Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2020-26224 In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function th… Prestashop 1.7.6.9+ Fix from $1,9502020-11-16 MEDIUM 5.5 CVE-2020-24441 Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could… Acrobat Reader after 20.6.2 Fix from $1,6002020-11-12 MEDIUM 6.5 CVE-2020-3592 A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author… Catalyst Sd Wan Manager after 20.1.12 Fix from $1,6002020-11-06 CRITICAL 9.8 CVE-2020-3284 A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remo… A9k Rsp880 Se Firmware 1.12 / 1.21+ Fix from $2,3002020-11-06 MEDIUM 6.5 CVE-2020-25662 A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of s… Enterprise Linux Mitigation only Fix from $1,6002020-11-05 HIGH 7.8 CVE-2020-24433EPSS 16% Adobe Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a local … Acrobat after 20.012.20048 Fix from $1,9502020-11-05 MEDIUM 6.8 CVE-2020-16261 Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access. Winston Firmware No fix yet Fix from $1,6002020-10-28 MEDIUM 5.3 CVE-2020-3564 A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… Adaptive Security Appliance 6.3.0.6 / 6.4.0.10+ Fix from $1,6002020-10-21 MEDIUM 5.8 CVE-2020-3565 A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t… Secure Firewall Threat Defense 6.4.0.8 / 6.5.0.4+ Fix from $1,6002020-10-21 HIGH 7.8 CVE-2020-10138 Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins… Cyber Backup 12.5 / 15+ Fix from $1,9502020-10-21 HIGH 7.8 CVE-2020-10139 Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True … True Image Mitigation only Fix from $1,9502020-10-21 MEDIUM 6.6 CVE-2020-1666 The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the … Junos Os Evolved Mitigation only Fix from $1,6002020-10-16 HIGH 8.0 CVE-2020-8182 Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves. Deck No fix yet Fix from $1,9502020-10-05 MEDIUM 6.8 CVE-2020-3524 A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cisco ASR 920 Series Aggregation… Ios Xe Rom Monitor 15.6 / 16.2+ Fix from $1,6002020-09-24 MEDIUM 6.0 CVE-2020-3503 A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access … Ios Xe Mitigation only Fix from $1,6002020-09-24 HIGH 7.2 CVE-2020-3396 A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical … Ios Xe Mitigation only Fix from $1,9502020-09-24 CRITICAL 9.8 CVE-2020-15181 The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the sy… Reset Password 1.2.0+ Fix from $2,3002020-09-18 CRITICAL 9.3 CVE-2020-8028 A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy … Salt Netapi Client 0.16.0-4.14.1 / 0.17.0-3.3.2+ Fix from $2,3002020-09-17 HIGH 7.8 CVE-2020-7531 A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place execut… Scadapack 7x Remote Connect after 3.6.3.574 Fix from $1,9502020-09-16 MEDIUM 6.3 CVE-2020-3522 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attac… Data Center Network Manager 11.4+ Fix from $1,6002020-08-26 MEDIUM 5.8 CVE-2020-3448 A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authen… Cyber Vision Center 3.0.4+ Fix from $1,6002020-08-17 HIGH 8.8 CVE-2020-5396 VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed… Gemfire 1.10.2 / 1.11.1+ Fix from $1,9502020-07-31 CRITICAL 9.9 CVE-2020-10731 A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw cause… Openstack Platform Mitigation only Fix from $2,3002020-07-31 MEDIUM 6.5 CVE-2020-10930 This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 r… R6700 Firmware Mitigation only Fix from $1,6002020-07-28 HIGH 8.8 CVE-2020-8207 Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic upd… Workspace Mitigation only Fix from $1,9502020-07-24 MEDIUM 6.5 CVE-2020-15102 In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The … Dashboard Products 2.1.0+ Fix from $1,6002020-07-21 CRITICAL 9.8 CVE-2020-3144 A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction … Rv110w Firmware 1.0.3.55 / 1.2.2.8+ Fix from $2,3002020-07-16 CRITICAL 9.8 CVE-2020-10288 IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can inpu… Robotware Mitigation only Fix from $2,3002020-07-15 HIGH 7.5 CVE-2020-14499 Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an att… Iview after 5.6 Fix from $1,9502020-07-15 HIGH 8.1 CVE-2020-7578 A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users… Opcenter Execution Core 8.2+ Fix from $1,9502020-07-14