Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.8 CVE-2021-34401 NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to … Shield Experience 9.0+ Fix from $1,9502022-01-18 MEDIUM 6.7 CVE-2021-34402 NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memor… Shield Experience 9.0+ Fix from $1,6002022-01-18 MEDIUM 6.5 CVE-2021-37864 Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view conte… Mattermost after 6.1 Fix from $1,6002022-01-18 HIGH 7.1 CVE-2021-28507 An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RE… Eos after 4.26.2f Fix from $1,9502022-01-14 HIGH 7.3 CVE-2022-23132 During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix … Fedora after 5.4.8 Fix from $1,9502022-01-13 MEDIUM 5.3 CVE-2022-23134 KEVEPSS 85% After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M… Fedora after 5.4.8 Fix from $1,6002022-01-13 HIGH 7.5 CVE-2021-45034 A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (Al… Cp 8000 Master Module With I\/o 25\/\+70 Firmware 16.20+ Fix from $1,9502022-01-11 HIGH 7.5 CVE-2022-0133 peertube is vulnerable to Improper Access Control Peertube 2022-01-06+ Fix from $1,9502022-01-10 MEDIUM 6.5 CVE-2021-4194 bookstack is vulnerable to Improper Access Control Bookstack 21.12.1+ Fix from $1,6002022-01-06 HIGH 7.3 CVE-2021-25991 In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to … Ifme after 7.32 Fix from $1,9502021-12-29 HIGH 7.5 CVE-2021-20050 An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, pot… Sma 100 Firmware 10.0.0.0+ Fix from $1,9502021-12-23 MEDIUM 6.7 CVE-2021-42808 Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. Sentinel Protection Installer 7.7.1+ Fix from $1,6002021-12-20 CRITICAL 9.8 CVE-2021-4119EPSS 27% bookstack is vulnerable to Improper Access Control Bookstack after 21.11.2 Fix from $2,3002021-12-15 CRITICAL 9.8 CVE-2021-36888EPSS 7% Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6… Image Hover Effects 9.6.1+ Fix from $2,3002021-12-15 MEDIUM 6.5 CVE-2021-24845 The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve… Improved Include Page after 1.2 Fix from $1,6002021-12-13 MEDIUM 6.5 CVE-2021-22565 An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to genera… Exposure Notification Verification Server 1.1.2+ Fix from $1,6002021-12-09 HIGH 8.8 CVE-2021-42124 An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a … Avalanche 6.3.3+ Fix from $1,9502021-12-07 MEDIUM 6.8 CVE-2021-35245 When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine. Serv U 15.2.4+ Fix from $1,6002021-12-06 HIGH 8.1 CVE-2020-10627 Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manu… Omnipod Insulin Management System Firmware Mitigation only Fix from $1,9502021-12-01 CRITICAL 9.9 CVE-2021-26334 The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation an… Amd Uprof 3.4.494 / 3.4.502+ Fix from $2,3002021-12-01 MEDIUM 6.5 CVE-2021-3992 kimai2 is vulnerable to Improper Access Control Kimai2 1.16.2+ Fix from $1,6002021-12-01 HIGH 7.5 CVE-2021-36917 WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can th… Hide My Wp after 6.2.3 Fix from $1,9502021-11-24 CRITICAL 10.0 CVE-2021-3554 Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows… Endpoint Security Tools 6.6.27.390 / 6.24.1-1+ Fix from $2,3002021-11-24 HIGH 8.1 CVE-2021-36909 Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the enti… Wp Reset Pro after 5.98 Fix from $1,9502021-11-18 HIGH 7.1 CVE-2021-35528 Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlemen… Counterparty Settlements And Billing after 5.7.3 Fix from $1,9502021-11-17 MEDIUM 5.4 CVE-2021-42360 On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contrib… Starter Templates after 2.7.0 Fix from $1,6002021-11-17 HIGH 7.5 CVE-2021-26338 Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting i… Epyc 7f72 Firmware Mitigation only Fix from $1,9502021-11-16 HIGH 8.8 CVE-2021-3062 An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to co… Pan Os 8.1.20 / 9.0.14+ Fix from $1,9502021-11-10 MEDIUM 5.5 CVE-2020-12488 The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without reques… Jovi Smart Scene 6.2.2.52+ Fix from $1,6002021-11-10 CRITICAL 9.1 CVE-2021-42359 WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available … Wp Dsgvo Tools after 3.1.23 Fix from $2,3002021-11-05