Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 8.8 CVE-2021-1574 Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack… Business Process Automation 3.1+ Fix from $1,9502021-07-08 MEDIUM 5.5 CVE-2021-25433 Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications to perform… Tizen 5.5+ Fix from $1,6002021-07-08 HIGH 7.2 CVE-2021-32523 Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary comman… Storage Manager after 3.3.1 Fix from $1,9502021-07-07 MEDIUM 6.5 CVE-2021-28563 Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Authorization vulnerability via t… Magento 2.3.7+ Fix from $1,6002021-06-28 CRITICAL 9.8 CVE-2021-3044 An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Corte… Cortex Xsoar Mitigation only Fix from $2,3002021-06-22 HIGH 8.8 CVE-2021-23140 Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre O… Command Centre 8.20.1259 / 8.30.1359+ Fix from $1,9502021-06-11 MEDIUM 6.5 CVE-2021-23136 Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Oper… Command Centre 8.20.1259 / 8.30.1359+ Fix from $1,6002021-06-11 HIGH 7.5 CVE-2021-25417 Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage. Android Mitigation only Fix from $1,9502021-06-11 HIGH 7.1 CVE-2021-25399 Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege. Smart Manager 11.0.05.0+ Fix from $1,9502021-06-11 HIGH 8.1 CVE-2020-25716 A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a… Cloudforms 5.11.10.1+ Fix from $1,9502021-06-07 MEDIUM 6.5 CVE-2020-1690 An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from pri… Openstack Selinux 0.8.24+ Fix from $1,6002021-06-07 CRITICAL 9.8 CVE-2021-32619 Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imp… Deno 1.10.2+ Fix from $2,3002021-05-28 HIGH 8.8 CVE-2021-32620 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 1… Xwiki 11.10.13 / 12.6.7+ Fix from $1,9502021-05-28 MEDIUM 6.5 CVE-2020-10716 A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a mali… Satellite 4.0.3.4+ Fix from $1,6002021-05-27 HIGH 8.8 CVE-2021-24192 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install an… Sitemap 2.9+ Fix from $1,9502021-05-14 HIGH 8.8 CVE-2021-24193 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin b… Visitor Traffic Real Time Statistics 2.12+ Fix from $1,9502021-05-14 HIGH 8.8 CVE-2021-24194 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPres… Login Protection Limit Failed Login Attempts 2.9+ Fix from $1,9502021-05-14 HIGH 8.8 CVE-2021-24195 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress pl… Login As User Or Customer \(user Switching\) 1.8+ Fix from $1,9502021-05-14 HIGH 8.8 CVE-2021-24188 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress p… Wp Content Copy Protection \& No Right Click 3.1.5+ Fix from $1,9502021-05-14 HIGH 8.8 CVE-2021-24189 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordP… Captchinoo 2.4+ Fix from $1,9502021-05-14 HIGH 8.8 CVE-2021-24190 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plug… Conditional Marketing Mailer 1.5.2+ Fix from $1,9502021-05-14 HIGH 8.8 CVE-2021-24191 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress… Coming Soon Page \& Maintenance Mode 1.8.2+ Fix from $1,9502021-05-14 CRITICAL 9.8 CVE-2021-28799 KEVEPSS 78% An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability all… Hybrid Backup Sync 3.0.210411 / 3.0.210412+ Fix from $2,3002021-05-13 HIGH 7.5 CVE-2020-17517 The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allo… Ozone 1.1.0+ Fix from $1,9502021-04-27 MEDIUM 5.5 CVE-2021-25382 An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secur… Android Mitigation only Fix from $1,6002021-04-23 HIGH 7.3 CVE-2021-0260 An improper authorization vulnerability in the Simple Network Management Protocol daemon (snmpd) service of Juniper Networks Junos OS leads an unauth… Junos Mitigation only Fix from $1,9502021-04-22 MEDIUM 5.5 CVE-2021-21096 Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software S… Bridge after 11.0.1 Fix from $1,6002021-04-15 HIGH 7.8 CVE-2021-25373 Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10… Customization Service 2.2.02.1 / 2.4.03.0+ Fix from $1,9502021-04-09 HIGH 7.5 CVE-2021-25374 An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and… Members after 2.4.83.9 Fix from $1,9502021-04-09 HIGH 7.8 CVE-2021-25381 Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows loca… Account Mitigation only Fix from $1,9502021-04-09