CVE-2019-18998

Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables…

Fix: 9.4.2.6 / 9.5.3.2+
Fix from $1,950 2020-02-17
Xclarity Administrator HIGH 7.5
CVE-2019-6193

An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated…

Fix: 2.6.6+
Fix from $1,950 2020-02-14
Nextcloud Server HIGH 8.1
CVE-2020-8121

A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

Fix: 13.0.9 / 14.0.5+
Fix from $1,950 2020-02-04
Nextcloud MEDIUM 6.1
CVE-2019-15615

A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.

Fix: after 3.9.0
Fix from $1,600 2020-02-04
GitLab MEDIUM 6.5
CVE-2019-5474

An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden witho…

Fix: 11.11.6 / 12.0.4+
Fix from $1,600 2020-01-28
GitLab HIGH 7.5
CVE-2019-15590

An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge…

Fix: 12.1.14 / 12.2.8+
Fix from $1,950 2020-01-28
Webex Meetings Online HIGH 7.5
CVE-2020-3142

A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a p…

Fix: 39.11.5 / 40.1.3+
Fix from $1,950 2020-01-26
Identity Services Engine MEDIUM 6.5
CVE-2019-15255

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass…

Mitigation only
Fix from $1,600 2020-01-26
Ubuntu Linux MEDIUM 5.4
CVE-2019-14902

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, wh…

Fix: 4.9.18 / 4.10.12+
Fix from $1,600 2020-01-21
Pi Vision MEDIUM 6.5
CVE-2019-18275

OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control, which may return unauth…

Fix: 2019+
Fix from $1,600 2020-01-15
Junos MEDIUM 5.3
CVE-2020-1604

On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewall filter evaluation of certa…

Mitigation only
Fix from $1,600 2020-01-15
Data Center Network Manager MEDIUM 6.3
CVE-2019-15999

A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unau…

Fix: 11.3+
Fix from $1,600 2020-01-06
Odoo HIGH 8.1
CVE-2019-11780

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated at…

Patch available
Fix from $1,950 2019-12-19
GitLab MEDIUM 5.3
CVE-2019-5487

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch…

Fix: 12.1.13 / 12.2.7+
Fix from $1,600 2019-12-18
GitLab HIGH 8.8
CVE-2019-15589

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clo…

Fix: 12.1.12 / 12.2.6+
Fix from $1,950 2019-12-18
GitLab MEDIUM 6.5
CVE-2019-15591

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through…

Fix: 12.3.3+
Fix from $1,600 2019-12-18
Sppa T3000 Ms3000 Migration Server HIGH 7.8
CVE-2019-18308

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a lo…

Mitigation only
Fix from $1,950 2019-12-12
Sppa T3000 Ms3000 Migration Server HIGH 7.8
CVE-2019-18309

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a lo…

Mitigation only
Fix from $1,950 2019-12-12
Ios Xr MEDIUM 5.3
CVE-2019-15998

A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access c…

Mitigation only
Fix from $1,600 2019-11-26
Asyncos HIGH 8.8
CVE-2019-15956

A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote…

Fix: 10.1.5-004 / 11.5.3-016+
Fix from $1,950 2019-11-26
Computing For Good\'s Basic Laboratory Information System CRITICAL 9.8
CVE-2019-5617

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Impro…

Fix: after 3.4
Fix from $2,300 2019-11-06
Computing For Good\'s Basic Laboratory Information System MEDIUM 5.3
CVE-2019-5643

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Impro…

Fix: after 3.5
Fix from $1,600 2019-11-06
Computing For Good\'s Basic Laboratory Information System CRITICAL 9.8
CVE-2019-5644

Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Impro…

Fix: after 3.5
Fix from $2,300 2019-11-06
One Endpoint MEDIUM 6.5
CVE-2019-6144

This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web prot…

Fix: after 19.08
Fix from $1,600 2019-10-23
Aironet 1540 Firmware CRITICAL 9.8
CVE-2019-15260

A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a target…

Fix: 8.5.151.0 / 8.8.120.0+
Fix from $2,300 2019-10-16
Explorer 710 Firmware MEDIUM 5.5
CVE-2019-9529

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, …

Mitigation only
Fix from $1,600 2019-10-10
Explorer 710 Firmware MEDIUM 5.5
CVE-2019-9530

The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files. This could…

Mitigation only
Fix from $1,600 2019-10-10
Explorer 710 Firmware CRITICAL 9.8
CVE-2019-9531

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthe…

Mitigation only
Fix from $2,300 2019-10-10