Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Tutor Lms HIGH 8.8
CVE-2021-24184

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to m…

Fix: 1.7.7+
Fix from $1,950 2021-04-05
Ninja Forms HIGH 8.8
CVE-2021-24163

The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, ther…

Fix: 3.4.34+
Fix from $1,950 2021-04-05
Mac Os X MEDIUM 5.5
CVE-2020-29621

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007…

Fix: 10.14.6 / 10.15.7+
Fix from $1,600 2021-04-02
Data Center MEDIUM 5.3
CVE-2020-36238

The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.…

Fix: 8.5.13 / 8.13.5+
Fix from $1,600 2021-04-01
Owasp Dependency Track MEDIUM 6.5
CVE-2021-21632

A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an …

Fix: after 3.1.0
Fix from $1,600 2021-03-30
Team Foundation Server MEDIUM 6.5
CVE-2021-21637

A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to connect to a…

Fix: after 5.157.1
Fix from $1,600 2021-03-30
Altalink B8045 Firmware HIGH 7.5
CVE-2021-28669

Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.02…

Fix: 103.001.020.23120 / 103.002.020.23120+
Fix from $1,950 2021-03-29
Cloud Manager CRITICAL 9.1
CVE-2021-26990

Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.

Fix: 3.9.4+
Fix from $2,300 2021-03-19
Exacqvision Web Service HIGH 7.5
CVE-2021-27656

A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exa…

Fix: after 20.12.2.0
Fix from $1,950 2021-03-18
Modern Events Calendar Lite HIGH 7.5
CVE-2021-24146EPSS 31%

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp…

Fix: 5.16.5+
Fix from $1,950 2021-03-18
Linux Kernel HIGH 7.8
CVE-2021-28375

An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from…

Fix: 5.4.106 / 5.10.24+
Fix from $1,950 2021-03-15
Modeler CRITICAL 9.1
CVE-2021-28154

Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vul…

Fix: after 4.6.0
Fix from $2,300 2021-03-11
Experience Manager HIGH 7.2
CVE-2020-14987

An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because th…

Fix: after 14.2.2
Fix from $1,950 2021-03-11
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2021-28141

An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web…

No fix yet
Fix from $2,300 2021-03-11
Android HIGH 7.8
CVE-2021-0380

In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony settings due to a missing permission…

Patch available
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0385

In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connection to untrusted WiFi networks…

Patch available
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0388

In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast handler. This could lead to …

Patch available
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0389

In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no …

Patch available
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0390

In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check. T…

Mitigation only
Fix from $1,950 2021-03-10
Payment Engine HIGH 8.8
CVE-2021-21487

SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Mitigation only
Fix from $1,950 2021-03-09
Enterprise Financial Services HIGH 8.8
CVE-2021-21486

SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authoriz…

Mitigation only
Fix from $1,950 2021-03-09
Glpi MEDIUM 6.5
CVE-2021-21326

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Fix: 9.5.4+
Fix from $1,600 2021-03-08
Glpi HIGH 7.5
CVE-2021-21327

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Fix: 9.5.4+
Fix from $1,950 2021-03-08
Android MEDIUM 5.5
CVE-2021-25344

Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without per…

Mitigation only
Fix from $1,600 2021-03-04
View Planner CRITICAL 9.8
CVE-2021-21978EPSS 99%

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authoriza…

Fix: 4.6+
Fix from $2,300 2021-03-03
Nextcloud Server MEDIUM 6.5
CVE-2021-22877

A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration whe…

Fix: 20.0.6+
Fix from $1,600 2021-03-03
Glpi MEDIUM 5.7
CVE-2021-21255

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Patch available
Fix from $1,600 2021-03-02
Firefox MEDIUM 6.5
CVE-2021-23975

The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function …

Fix: 86.0+
Fix from $1,600 2021-02-26
Lucee Server CRITICAL 9.8
CVE-2021-21307EPSS 89%

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before version…

Fix: 5.3.5.96 / 5.3.6.68+
Fix from $2,300 2021-02-11
Android HIGH 7.8
CVE-2021-0328

In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to…

Patch available
Fix from $1,950 2021-02-10