Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Command Centre MEDIUM 6.5
CVE-2021-23204

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to…

Fix: 8.30.1359 / 8.40.1888+
Fix from $1,600 2021-06-11
HTTP Server MEDIUM 5.5
CVE-2020-13938EPSS 12%

Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

Fix: 5.10.0+
Fix from $1,600 2021-06-10
Netweaver Application Server Abap MEDIUM 6.3
CVE-2021-21473

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC…

No fix yet
Fix from $1,600 2021-06-09
Npct75x Firmware MEDIUM 6.0
CVE-2021-32015

In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to …

Mitigation only
Fix from $1,600 2021-06-08
Istio CRITICAL 9.8
CVE-2021-31921

Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in th…

Fix: 1.8.6 / 1.9.5+
Fix from $2,300 2021-06-02
Libvirt MEDIUM 6.5
CVE-2020-10701

A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connec…

Fix: 6.2.0+
Fix from $1,600 2021-05-27
Sharefile Storagezones Controller CRITICAL 9.8
CVE-2021-22891

A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow un…

Fix: 5.7.3 / 5.9.3+
Fix from $2,300 2021-05-27
Certification HIGH 7.5
CVE-2018-10865

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $1,950 2021-05-26
Certification CRITICAL 9.1
CVE-2018-10866

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $2,300 2021-05-26
Planning Analytics Cloud CRITICAL 9.1
CVE-2020-4669

IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …

Patch available
Fix from $2,300 2021-05-17
Debian Linux MEDIUM 5.3
CVE-2021-32917

An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP accou…

Fix: 0.11.9+
Fix from $1,600 2021-05-13
Big Ip Advanced Web Application Firewall HIGH 8.8
CVE-2021-23014

On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for …

Fix: 14.1.4 / 15.1.3+
Fix from $1,950 2021-05-10
Emote Remote Mouse CRITICAL 9.8
CVE-2021-27573

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with n…

Fix: after 4.0.0.0
Fix from $2,300 2021-05-07
Vrealize Business For Cloud CRITICAL 9.8
CVE-2021-21984

VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious ac…

Fix: 7.6.0+
Fix from $2,300 2021-05-07
Emissary MEDIUM 6.5
CVE-2021-32093

The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the Con…

No fix yet
Fix from $1,600 2021-05-07
Emissary HIGH 8.1
CVE-2021-32095

U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files.

Mitigation only
Fix from $1,950 2021-05-07
Puppycms HIGH 7.5
CVE-2020-18888

Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.

No fix yet
Fix from $1,950 2021-05-06
Catalyst Sd Wan Manager HIGH 8.8
CVE-2021-1505

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 20.3.3 / 20.4.1+
Fix from $1,950 2021-05-06
Catalyst Sd Wan Manager HIGH 7.2
CVE-2021-1506

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 20.3.3 / 20.4.1+
Fix from $1,950 2021-05-06
Catalyst Sd Wan Manager HIGH 8.8
CVE-2021-1508

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 19.2.99 / 20.3.3+
Fix from $1,950 2021-05-06
October MEDIUM 5.2
CVE-2021-21264

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1…

Fix: after 1.1.1
Fix from $1,600 2021-05-03
Gurunavi HIGH 7.5
CVE-2021-20693

Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and earlier allows a remote attacker…

Fix: after 11.1.2
Fix from $1,950 2021-04-26
Netweaver Application Server Java MEDIUM 5.3
CVE-2021-27598

SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ…

Mitigation only
Fix from $1,600 2021-04-13
Focused Run MEDIUM 6.5
CVE-2021-27609

SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData s…

Mitigation only
Fix from $1,600 2021-04-13
Android MEDIUM 5.5
CVE-2021-0428

In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could …

Patch available
Fix from $1,600 2021-04-13
Vela MEDIUM 6.5
CVE-2021-21432

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0…

Fix: 0.7.5+
Fix from $1,600 2021-04-09
Data Center MEDIUM 5.3
CVE-2020-36287EPSS 9%

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from ve…

Fix: 8.13.5 / 8.15.1+
Fix from $1,600 2021-04-09
Application Automation Tools MEDIUM 6.5
CVE-2021-22513

Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and ea…

Fix: after 6.7
Fix from $1,600 2021-04-08
Insider Threat Management HIGH 8.1
CVE-2021-27900

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. Th…

Fix: 7.9.3 / 7.10.3+
Fix from $1,950 2021-04-06
Openiam HIGH 8.1
CVE-2020-13422

OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.

Fix: 4.2.0.3+
Fix from $1,950 2021-04-06