Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2020-8193 KEVEPSS 88% Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW… Application Delivery Controller Firmware 10.2.7 / 10.5-70.18+ Fix from $1,6002020-07-10 MEDIUM 5.4 CVE-2020-15079 In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions.… Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 MEDIUM 6.5 CVE-2020-2500 This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive dat… Helpdesk 3.0.1+ Fix from $1,6002020-07-01 MEDIUM 6.1 CVE-2020-12024 Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to the USB inte… Em2400 Firmware Mitigation only Fix from $1,6002020-06-29 CRITICAL 9.0 CVE-2020-4062 In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with… Conjur Oss Helm Chart 2.0.0+ Fix from $2,3002020-06-22 MEDIUM 5.3 CVE-2020-3364 A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could all… Ios Xr Mitigation only Fix from $1,6002020-06-18 MEDIUM 5.3 CVE-2020-3245 A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to creat… Smart Software Manager On Prem 8-202004+ Fix from $1,6002020-06-18 CRITICAL 10.0 CVE-2020-12493 An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access contro… Cpu Ls4000 Firmware Mitigation only Fix from $2,3002020-05-29 HIGH 8.8 CVE-2020-6774 Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk M… Recording Station Firmware Mitigation only Fix from $1,9502020-05-27 HIGH 7.8 CVE-2020-9046 A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level pri… Kantech Entrapass after 8.22 Fix from $1,9502020-05-26 HIGH 8.8 CVE-2020-2025 Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can o… Runtime 1.11.0+ Fix from $1,9502020-05-19 CRITICAL 9.1 CVE-2020-10612 Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open with… Softpac Project after 9.6 Fix from $2,3002020-05-14 HIGH 8.1 CVE-2020-8153 Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name. Group Folders 4.0.4+ Fix from $1,9502020-05-12 HIGH 7.5 CVE-2020-3312 A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attac… Secure Firewall Management Center Mitigation only Fix from $1,9502020-05-06 MEDIUM 5.3 CVE-2020-3186 A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a… Secure Firewall Threat Defense 6.3.0.6 / 6.4.0.7+ Fix from $1,6002020-05-06 MEDIUM 6.7 CVE-2020-3253 A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access… Secure Firewall Threat Defense 6.5.0+ Fix from $1,6002020-05-06 MEDIUM 6.8 CVE-2020-8157 UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through … Unifi Cloud Key Gen2 Firmware after 1.1.10 Fix from $1,6002020-05-02 HIGH 7.5 CVE-2020-11028 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of… WordPress 5.4.1+ Fix from $1,9502020-04-30 HIGH 7.5 CVE-2020-10641 An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This res… Ignition Gateway 8.0.10+ Fix from $1,9502020-04-28 MEDIUM 6.5 CVE-2020-5287 In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5. Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5288 "In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5. Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5293 In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific pr… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5279 In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-d… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-7278 Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to… Endpoint Security Mitigation only Fix from $1,6002020-04-15 MEDIUM 6.5 CVE-2020-5302 MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access the steward commands on the IRC… Mh Wikibot 2020-04-06+ Fix from $1,6002020-04-07 HIGH 7.5 CVE-2019-3942 Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vu… Webaccess Mitigation only Fix from $1,9502020-04-01 MEDIUM 6.5 CVE-2020-8139 A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /do… Nextcloud Server 16.0.9 / 17.0.4+ Fix from $1,6002020-03-20 HIGH 7.8 CVE-2020-6971 In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate p… Valvelink after 13.4.118 Fix from $1,9502020-03-05 HIGH 8.8 CVE-2019-5162 An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13… Awk 3131a Firmware No fix yet Fix from $1,9502020-02-25 HIGH 8.8 CVE-2019-5136 An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially cra… Awk 3131a Firmware No fix yet Fix from $1,9502020-02-25