Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.5 CVE-2021-41308 Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication se… Jira 8.6.0 / 8.13.12+ Fix from $1,6002021-10-26 CRITICAL 10.0 CVE-2021-31384 Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in … Junos Mitigation only Fix from $2,3002021-10-19 HIGH 8.5 CVE-2021-38486 InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any req… Ir615 Firmware Mitigation only Fix from $1,9502021-10-19 HIGH 8.8 CVE-2021-42330 The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attacker… Xinhe Teaching Platform System Mitigation only Fix from $1,9502021-10-15 MEDIUM 5.4 CVE-2021-42331 The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers… Xinhe Teaching Platform System Mitigation only Fix from $1,6002021-10-15 HIGH 8.8 CVE-2021-41137 Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that … Minio Patch available Fix from $1,9502021-10-13 MEDIUM 6.5 CVE-2021-33723 A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any u… Sinec Nms 1.0+ Fix from $1,6002021-10-12 HIGH 8.8 CVE-2021-39317 A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_insta… Access Demo Importer 1.0.7+ Fix from $1,9502021-10-11 MEDIUM 6.5 CVE-2021-41568 Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin b… Tad Web after 1.76 Fix from $1,6002021-10-08 CRITICAL 9.1 CVE-2021-41974 Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content o… Tad Book3 3.9+ Fix from $2,3002021-10-08 CRITICAL 9.1 CVE-2021-41975 TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the sy… Tadtools 3.2.2+ Fix from $2,3002021-10-08 MEDIUM 5.3 CVE-2021-41976 Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in t… Tad Uploader 3.5.4+ Fix from $1,6002021-10-08 MEDIUM 6.5 CVE-2021-41564 Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbit… Tad Honor 1.47+ Fix from $1,6002021-10-08 MEDIUM 5.5 CVE-2021-25499 Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provi… Galaxy Store 4.5.32.4+ Fix from $1,6002021-10-06 CRITICAL 9.8 CVE-2021-41093 Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by … Wire 3.86+ Fix from $2,3002021-10-04 CRITICAL 9.8 CVE-2021-41100 Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address… Wire Server 2021-08-16+ Fix from $2,3002021-10-04 MEDIUM 5.5 CVE-2021-25459 An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZSe… Android Mitigation only Fix from $1,6002021-09-09 MEDIUM 5.5 CVE-2021-25460 An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate Blockchain… Android Mitigation only Fix from $1,6002021-09-09 MEDIUM 6.5 CVE-2021-28567 Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in … Magento after 2.4.2 Fix from $1,6002021-09-08 HIGH 7.2 CVE-2021-36029 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vuln… Adobe Commerce after 2.4.2 Fix from $1,9502021-09-01 MEDIUM 6.5 CVE-2021-36037 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vuln… Adobe Commerce after 2.4.2 Fix from $1,6002021-09-01 MEDIUM 5.3 CVE-2021-34434 In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is … Fedora after 2.0.11 Fix from $1,6002021-08-30 CRITICAL 9.8 CVE-2021-27663 A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequat… Ac2000 Firmware after 10.5 Fix from $2,3002021-08-30 HIGH 7.5 CVE-2021-28626 Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Authorization vulnerability allow… Experience Manager after 6.5.8.0 Fix from $1,9502021-08-24 CRITICAL 9.8 CVE-2021-3616 A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware … Smart Camera C2e Firmware 01.03.29.16+ Fix from $2,3002021-08-17 CRITICAL 10.0 CVE-2021-37705 OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow… Onefuzz 2.31.0+ Fix from $2,3002021-08-13 HIGH 7.8 CVE-2021-36276 Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, d… Dbutildrv2.sys Firmware Patch available Fix from $1,9502021-08-09 CRITICAL 9.8 CVE-2021-35964 The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the ma… Orca Hcm after 10.0 Fix from $2,3002021-07-19 HIGH 8.8 CVE-2021-32688 Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes.… Nextcloud Server 19.0.13 / 20.0.11+ Fix from $1,9502021-07-12 HIGH 8.8 CVE-2021-1576 Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack… Business Process Automation 3.1+ Fix from $1,9502021-07-08