Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Business Process Automation HIGH 8.8
CVE-2021-1574

Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack…

Fix: 3.1+
Fix from $1,950 2021-07-08
Tizen MEDIUM 5.5
CVE-2021-25433

Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications to perform…

Fix: 5.5+
Fix from $1,600 2021-07-08
Storage Manager HIGH 7.2
CVE-2021-32523

Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary comman…

Fix: after 3.3.1
Fix from $1,950 2021-07-07
Magento MEDIUM 6.5
CVE-2021-28563

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via t…

Fix: 2.3.7+
Fix from $1,600 2021-06-28
Cortex Xsoar CRITICAL 9.8
CVE-2021-3044

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Corte…

Mitigation only
Fix from $2,300 2021-06-22
Command Centre HIGH 8.8
CVE-2021-23140

Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre O…

Fix: 8.20.1259 / 8.30.1359+
Fix from $1,950 2021-06-11
Command Centre MEDIUM 6.5
CVE-2021-23136

Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Oper…

Fix: 8.20.1259 / 8.30.1359+
Fix from $1,600 2021-06-11
Android HIGH 7.5
CVE-2021-25417

Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.

Mitigation only
Fix from $1,950 2021-06-11
Smart Manager HIGH 7.1
CVE-2021-25399

Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.

Fix: 11.0.05.0+
Fix from $1,950 2021-06-11
Cloudforms HIGH 8.1
CVE-2020-25716

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a…

Fix: 5.11.10.1+
Fix from $1,950 2021-06-07
Openstack Selinux MEDIUM 6.5
CVE-2020-1690

An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from pri…

Fix: 0.8.24+
Fix from $1,600 2021-06-07
Deno CRITICAL 9.8
CVE-2021-32619

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imp…

Fix: 1.10.2+
Fix from $2,300 2021-05-28
Xwiki HIGH 8.8
CVE-2021-32620

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 1…

Fix: 11.10.13 / 12.6.7+
Fix from $1,950 2021-05-28
Satellite MEDIUM 6.5
CVE-2020-10716

A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a mali…

Fix: 4.0.3.4+
Fix from $1,600 2021-05-27
Sitemap HIGH 8.8
CVE-2021-24192

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install an…

Fix: 2.9+
Fix from $1,950 2021-05-14
Visitor Traffic Real Time Statistics HIGH 8.8
CVE-2021-24193

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin b…

Fix: 2.12+
Fix from $1,950 2021-05-14
Login Protection Limit Failed Login Attempts HIGH 8.8
CVE-2021-24194

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPres…

Fix: 2.9+
Fix from $1,950 2021-05-14
Login As User Or Customer \(user Switching\) HIGH 8.8
CVE-2021-24195

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress pl…

Fix: 1.8+
Fix from $1,950 2021-05-14
Wp Content Copy Protection \& No Right Click HIGH 8.8
CVE-2021-24188

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress p…

Fix: 3.1.5+
Fix from $1,950 2021-05-14
Captchinoo HIGH 8.8
CVE-2021-24189

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordP…

Fix: 2.4+
Fix from $1,950 2021-05-14
Conditional Marketing Mailer HIGH 8.8
CVE-2021-24190

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plug…

Fix: 1.5.2+
Fix from $1,950 2021-05-14
Coming Soon Page \& Maintenance Mode HIGH 8.8
CVE-2021-24191

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress…

Fix: 1.8.2+
Fix from $1,950 2021-05-14
Hybrid Backup Sync CRITICAL 9.8
CVE-2021-28799 KEVEPSS 78%

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability all…

Fix: 3.0.210411 / 3.0.210412+
Fix from $2,300 2021-05-13
Ozone HIGH 7.5
CVE-2020-17517

The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allo…

Fix: 1.1.0+
Fix from $1,950 2021-04-27
Android MEDIUM 5.5
CVE-2021-25382

An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secur…

Mitigation only
Fix from $1,600 2021-04-23
Junos HIGH 7.3
CVE-2021-0260

An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauth…

Mitigation only
Fix from $1,950 2021-04-22
Bridge MEDIUM 5.5
CVE-2021-21096

Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software S…

Fix: after 11.0.1
Fix from $1,600 2021-04-15
Customization Service HIGH 7.8
CVE-2021-25373

Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10…

Fix: 2.2.02.1 / 2.4.03.0+
Fix from $1,950 2021-04-09
Members HIGH 7.5
CVE-2021-25374

An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and…

Fix: after 2.4.83.9
Fix from $1,950 2021-04-09
Account HIGH 7.8
CVE-2021-25381

Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows loca…

Mitigation only
Fix from $1,950 2021-04-09