Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Express Jwt CRITICAL 9.1
CVE-2020-15084

In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When al…

Fix: after 5.3.3
Fix from $2,300 2020-06-30
Ceph HIGH 8.0
CVE-2020-10736

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restri…

Fix: 15.2.2+
Fix from $1,950 2020-06-22
Unified Contact Center Express HIGH 7.1
CVE-2020-3267

A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change th…

Fix: 12.5+
Fix from $1,950 2020-06-03
GitHub CRITICAL 9.8
CVE-2020-10516

An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissio…

Fix: 2.18.20 / 2.19.15+
Fix from $2,300 2020-06-03
Softpac Project CRITICAL 9.8
CVE-2020-10620

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to…

Fix: after 9.6
Fix from $2,300 2020-05-14
Pan Os HIGH 8.8
CVE-2020-1998

An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions …

Fix: 7.1.26 / 8.1.13+
Fix from $1,950 2020-05-13
Undertow CRITICAL 9.8
CVE-2020-1745

A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final …

Fix: after 2.0.29
Fix from $2,300 2020-04-28
Mark Vie Control System HIGH 8.8
CVE-2019-13554

GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. G…

Mitigation only
Fix from $1,950 2020-04-07
Elide MEDIUM 6.5
CVE-2020-5289

In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can …

Fix: 4.5.14+
Fix from $1,600 2020-03-30
Symfony HIGH 8.1
CVE-2020-5275

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and s…

Fix: 4.4.7 / 5.0.7+
Fix from $1,950 2020-03-30
Moodle MEDIUM 5.3
CVE-2019-14883

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were n…

Fix: 3.6.7 / 3.7.3+
Fix from $1,600 2020-03-18
PostgreSQL MEDIUM 6.5
CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker…

Fix: 9.6.17 / 10.12+
Fix from $1,600 2020-03-17
Wagtail 2fa HIGH 8.5
CVE-2020-5240

In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does …

Fix: 1.4.1+
Fix from $1,950 2020-03-13
Prestashop MEDIUM 6.3
CVE-2020-5250

In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone …

Fix: 1.7.6.4+
Fix from $1,600 2020-03-05
Parse Server MEDIUM 5.3
CVE-2020-5251

In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex o…

Fix: 4.1.0+
Fix from $1,600 2020-03-04
Emc Isilon Onefs HIGH 7.5
CVE-2020-5318

Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vuln…

Mitigation only
Fix from $1,950 2020-02-06
Ethereum Name Service HIGH 8.7
CVE-2020-5232

A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new own…

Fix: after 0.1.0
Fix from $1,950 2020-01-31
Opencast CRITICAL 10.0
CVE-2020-5206

In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that use…

Fix: 7.6+
Fix from $2,300 2020-01-30
Opencast MEDIUM 6.5
CVE-2020-5231

In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE…

Fix: 7.6+
Fix from $1,600 2020-01-30
Sonicos HIGH 7.2
CVE-2019-7479

A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen…

Fix: after 5.9.1.12-4o
Fix from $1,950 2019-12-31
Email Security Appliance CRITICAL 9.8
CVE-2019-7489EPSS 5%

A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Ema…

Fix: after 10.0.2
Fix from $2,300 2019-12-23
Clickshare Cs 100 Firmware MEDIUM 5.9
CVE-2019-18827

On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code execution. This means that JTAG…

Fix: 1.9.0+
Fix from $1,600 2019-12-16
Fedora MEDIUM 5.4
CVE-2019-14870

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation mode…

Fix: 4.9.17 / 4.10.11+
Fix from $1,600 2019-12-10
Rv016 Multi Wan Vpn Firmware MEDIUM 5.3
CVE-2019-15990

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attack…

Fix: 4.2.3.10+
Fix from $1,600 2019-11-26
Satellite CRITICAL 9.1
CVE-2019-17631

From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…

Fix: after 0.16.0
Fix from $2,300 2019-10-17
Ios Xe HIGH 7.8
CVE-2019-12671

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execu…

Mitigation only
Fix from $1,950 2019-09-25
Webaccess CRITICAL 9.8
CVE-2019-13550

In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improp…

Fix: after 8.4.1
Fix from $2,300 2019-09-18
Unified Computing System HIGH 8.8
CVE-2019-1907

A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive conf…

Fix: 4.0+
Fix from $1,950 2019-08-21
Unified Computing System HIGH 8.1
CVE-2019-1863

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a…

Fix: 1.5 / 2.0+
Fix from $1,950 2019-08-21
Clickhouse CRITICAL 9.8
CVE-2018-14670

Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.

Fix: 1.1.54131+
Fix from $2,300 2019-08-15