Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Ninja Forms MEDIUM 6.5
CVE-2021-34647

The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/R…

Fix: after 3.5.7
Fix from $1,600 2021-09-22
Visual Link Preview MEDIUM 5.4
CVE-2021-24635

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all…

Fix: 2.2.3+
Fix from $1,600 2021-09-20
Omgf HIGH 8.1
CVE-2021-24639

The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which …

Fix: 4.5.4+
Fix from $1,950 2021-09-20
Business One HIGH 8.8
CVE-2021-33704

The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricte…

Patch available
Fix from $1,950 2021-09-15
Enterprise Search HIGH 8.8
CVE-2021-22149

Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate rou…

Fix: 7.14.0+
Fix from $1,950 2021-09-15
Elasticsearch MEDIUM 6.5
CVE-2021-22147

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining…

Fix: 7.14.0+
Fix from $1,600 2021-09-15
Travis Ci HIGH 7.5
CVE-2021-41077

The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not spec…

Fix: after 2021-09-10
Fix from $1,950 2021-09-14
Netweaver Application Server Java CRITICAL 9.8
CVE-2021-37535

SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization…

Mitigation only
Fix from $2,300 2021-09-14
Erp Financial Accounting MEDIUM 5.4
CVE-2021-38164

SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE …

Mitigation only
Fix from $1,600 2021-09-14
Central Dogma HIGH 8.8
CVE-2021-38388

Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.

Fix: 0.51.1+
Fix from $1,950 2021-09-08
Base Software CRITICAL 9.8
CVE-2020-24672

A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This…

Fix: after 6.1
Fix from $2,300 2021-09-08
Mac Os X HIGH 7.8
CVE-2021-30713 KEVEPSS 7%

A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass …

Fix: 11.4+
Fix from $1,950 2021-09-08
Mac Os X MEDIUM 5.5
CVE-2021-30657 KEVEPSS 69%

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious…

Fix: 11.3+
Fix from $1,600 2021-09-08
Consul MEDIUM 6.5
CVE-2021-38698

HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service …

Fix: 1.8.15 / 1.9.9+
Fix from $1,600 2021-09-07
Ip70 Firmware HIGH 8.1
CVE-2021-40378EPSS 15%

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from t…

No fix yet
Fix from $1,950 2021-09-01
Ip70 Firmware HIGH 7.5
CVE-2021-40379EPSS 22%

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.

No fix yet
Fix from $1,950 2021-09-01
Mik.starlight HIGH 8.8
CVE-2021-36232

Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

No fix yet
Fix from $1,950 2021-08-31
Ejbca MEDIUM 5.4
CVE-2021-40088

An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling cli…

Fix: 7.6.0+
Fix from $1,600 2021-08-25
Ipados HIGH 7.5
CVE-2021-30874

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installe…

Fix: 12.0.1 / 15.0+
Fix from $1,950 2021-08-24
Rconfig CRITICAL 9.1
CVE-2020-25359

An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted r…

No fix yet
Fix from $2,300 2021-08-20
Rconfig HIGH 7.8
CVE-2020-27464

An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file.

Fix: after 3.9.6
Fix from $1,950 2021-08-20
Rconfig HIGH 7.8
CVE-2020-27466

An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a craf…

Mitigation only
Fix from $1,950 2021-08-20
Android MEDIUM 5.5
CVE-2021-0415

In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information discl…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 5.5
CVE-2021-0641

In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission …

Patch available
Fix from $1,600 2021-08-17
Android MEDIUM 5.5
CVE-2021-0642

In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permis…

Patch available
Fix from $1,600 2021-08-17
Hospital Management System MEDIUM 5.3
CVE-2021-38755

Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.

No fix yet
Fix from $1,600 2021-08-16
Mac1100 Plc Firmware CRITICAL 9.8
CVE-2020-18753

An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted pa…

No fix yet
Fix from $2,300 2021-08-13
Mac1100 Plc Firmware HIGH 7.5
CVE-2020-18757

An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.

No fix yet
Fix from $1,950 2021-08-13
Workreap HIGH 8.1
CVE-2021-24500

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer…

Fix: 2.2.2+
Fix from $1,950 2021-08-09
Workreap HIGH 8.1
CVE-2021-24501

The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform criti…

Fix: 2.2.2+
Fix from $1,950 2021-08-09