Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Vela MEDIUM 6.5
CVE-2021-21432

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0…

Fix: 0.7.5+
Fix from $1,600 2021-04-09
Enterprise Server MEDIUM 6.5
CVE-2021-22865

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web auth…

Fix: 2.21.18 / 2.22.10+
Fix from $1,600 2021-04-02
Bixby Voice HIGH 7.8
CVE-2021-25352

Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and mod…

Fix: 3.0.52.14+
Fix from $1,950 2021-03-25
Galaxy Themes HIGH 7.1
CVE-2021-25353

Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Theme…

Fix: 5.2.00.1215+
Fix from $1,950 2021-03-25
Internet MEDIUM 5.3
CVE-2021-25354

Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious…

Fix: 13.2.1.46+
Fix from $1,600 2021-03-25
Notes HIGH 7.8
CVE-2021-25355

Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking th…

Fix: 4.2.00.22+
Fix from $1,950 2021-03-25
Minio MEDIUM 6.5
CVE-2021-21362

MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before versio…

Fix: 2021-03-04t00-53-13z+
Fix from $1,600 2021-03-08
Enterprise Linux HIGH 7.5
CVE-2020-27779

A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove …

Fix: 2.06+
Fix from $1,950 2021-03-03
GitHub MEDIUM 6.5
CVE-2021-22861

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to gain write ac…

Fix: 2.20.24 / 2.21.15+
Fix from $1,600 2021-03-03
GitHub MEDIUM 6.5
CVE-2021-22862

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a rep…

Mitigation only
Fix from $1,600 2021-03-03
GitHub HIGH 8.1
CVE-2021-22863

An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance …

Fix: 2.20.24 / 2.21.15+
Fix from $1,950 2021-03-03
Emc Avamar Server HIGH 8.1
CVE-2021-21511

Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could …

Mitigation only
Fix from $1,950 2021-02-15
Magento MEDIUM 5.3
CVE-2021-21026

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authorization vulnerability in the i…

Fix: 2.3.6+
Fix from $1,600 2021-02-11
Symphony \+ Historian HIGH 8.8
CVE-2020-24674

In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users c…

Mitigation only
Fix from $1,950 2020-12-22
Pimcore MEDIUM 6.5
CVE-2020-26246

Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without hav…

Fix: 6.8.5+
Fix from $1,600 2020-12-03
C Cure Web MEDIUM 5.3
CVE-2020-9049

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated atta…

Fix: after 5.6
Fix from $1,600 2020-11-19
Pan Os HIGH 8.2
CVE-2020-2050

An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to…

Fix: 8.1.17 / 9.0.11+
Fix from $1,950 2020-11-12
Emc Networker MEDIUM 6.5
CVE-2020-26183

Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit t…

Fix: 19.3.0.2+
Fix from $1,600 2020-10-16
Victor Web Client HIGH 8.1
CVE-2020-9048

A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated…

Fix: after 5.4.1
Fix from $1,950 2020-10-08
Scadapack 7x Remote Connect HIGH 8.8
CVE-2020-7530

A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executabl…

Fix: after 3.6.3.574
Fix from $1,950 2020-09-16
Command Centre HIGH 7.7
CVE-2020-16096

In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(…

Fix: 7.80.960 / 7.90.991+
Fix from $1,950 2020-09-15
Bank Analyzer MEDIUM 6.5
CVE-2020-6311

Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly per…

Mitigation only
Fix from $1,600 2020-09-09
Nx Os HIGH 7.8
CVE-2020-3394

A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could …

Mitigation only
Fix from $1,950 2020-08-27
Automation License Manager HIGH 7.8
CVE-2020-7583

A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The applica…

Fix: 6.0.8+
Fix from $1,950 2020-08-14
Data Center Network Manager HIGH 8.8
CVE-2020-3386

A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privile…

Fix: 11.4+
Fix from $1,950 2020-07-31
Sd Wan CRITICAL 9.9
CVE-2020-3374

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…

Fix: 18.4.5 / 19.2.2+
Fix from $2,300 2020-07-31
Openclinic Ga HIGH 8.8
CVE-2020-14486

An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which …

Mitigation only
Fix from $1,950 2020-07-29
Rv110w Firmware MEDIUM 5.9
CVE-2020-3150

A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote…

Fix: 1.2.2.8 / 1.3.1.7+
Fix from $1,600 2020-07-16
Powerprotect Data Manager MEDIUM 6.5
CVE-2020-5356

Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulne…

Fix: 3.2 / 19.4+
Fix from $1,600 2020-07-06
Presto HIGH 8.8
CVE-2020-15087

In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. This impacts Presto server ins…

Fix: 337+
Fix from $1,950 2020-06-30