Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
A720r Firmware CRITICAL 9.8
CVE-2021-35327

A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default cre…

No fix yet
Fix from $2,300 2021-08-05
Go MEDIUM 5.3
CVE-2021-33197

In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker i…

Fix: 1.15.13 / 1.16.5+
Fix from $1,600 2021-08-02
S Cms HIGH 7.2
CVE-2020-20698

A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modification of a PHP file.

No fix yet
Fix from $1,950 2021-07-30
Learnpress HIGH 8.1
CVE-2020-11511

The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-…

Fix: 3.2.6.9+
Fix from $1,950 2021-07-30
Jira Data Center CRITICAL 9.8
CVE-2020-36239EPSS 47%

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.1…

Fix: 4.5.16 / 4.13.8+
Fix from $2,300 2021-07-29
Wifi Digital Microscope 3 Firmware HIGH 8.1
CVE-2020-12734

DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owne…

No fix yet
Fix from $1,950 2021-07-15
Android MEDIUM 5.5
CVE-2021-0518

In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with…

Mitigation only
Fix from $1,600 2021-07-14
Android MEDIUM 5.5
CVE-2021-0597

In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission …

Mitigation only
Fix from $1,600 2021-07-14
Android MEDIUM 5.5
CVE-2021-0654

In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information …

Mitigation only
Fix from $1,600 2021-07-14
Netweaver Guided Procedures HIGH 8.8
CVE-2021-33671

SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization che…

Mitigation only
Fix from $1,950 2021-07-14
Customer Relationship Management HIGH 7.2
CVE-2021-33676

A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise c…

Mitigation only
Fix from $1,950 2021-07-14
Sharecare CRITICAL 9.8
CVE-2021-36124

An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive res…

Mitigation only
Fix from $2,300 2021-07-13
Halo CRITICAL 9.1
CVE-2020-19038

File Deletion vulnerability in Halo 0.4.3 via delBackup.

No fix yet
Fix from $2,300 2021-07-12
Craft Cms CRITICAL 9.8
CVE-2021-27903

An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…

Fix: 3.6.7+
Fix from $2,300 2021-06-30
Hospital Management System HIGH 7.5
CVE-2020-22176

PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated user…

No fix yet
Fix from $1,950 2021-06-22
Android HIGH 7.8
CVE-2021-0539

In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permis…

Mitigation only
Fix from $1,950 2021-06-22
Android HIGH 7.8
CVE-2021-0547

In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permi…

Mitigation only
Fix from $1,950 2021-06-22
Android MEDIUM 5.5
CVE-2021-0554

In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2021-06-22
Android HIGH 7.8
CVE-2021-0568

In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead…

Mitigation only
Fix from $1,950 2021-06-22
Asken MEDIUM 6.1
CVE-2021-20733

Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions from v.3.0.0 to v.4.2.x…

Fix: 4.3.0+
Fix from $1,600 2021-06-22
Android HIGH 7.8
CVE-2021-0505

In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of pr…

Patch available
Fix from $1,950 2021-06-21
Android HIGH 7.8
CVE-2021-0513

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state va…

Patch available
Fix from $1,950 2021-06-21
Android MEDIUM 5.5
CVE-2021-0521

In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check. This could lead to local in…

Patch available
Fix from $1,600 2021-06-21
Openclinic HIGH 7.2
CVE-2020-20444

Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/s…

Patch available
Fix from $1,950 2021-06-16
Simple 301 Redirects HIGH 8.8
CVE-2021-24352

The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possibl…

Fix: 2.0.4+
Fix from $1,950 2021-06-14
Simple 301 Redirects HIGH 8.8
CVE-2021-24353

The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possibl…

Fix: 2.0.4+
Fix from $1,950 2021-06-14
Simple 301 Redirects HIGH 8.8
CVE-2021-24354

A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4,…

Fix: 2.0.4+
Fix from $1,950 2021-06-14
Simple 301 Redirects HIGH 8.8
CVE-2021-24356

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action…

Fix: 2.0.4+
Fix from $1,950 2021-06-14
Restund CRITICAL 9.6
CVE-2021-21382

Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows …

Fix: 0.4.15+
Fix from $2,300 2021-06-11
Android HIGH 7.8
CVE-2021-0491

In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2021-06-11