Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.2 CVE-2021-21045 Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an im… Acrobat after 20.013.20074 Fix from $1,9502021-02-11 MEDIUM 5.3 CVE-2021-21020 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control bypass vulnerability in the … Magento 2.3.6+ Fix from $1,6002021-02-11 HIGH 7.8 CVE-2020-25238 A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain … Simatic Process Control System Neo 3.1+ Fix from $1,9502021-02-09 MEDIUM 6.5 CVE-2021-1389 A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthentic… Ios Xr 6.6.3+ Fix from $1,6002021-02-04 HIGH 7.5 CVE-2021-1243 A vulnerability in the Local Packet Transport Services (LPTS) programming of the SNMP with the management plane protection feature of Cisco IOS XR So… Ios Xr 6.6.4 / 7.0.2+ Fix from $1,9502021-02-04 MEDIUM 6.5 CVE-2020-27873 This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 rout… Ac2100 Firmware 1.2.0.76+ Fix from $1,6002021-02-04 CRITICAL 9.8 CVE-2020-2506 KEV The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attacker… Helpdesk 3.0.3+ Fix from $2,3002021-02-03 HIGH 7.5 CVE-2019-20470 An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used … Q90 Junior Gps Horloge Firmware Mitigation only Fix from $1,9502021-02-01 MEDIUM 6.8 CVE-2019-20473 An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device cannot have a PIN configured. If a… Q90 Junior Gps Horloge Firmware Mitigation only Fix from $1,6002021-02-01 HIGH 7.5 CVE-2021-26118 While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 … Artemis Mitigation only Fix from $1,9502021-01-27 MEDIUM 5.8 CVE-2021-0205 When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or … Junos Mitigation only Fix from $1,6002021-01-15 CRITICAL 9.1 CVE-2018-19945 A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restri… Qts 4.3.4.0899 / 4.3.6.0895+ Fix from $2,3002020-12-31 HIGH 7.5 CVE-2020-2504 If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues… Qes 2.1.1+ Fix from $1,9502020-12-24 MEDIUM 6.5 CVE-2018-15645 Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users … Odoo after 12.0 Fix from $1,6002020-12-22 MEDIUM 6.5 CVE-2019-11782 Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to con… Odoo after 14.0 Fix from $1,6002020-12-22 MEDIUM 6.5 CVE-2019-11783 Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote auth… Odoo after 14.0 Fix from $1,6002020-12-22 MEDIUM 6.5 CVE-2019-11784 Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authent… Odoo after 14.0 Fix from $1,6002020-12-22 MEDIUM 6.5 CVE-2020-35497 A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email an… Virtualization after 4.4.3 Fix from $1,6002020-12-21 HIGH 7.8 CVE-2020-10143 Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service tha… Reflect 7.3.5281+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-25629 A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some … Moodle 3.5.14 / 3.7.8+ Fix from $1,9502020-12-08 HIGH 7.2 CVE-2020-7545 A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notificat… Ecostruxure Energy Expert Mitigation only Fix from $1,9502020-12-01 HIGH 8.8 CVE-2020-7547 A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notifica… Ecostruxure Energy Expert Mitigation only Fix from $1,9502020-12-01 HIGH 7.2 CVE-2020-25654 An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication wi… Debian Linux 1.1.23 / 2.0.3+ Fix from $1,9502020-11-24 MEDIUM 6.5 CVE-2020-7573 A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker be… Webreports after 3.1 Fix from $1,6002020-11-19 CRITICAL 9.8 CVE-2020-7561 A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide ra… Easergy T300 Firmware after 2.7 Fix from $2,3002020-11-19 HIGH 7.5 CVE-2020-25698 Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them … Moodle after 3.9.2 Fix from $1,9502020-11-19 MEDIUM 5.3 CVE-2020-25701 If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneousl… Moodle after 3.9.2 Fix from $1,6002020-11-19 MEDIUM 5.3 CVE-2020-8278 Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user. Social No fix yet Fix from $1,6002020-11-19 MEDIUM 6.5 CVE-2020-3482 A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote … Expressway Mitigation only Fix from $1,6002020-11-18 HIGH 8.7 CVE-2020-26072 A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify informat… Iot Field Network Director 4.6.1+ Fix from $1,9502020-11-18