Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2021-1017

In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permiss…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0985

In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local esca…

Patch available
Fix from $1,950 2021-12-15
Android MEDIUM 5.5
CVE-2021-0986

In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owner, profile owner, or device a…

Patch available
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-0922

In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a miss…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0923

In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to loca…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0926

In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a missing permission check. This c…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 8.8
CVE-2021-0965

In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This …

Patch available
Fix from $1,950 2021-12-15
Android MEDIUM 5.5
CVE-2021-0653

In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission ch…

Mitigation only
Fix from $1,600 2021-12-15
Listary HIGH 7.5
CVE-2021-41066

An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to acce…

Fix: after 6
Fix from $1,950 2021-12-14
Variation Swatches For Woocommerce MEDIUM 5.4
CVE-2021-42367

The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/c…

Fix: after 2.1.1
Fix from $1,600 2021-12-14
Access Control HIGH 8.8
CVE-2021-44233

SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which c…

Mitigation only
Fix from $1,950 2021-12-14
Advanced Custom Fields MEDIUM 6.5
CVE-2021-20867

Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in …

Fix: 5.11+
Fix from $1,600 2021-12-13
Advanced Custom Fields HIGH 7.5
CVE-2021-20865

Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in …

Fix: 5.11+
Fix from $1,950 2021-12-13
Advanced Custom Fields MEDIUM 6.5
CVE-2021-20866

Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in …

Fix: 5.11+
Fix from $1,600 2021-12-13
Tawk.to Live Chat HIGH 8.0
CVE-2021-24914

The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX act…

Fix: 0.6.0+
Fix from $1,950 2021-12-06
Chamilo Lms HIGH 8.8
CVE-2021-35413

A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary…

Fix: after 1.11.16
Fix from $1,950 2021-12-03
Bulk Datetime Change MEDIUM 5.4
CVE-2021-24842

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private…

Fix: 1.12+
Fix from $1,600 2021-11-29
Hide My Wp HIGH 7.5
CVE-2021-36917

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can th…

Fix: after 6.2.3
Fix from $1,950 2021-11-24
Mercari HIGH 7.5
CVE-2021-20835

Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan …

Fix: 4.49.1+
Fix from $1,950 2021-11-24
Ozone CRITICAL 9.1
CVE-2021-39231

In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an att…

Fix: 1.2.0+
Fix from $2,300 2021-11-19
Ozone HIGH 8.8
CVE-2021-39232

In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

Fix: 1.2.0+
Fix from $1,950 2021-11-19
Ozone HIGH 8.8
CVE-2021-39236

In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

Fix: 1.2.0+
Fix from $1,950 2021-11-19
Android MEDIUM 5.5
CVE-2021-0672

In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no…

Mitigation only
Fix from $1,600 2021-11-18
Wp Reset Pro HIGH 8.1
CVE-2021-36909

Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the enti…

Fix: after 5.98
Fix from $1,950 2021-11-18
Abap Platform Kernel HIGH 8.1
CVE-2021-40501

SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resul…

Mitigation only
Fix from $1,950 2021-11-10
Commerce HIGH 8.8
CVE-2021-40502

SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in es…

Mitigation only
Fix from $1,950 2021-11-10
Wp Dsgvo Tools CRITICAL 9.1
CVE-2021-42359

WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available …

Fix: after 3.1.23
Fix from $2,300 2021-11-05
Jenkins CRITICAL 9.1
CVE-2021-21687

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic lin…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins HIGH 7.5
CVE-2021-21688

The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not reject any operat…

Fix: 2.303.3 / 2.319+
Fix from $1,950 2021-11-04
Jenkins CRITICAL 9.8
CVE-2021-21694

FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04