Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2020-5244 In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. Th… Buddypress 5.1.2+ Fix from $1,9502020-02-24 HIGH 8.8 CVE-2020-5242 openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary comma… Openhab 2.5.2+ Fix from $1,9502020-02-20 HIGH 7.1 CVE-2019-18998 Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables… Asset Suite 9.4.2.6 / 9.5.3.2+ Fix from $1,9502020-02-17 HIGH 7.5 CVE-2019-6193 An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated… Xclarity Administrator 2.6.6+ Fix from $1,9502020-02-14 HIGH 8.1 CVE-2020-8121 A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer. Nextcloud Server 13.0.9 / 14.0.5+ Fix from $1,9502020-02-04 MEDIUM 6.1 CVE-2019-15615 A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past. Nextcloud after 3.9.0 Fix from $1,6002020-02-04 MEDIUM 6.5 CVE-2019-5474 An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden witho… GitLab 11.11.6 / 12.0.4+ Fix from $1,6002020-01-28 HIGH 7.5 CVE-2019-15590 An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge… GitLab 12.1.14 / 12.2.8+ Fix from $1,9502020-01-28 HIGH 7.5 CVE-2020-3142 A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a p… Webex Meetings Online 39.11.5 / 40.1.3+ Fix from $1,9502020-01-26 MEDIUM 6.5 CVE-2019-15255 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass… Identity Services Engine Mitigation only Fix from $1,6002020-01-26 MEDIUM 5.4 CVE-2019-14902 There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, wh… Ubuntu Linux 4.9.18 / 4.10.12+ Fix from $1,6002020-01-21 MEDIUM 6.5 CVE-2019-18275 OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control, which may return unauth… Pi Vision 2019+ Fix from $1,6002020-01-15 MEDIUM 5.3 CVE-2020-1604 On EX4300, EX4600, QFX3500, and QFX5100 Series, a vulnerability in the IP firewall filter component may cause the firewall filter evaluation of certa… Junos Mitigation only Fix from $1,6002020-01-15 MEDIUM 6.3 CVE-2019-15999 A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unau… Data Center Network Manager 11.3+ Fix from $1,6002020-01-06 HIGH 8.1 CVE-2019-11780 Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated at… Odoo Patch available Fix from $1,9502019-12-19 MEDIUM 5.3 CVE-2019-5487 An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch… GitLab 12.1.13 / 12.2.7+ Fix from $1,6002019-12-18 HIGH 8.8 CVE-2019-15589 An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clo… GitLab 12.1.12 / 12.2.6+ Fix from $1,9502019-12-18 MEDIUM 6.5 CVE-2019-15591 An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through… GitLab 12.3.3+ Fix from $1,6002019-12-18 HIGH 7.8 CVE-2019-18308 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a lo… Sppa T3000 Ms3000 Migration Server Mitigation only Fix from $1,9502019-12-12 HIGH 7.8 CVE-2019-18309 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a lo… Sppa T3000 Ms3000 Migration Server Mitigation only Fix from $1,9502019-12-12 MEDIUM 5.3 CVE-2019-15998 A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access c… Ios Xr Mitigation only Fix from $1,6002019-11-26 HIGH 8.8 CVE-2019-15956 A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote… Asyncos 10.1.5-004 / 11.5.3-016+ Fix from $1,9502019-11-26 CRITICAL 9.8 CVE-2019-5617 Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Impro… Computing For Good\'s Basic Laboratory Information System after 3.4 Fix from $2,3002019-11-06 MEDIUM 5.3 CVE-2019-5643 Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Impro… Computing For Good\'s Basic Laboratory Information System after 3.5 Fix from $1,6002019-11-06 CRITICAL 9.8 CVE-2019-5644 Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Impro… Computing For Good\'s Basic Laboratory Information System after 3.5 Fix from $2,3002019-11-06 MEDIUM 6.5 CVE-2019-6144 This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web prot… One Endpoint after 19.08 Fix from $1,6002019-10-23 CRITICAL 9.8 CVE-2019-15260 A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a target… Aironet 1540 Firmware 8.5.151.0 / 8.8.120.0+ Fix from $2,3002019-10-16 MEDIUM 5.5 CVE-2019-9529 The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, … Explorer 710 Firmware Mitigation only Fix from $1,6002019-10-10 MEDIUM 5.5 CVE-2019-9530 The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files. This could… Explorer 710 Firmware Mitigation only Fix from $1,6002019-10-10 CRITICAL 9.8 CVE-2019-9531 The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthe… Explorer 710 Firmware Mitigation only Fix from $2,3002019-10-10