Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Jira MEDIUM 6.5
CVE-2021-41308

Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication se…

Fix: 8.6.0 / 8.13.12+
Fix from $1,600 2021-10-26
Junos CRITICAL 10.0
CVE-2021-31384

Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in …

Mitigation only
Fix from $2,300 2021-10-19
Ir615 Firmware HIGH 8.5
CVE-2021-38486

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any req…

Mitigation only
Fix from $1,950 2021-10-19
Xinhe Teaching Platform System HIGH 8.8
CVE-2021-42330

The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attacker…

Mitigation only
Fix from $1,950 2021-10-15
Xinhe Teaching Platform System MEDIUM 5.4
CVE-2021-42331

The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers…

Mitigation only
Fix from $1,600 2021-10-15
Minio HIGH 8.8
CVE-2021-41137

Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that …

Patch available
Fix from $1,950 2021-10-13
Sinec Nms MEDIUM 6.5
CVE-2021-33723

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any u…

Fix: 1.0+
Fix from $1,600 2021-10-12
Access Demo Importer HIGH 8.8
CVE-2021-39317

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_insta…

Fix: 1.0.7+
Fix from $1,950 2021-10-11
Tad Web MEDIUM 6.5
CVE-2021-41568

Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin b…

Fix: after 1.76
Fix from $1,600 2021-10-08
Tad Book3 CRITICAL 9.1
CVE-2021-41974

Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content o…

Fix: 3.9+
Fix from $2,300 2021-10-08
Tadtools CRITICAL 9.1
CVE-2021-41975

TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the sy…

Fix: 3.2.2+
Fix from $2,300 2021-10-08
Tad Uploader MEDIUM 5.3
CVE-2021-41976

Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in t…

Fix: 3.5.4+
Fix from $1,600 2021-10-08
Tad Honor MEDIUM 6.5
CVE-2021-41564

Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbit…

Fix: 1.47+
Fix from $1,600 2021-10-08
Galaxy Store MEDIUM 5.5
CVE-2021-25499

Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provi…

Fix: 4.5.32.4+
Fix from $1,600 2021-10-06
Wire CRITICAL 9.8
CVE-2021-41093

Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by …

Fix: 3.86+
Fix from $2,300 2021-10-04
Wire Server CRITICAL 9.8
CVE-2021-41100

Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address…

Fix: 2021-08-16+
Fix from $2,300 2021-10-04
Android MEDIUM 5.5
CVE-2021-25459

An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZSe…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25460

An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate Blockchain…

Mitigation only
Fix from $1,600 2021-09-09
Magento MEDIUM 6.5
CVE-2021-28567

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in …

Fix: after 2.4.2
Fix from $1,600 2021-09-08
Adobe Commerce HIGH 7.2
CVE-2021-36029

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vuln…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Adobe Commerce MEDIUM 6.5
CVE-2021-36037

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vuln…

Fix: after 2.4.2
Fix from $1,600 2021-09-01
Fedora MEDIUM 5.3
CVE-2021-34434

In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is …

Fix: after 2.0.11
Fix from $1,600 2021-08-30
Ac2000 Firmware CRITICAL 9.8
CVE-2021-27663

A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequat…

Fix: after 10.5
Fix from $2,300 2021-08-30
Experience Manager HIGH 7.5
CVE-2021-28626

Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Authorization vulnerability allow…

Fix: after 6.5.8.0
Fix from $1,950 2021-08-24
Smart Camera C2e Firmware CRITICAL 9.8
CVE-2021-3616

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware …

Fix: 01.03.29.16+
Fix from $2,300 2021-08-17
Onefuzz CRITICAL 10.0
CVE-2021-37705

OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow…

Fix: 2.31.0+
Fix from $2,300 2021-08-13
Dbutildrv2.sys Firmware HIGH 7.8
CVE-2021-36276

Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, d…

Patch available
Fix from $1,950 2021-08-09
Orca Hcm CRITICAL 9.8
CVE-2021-35964

The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the ma…

Fix: after 10.0
Fix from $2,300 2021-07-19
Nextcloud Server HIGH 8.8
CVE-2021-32688

Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes.…

Fix: 19.0.13 / 20.0.11+
Fix from $1,950 2021-07-12
Business Process Automation HIGH 8.8
CVE-2021-1576

Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack…

Fix: 3.1+
Fix from $1,950 2021-07-08