Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.1 CVE-2021-1577 A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con… Application Policy Infrastructure Controller 3.2 / 4.2+ Fix from $2,3002021-08-25 HIGH 7.2 CVE-2021-25956 In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to vali… Dolibarr after 13.0.2 Fix from $1,9502021-08-17 HIGH 8.1 CVE-2021-24500 Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer… Workreap 2.2.2+ Fix from $1,9502021-08-09 MEDIUM 6.5 CVE-2021-22920 A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Cit… Application Delivery Management Mitigation only Fix from $1,6002021-08-05 MEDIUM 5.3 CVE-2021-25446 Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in w… Smartthings Firmware 1.7.67.25+ Fix from $1,6002021-08-05 MEDIUM 5.3 CVE-2021-25447 Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webvie… Smartthings Firmware 1.7.67.25+ Fix from $1,6002021-08-05 MEDIUM 5.3 CVE-2021-25448 Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview. Smart Touch Call 1.0.0.5+ Fix from $1,6002021-08-05 HIGH 8.3 CVE-2021-1600 Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal service… Intersight Virtual Appliance Patch available Fix from $1,9502021-07-22 HIGH 8.3 CVE-2021-1601 Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal service… Intersight Virtual Appliance Patch available Fix from $1,9502021-07-22 CRITICAL 9.9 CVE-2021-25320 A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the clou… Rancher 2.4.16 / 2.5.9+ Fix from $2,3002021-07-15 MEDIUM 6.5 CVE-2021-32753 EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edi… Edgex Foundry 2.0.0+ Fix from $1,6002021-07-09 HIGH 7.8 CVE-2021-25440 Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an esca… Factorycamerafb 3.4.74+ Fix from $1,9502021-07-08 MEDIUM 5.5 CVE-2021-25431 Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows untrusted a… Cameralyzer 3.2.1041 / 3.3.1040+ Fix from $1,6002021-07-08 HIGH 7.8 CVE-2021-25438 Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and… Members 2.4.85.11+ Fix from $1,9502021-07-08 CRITICAL 9.8 CVE-2021-28809EPSS 16% An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attack… Hybrid Backup Sync 3.0.210506 / 3.0.210507+ Fix from $2,3002021-07-08 HIGH 7.5 CVE-2021-32514 Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and discontinue the device. The re… Storage Manager 3.3.3+ Fix from $1,9502021-07-07 HIGH 7.5 CVE-2021-32517 Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files using particular para… Storage Manager 3.3.3+ Fix from $1,9502021-07-07 HIGH 7.5 CVE-2021-21083 AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access… Experience Manager 6.4.8.4 / 6.5.8.0+ Fix from $1,9502021-06-28 HIGH 8.8 CVE-2021-23845 This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovere… B426 Firmware 03.08 / 03.10+ Fix from $1,9502021-06-18 MEDIUM 6.5 CVE-2020-8300 Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper ac… Gateway 11.1-65.20 / 12.1-55.238+ Fix from $1,6002021-06-16 MEDIUM 5.3 CVE-2021-24359 The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legi… The Plus Addons For Elementor 4.1.11+ Fix from $1,6002021-06-14 HIGH 7.8 CVE-2021-25412 An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity wi… Android Mitigation only Fix from $1,9502021-06-11 MEDIUM 5.5 CVE-2021-25405 An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access loc… Notes 4.2.04.27+ Fix from $1,6002021-06-11 MEDIUM 6.3 CVE-2020-14388 A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This f… 3scale Api Management Mitigation only Fix from $1,6002021-06-02 HIGH 8.6 CVE-2021-32656 Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions prior to 19.0.11, 20.0.10, a… Nextcloud Server 19.0.11 / 20.0.10+ Fix from $1,9502021-06-01 MEDIUM 6.5 CVE-2021-24318 The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any … Listeo 1.6.11+ Fix from $1,6002021-06-01 HIGH 7.8 CVE-2020-10145 The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By … Coldfusion Mitigation only Fix from $1,9502021-05-27 HIGH 7.8 CVE-2021-22907 An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2… Workspace 19.12.4000 / 2105+ Fix from $1,9502021-05-27 MEDIUM 5.4 CVE-2020-25634 A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive informa… 3scale 2.10.0+ Fix from $1,6002021-05-26 HIGH 7.5 CVE-2021-28798 A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attac… Qts 4.3.3.1624 / 4.3.6.1663+ Fix from $1,9502021-05-21