Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
CRITICAL 9.1 CVE-2020-15084 In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When al… Express Jwt after 5.3.3 Fix from $2,3002020-06-30 HIGH 8.0 CVE-2020-10736 An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restri… Ceph 15.2.2+ Fix from $1,9502020-06-22 HIGH 7.1 CVE-2020-3267 A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change th… Unified Contact Center Express 12.5+ Fix from $1,9502020-06-03 CRITICAL 9.8 CVE-2020-10516 An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissio… GitHub 2.18.20 / 2.19.15+ Fix from $2,3002020-06-03 CRITICAL 9.8 CVE-2020-10620 Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to… Softpac Project after 9.6 Fix from $2,3002020-05-14 HIGH 8.8 CVE-2020-1998 An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions … Pan Os 7.1.26 / 8.1.13+ Fix from $1,9502020-05-13 CRITICAL 9.8 CVE-2020-1745 A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final … Undertow after 2.0.29 Fix from $2,3002020-04-28 HIGH 8.8 CVE-2019-13554 GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. G… Mark Vie Control System Mitigation only Fix from $1,9502020-04-07 MEDIUM 6.5 CVE-2020-5289 In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can … Elide 4.5.14+ Fix from $1,6002020-03-30 HIGH 8.1 CVE-2020-5275 In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and s… Symfony 4.4.7 / 5.0.7+ Fix from $1,9502020-03-30 MEDIUM 5.3 CVE-2019-14883 A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were n… Moodle 3.6.7 / 3.7.3+ Fix from $1,6002020-03-18 MEDIUM 6.5 CVE-2020-1720 A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker… PostgreSQL 9.6.17 / 10.12+ Fix from $1,6002020-03-17 HIGH 8.5 CVE-2020-5240 In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does … Wagtail 2fa 1.4.1+ Fix from $1,9502020-03-13 MEDIUM 6.3 CVE-2020-5250 In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone … Prestashop 1.7.6.4+ Fix from $1,6002020-03-05 MEDIUM 5.3 CVE-2020-5251 In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex o… Parse Server 4.1.0+ Fix from $1,6002020-03-04 HIGH 7.5 CVE-2020-5318 Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vuln… Emc Isilon Onefs Mitigation only Fix from $1,9502020-02-06 HIGH 8.7 CVE-2020-5232 A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new own… Ethereum Name Service after 0.1.0 Fix from $1,9502020-01-31 CRITICAL 10.0 CVE-2020-5206 In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that use… Opencast 7.6+ Fix from $2,3002020-01-30 MEDIUM 6.5 CVE-2020-5231 In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE… Opencast 7.6+ Fix from $1,6002020-01-30 HIGH 7.2 CVE-2019-7479 A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen… Sonicos after 5.9.1.12-4o Fix from $1,9502019-12-31 CRITICAL 9.8 CVE-2019-7489EPSS 5% A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Ema… Email Security Appliance after 10.0.2 Fix from $2,3002019-12-23 MEDIUM 5.9 CVE-2019-18827 On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code execution. This means that JTAG… Clickshare Cs 100 Firmware 1.9.0+ Fix from $1,6002019-12-16 MEDIUM 5.4 CVE-2019-14870 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation mode… Fedora 4.9.17 / 4.10.11+ Fix from $1,6002019-12-10 MEDIUM 5.3 CVE-2019-15990 A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attack… Rv016 Multi Wan Vpn Firmware 4.2.3.10+ Fix from $1,6002019-11-26 CRITICAL 9.1 CVE-2019-17631 From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil… Satellite after 0.16.0 Fix from $2,3002019-10-17 HIGH 7.8 CVE-2019-12671 A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execu… Ios Xe Mitigation only Fix from $1,9502019-09-25 CRITICAL 9.8 CVE-2019-13550 In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improp… Webaccess after 8.4.1 Fix from $2,3002019-09-18 HIGH 8.8 CVE-2019-1907 A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive conf… Unified Computing System 4.0+ Fix from $1,9502019-08-21 HIGH 8.1 CVE-2019-1863 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote a… Unified Computing System 1.5 / 2.0+ Fix from $1,9502019-08-21 CRITICAL 9.8 CVE-2018-14670 Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database. Clickhouse 1.1.54131+ Fix from $2,3002019-08-15