Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Jenkins CRITICAL 9.1
CVE-2021-21685

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs.

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Dir 823g Firmware CRITICAL 9.1
CVE-2020-25366

An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspe…

Mitigation only
Fix from $2,300 2021-11-04
Hangfire HIGH 7.5
CVE-2021-41238

Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process re…

Mitigation only
Fix from $1,950 2021-11-02
Wp Attachment Export HIGH 7.5
CVE-2015-20067EPSS 8%

The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data …

Fix: 0.2.4+
Fix from $1,950 2021-11-01
Learndash HIGH 7.5
CVE-2018-25019

The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment…

Fix: after 2.5.4
Fix from $1,950 2021-11-01
Deck HIGH 8.1
CVE-2021-39225

Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows ano…

Fix: 1.2.9 / 1.4.5+
Fix from $1,950 2021-10-25
Wp Debugging MEDIUM 6.5
CVE-2021-24779

The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF che…

Fix: 2.11.0+
Fix from $1,600 2021-10-25
Android MEDIUM 5.5
CVE-2021-0706

In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This coul…

Mitigation only
Fix from $1,600 2021-10-22
Android MEDIUM 5.5
CVE-2021-0643

In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due t…

Mitigation only
Fix from $1,600 2021-10-22
Junos CRITICAL 10.0
CVE-2021-31384

Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in …

Mitigation only
Fix from $2,300 2021-10-19
Ir615 Firmware HIGH 8.5
CVE-2021-38486

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any req…

Mitigation only
Fix from $1,950 2021-10-19
Find My Blocks MEDIUM 5.3
CVE-2021-24677

The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enume…

Fix: 3.4.0+
Fix from $1,600 2021-10-18
Clearpass Policy Manager HIGH 7.5
CVE-2021-37738

A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10…

Fix: 6.10.2+
Fix from $1,950 2021-10-15
Xinhe Teaching Platform System MEDIUM 5.4
CVE-2021-42331

The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers…

Mitigation only
Fix from $1,600 2021-10-15
Nike MEDIUM 6.1
CVE-2021-20834

Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 and Nike App for iOS versions p…

Fix: 2.177.1 / 2.177.3.3688+
Fix from $1,600 2021-10-13
Electron HIGH 8.6
CVE-2021-39184

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, …

Fix: 11.5.0 / 12.1.0+
Fix from $1,950 2021-10-12
Projectsend HIGH 8.1
CVE-2021-40884

Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php a…

No fix yet
Fix from $1,950 2021-10-11
Chrome MEDIUM 6.5
CVE-2021-37976 KEVEPSS 20%

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 94.0.4606.71+
Fix from $1,600 2021-10-08
Maian Cart CRITICAL 9.8
CVE-2021-32172EPSS 66%

Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

No fix yet
Fix from $2,300 2021-10-07
Android MEDIUM 5.5
CVE-2021-0680

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0681

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0682

In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. …

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0686

In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user d…

Patch available
Fix from $1,600 2021-10-06
Grafana HIGH 7.3
CVE-2021-39226 KEVEPSS 100%

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit…

Fix: 7.5.11 / 8.1.6+
Fix from $1,950 2021-10-05
Web Central HIGH 8.8
CVE-2021-41554

ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endp…

No fix yet
Fix from $1,950 2021-10-05
GitLab HIGH 7.5
CVE-2021-39893

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

Fix: 14.1.7 / 14.2.5+
Fix from $1,950 2021-10-05
Baicloud Cms CRITICAL 9.1
CVE-2021-41729

BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through…

No fix yet
Fix from $2,300 2021-09-30
Linux Kernel HIGH 8.8
CVE-2021-3653

A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control bl…

Fix: 4.4.282 / 4.9.281+
Fix from $1,950 2021-09-29
Ansible CRITICAL 9.8
CVE-2021-33924

Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allow…

Mitigation only
Fix from $2,300 2021-09-29
Cms Enterprise Website Construction System CRITICAL 9.8
CVE-2021-37270

There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly…

Mitigation only
Fix from $2,300 2021-09-27