Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Zulip Desktop MEDIUM 5.3
CVE-2020-10858

Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.

Fix: 5.0.0+
Fix from $1,600 2021-02-05
Mantisbt MEDIUM 6.5
CVE-2020-29604

An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues…

Fix: 2.24.4+
Fix from $1,600 2021-01-29
Cloud Pak For Security MEDIUM 5.9
CVE-2020-4816

IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTT…

Patch available
Fix from $1,600 2021-01-27
Agent MEDIUM 5.5
CVE-2020-7343

Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulatin…

Fix: 5.7.1+
Fix from $1,600 2021-01-18
Onedev HIGH 7.5
CVE-2021-21246EPSS 49%

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that o…

Fix: 4.0.3+
Fix from $1,950 2021-01-15
Hono HIGH 8.8
CVE-2020-27220

The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control mess…

Fix: after 1.4.4
Fix from $1,950 2021-01-14
Smc2.0 Firmware MEDIUM 6.7
CVE-2020-9209

There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located improperly. It does not apply the …

Mitigation only
Fix from $1,600 2021-01-13
Joomla\! MEDIUM 5.3
CVE-2021-23123

An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublishe…

Fix: after 3.9.23
Fix from $1,600 2021-01-12
Business Warehouse MEDIUM 6.5
CVE-2021-21468

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allow…

No fix yet
Fix from $1,600 2021-01-12
Spectrum Protect Plus MEDIUM 5.3
CVE-2020-5022

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Chrome MEDIUM 6.5
CVE-2020-16027

Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malic…

Fix: 87.0.4280.66+
Fix from $1,600 2021-01-08
Chrome HIGH 8.8
CVE-2020-16029

Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a craft…

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08
Hospital Management System HIGH 8.8
CVE-2020-35745

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of us…

No fix yet
Fix from $1,950 2021-01-07
Zammad HIGH 7.5
CVE-2020-29160

An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.

Fix: 3.5.1+
Fix from $1,950 2020-12-28
Notouch Center HIGH 8.8
CVE-2020-25917

Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "hel…

Fix: 4.4.68+
Fix from $1,950 2020-12-26
Odoo MEDIUM 6.5
CVE-2019-11783

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote auth…

Fix: after 14.0
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.5
CVE-2019-11784

Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authent…

Fix: after 14.0
Fix from $1,600 2020-12-22
Mediawiki HIGH 8.8
CVE-2020-35625

An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace c…

Fix: after 1.35.1
Fix from $1,950 2020-12-21
Security Secret Server MEDIUM 5.9
CVE-2020-4841

IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T…

Patch available
Fix from $1,600 2020-12-21
Cam HIGH 8.8
CVE-2020-13512

A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted …

No fix yet
Fix from $1,950 2020-12-18
Cam HIGH 8.8
CVE-2020-13513

A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted …

No fix yet
Fix from $1,950 2020-12-18
Cam HIGH 8.8
CVE-2020-13514

A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted …

No fix yet
Fix from $1,950 2020-12-18
Cam HIGH 8.8
CVE-2020-13515

A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/O request…

No fix yet
Fix from $1,950 2020-12-18
Cam HIGH 8.8
CVE-2020-13519

A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/O request…

No fix yet
Fix from $1,950 2020-12-18
Debian Linux HIGH 8.8
CVE-2020-29479

An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for t…

Fix: after 4.14.0
Fix from $1,950 2020-12-15
Linux Kernel MEDIUM 6.7
CVE-2020-27777

A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest sy…

Fix: 4.14.204 / 4.19.155+
Fix from $1,600 2020-12-15
Android HIGH 7.8
CVE-2020-27052

In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a permissions bypass. This cou…

Patch available
Fix from $1,950 2020-12-15
Android HIGH 7.8
CVE-2020-27054

In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no addi…

Patch available
Fix from $1,950 2020-12-15
Android MEDIUM 5.5
CVE-2020-27032

In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing permission check. This could lead…

Mitigation only
Fix from $1,600 2020-12-15
Android MEDIUM 5.5
CVE-2020-0497

In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information disclosure with no additional e…

Mitigation only
Fix from $1,600 2020-12-15