Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.8 CVE-2020-36197EPSS 18% An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attac… Music Station 5.1.14 / 5.2.10+ Fix from $1,9502021-05-13 MEDIUM 6.5 CVE-2021-1478 A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communicatio… Hosted Collaboration Mediation Fulfillment 12.6+ Fix from $1,6002021-05-06 HIGH 8.8 CVE-2021-1284 A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to by… Catalyst Sd Wan Manager 20.3.1 / 20.4.1+ Fix from $1,9502021-05-06 HIGH 7.5 CVE-2020-7038 A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker… Equinox Conferencing 9.1.11+ Fix from $1,9502021-04-28 HIGH 7.8 CVE-2021-22682 Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write a… Cscape 9.90+ Fix from $1,9502021-04-23 MEDIUM 5.3 CVE-2021-26909 Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an … Automox 31+ Fix from $1,6002021-04-23 MEDIUM 6.5 CVE-2021-24238 The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user maki… Findeo 1.2.4 / 1.3.1+ Fix from $1,6002021-04-22 HIGH 7.4 CVE-2021-0232 An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific informatio… Fedora 2.35.6 / 2.36.2+ Fix from $1,9502021-04-22 HIGH 7.8 CVE-2020-9668 Adobe Genuine Service version 6.6 (and earlier) is affected by an Improper Access control vulnerability when handling symbolic links. An unauthentica… Genuine Service after 6.6 Fix from $1,9502021-04-16 CRITICAL 9.8 CVE-2021-27258 This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati… Orion Platform Mitigation only Fix from $2,3002021-04-14 HIGH 7.5 CVE-2021-21399 Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the … Ampache 4.4.1+ Fix from $1,9502021-04-13 MEDIUM 5.3 CVE-2021-27598 SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ… Netweaver Application Server Java Mitigation only Fix from $1,6002021-04-13 CRITICAL 9.8 CVE-2021-24215EPSS 10% An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the webs… Controlled Admin Access 1.5.2+ Fix from $2,3002021-04-12 MEDIUM 5.3 CVE-2021-24219 The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin be… Focusblog 2.0.0+ Fix from $1,6002021-04-12 HIGH 8.1 CVE-2021-24197 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that v… Wpdatatables 3.4.2+ Fix from $1,9502021-04-12 HIGH 8.1 CVE-2021-24198 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that v… Wpdatatables 3.4.2+ Fix from $1,9502021-04-12 HIGH 8.1 CVE-2021-21431 sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot usin… Channelmgnt 2.0.1+ Fix from $1,9502021-04-09 CRITICAL 9.8 CVE-2021-21425EPSS 81% Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an una… Grav Plugin Admin 1.10.8+ Fix from $2,3002021-04-07 HIGH 7.8 CVE-2021-25349 Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijackin… Slow Motion Editor 3.5.18.5+ Fix from $1,9502021-03-25 MEDIUM 6.7 CVE-2021-1449 A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time.… Aironet Access Point Software 8.5.171.0 / 8.10.150.0+ Fix from $1,6002021-03-24 HIGH 7.2 CVE-2019-10200 A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloa… Openshift Container Platform Patch available Fix from $1,9502021-03-19 HIGH 7.8 CVE-2019-10128 A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down th… PostgreSQL 9.4.22 / 9.5.17+ Fix from $1,9502021-03-19 HIGH 8.8 CVE-2019-10127 A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL … PostgreSQL 9.4.22 / 9.5.17+ Fix from $1,9502021-03-19 HIGH 7.5 CVE-2021-24146EPSS 31% Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp… Modern Events Calendar Lite 5.16.5+ Fix from $1,9502021-03-18 HIGH 8.8 CVE-2021-25672 A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does no… Forgot Password 3.2.1+ Fix from $1,9502021-03-15 HIGH 7.2 CVE-2020-29020 Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the c… Sitemanager Firmware 9.4.620527004+ Fix from $1,9502021-03-05 MEDIUM 6.5 CVE-2021-22877 A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration whe… Nextcloud Server 20.0.6+ Fix from $1,6002021-03-03 MEDIUM 6.5 CVE-2021-1228 A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastr… Nx Os Mitigation only Fix from $1,6002021-02-24 MEDIUM 6.5 CVE-2021-26559 Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configur… Airflow Mitigation only Fix from $1,6002021-02-17 MEDIUM 5.4 CVE-2021-22853 The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific… Hr Portal Mitigation only Fix from $1,6002021-02-17