Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2020-0475

In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. T…

Mitigation only
Fix from $1,950 2020-12-15
Android MEDIUM 5.5
CVE-2020-0477

In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This c…

Patch available
Fix from $1,600 2020-12-15
Android HIGH 7.8
CVE-2020-0480

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escala…

Patch available
Fix from $1,950 2020-12-15
Android HIGH 7.8
CVE-2020-0485

In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missing permission check. This cou…

Patch available
Fix from $1,950 2020-12-15
Android MEDIUM 5.5
CVE-2020-0468

In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permissi…

Patch available
Fix from $1,600 2020-12-14
Android HIGH 7.8
CVE-2020-0440

In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check.…

Patch available
Fix from $1,950 2020-12-14
GitLab MEDIUM 5.3
CVE-2020-26408

A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows a…

Fix: 13.4.7 / 13.5.5+
Fix from $1,600 2020-12-11
Easergy T300 Firmware CRITICAL 9.8
CVE-2020-28215

A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including …

Fix: after 2.7
Fix from $2,300 2020-12-11
A3002r Firmware HIGH 8.8
CVE-2020-25499

TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality…

Fix: 1.0.0-b20201028.1743 / 1.0.0-b20201103.1713+
Fix from $1,950 2020-12-09
Solution Manager HIGH 8.1
CVE-2020-26830

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due …

No fix yet
Fix from $1,950 2020-12-09
Netweaver Application Server Abap HIGH 7.6
CVE-2020-26832

SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and S…

No fix yet
Fix from $1,950 2020-12-09
Ubuntu Linux MEDIUM 5.5
CVE-2020-27349

Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1…

Patch available
Fix from $1,600 2020-12-09
Divebook MEDIUM 5.3
CVE-2020-14205

The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An…

No fix yet
Fix from $1,600 2020-12-08
Moodle HIGH 8.8
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some …

Fix: 3.5.14 / 3.7.8+
Fix from $1,950 2020-12-08
Drivergenius HIGH 7.8
CVE-2020-23740

In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to incr…

Mitigation only
Fix from $1,950 2020-12-03
Cyber Game Accelerator HIGH 7.8
CVE-2020-23735

In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constructed program to increase user…

No fix yet
Fix from $1,950 2020-12-03
Data Grid MEDIUM 6.5
CVE-2020-25711

A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When …

Fix: 11.0.6+
Fix from $1,600 2020-12-03
Chaos Monkey HIGH 7.5
CVE-2020-2322

Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permis…

Fix: after 0.3
Fix from $1,950 2020-12-03
Chaos Monkey MEDIUM 5.3
CVE-2020-2323

Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission t…

Fix: after 0.4
Fix from $1,600 2020-12-03
Crafter Cms MEDIUM 6.5
CVE-2017-15680

In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.

Fix: 3.0.1+
Fix from $1,600 2020-11-27
Glpi MEDIUM 6.5
CVE-2020-26212

GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk fe…

Fix: 9.5.3+
Fix from $1,600 2020-11-25
Misp CRITICAL 9.8
CVE-2020-29006

MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.

Fix: 2.4.135+
Fix from $2,300 2020-11-24
October MEDIUM 6.7
CVE-2020-26231

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 (fixed in 1.0.469 and 1.1.0) …

Patch available
Fix from $1,600 2020-11-23
October MEDIUM 5.2
CVE-2020-15247

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1…

Fix: 1.0.469+
Fix from $1,600 2020-11-23
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4783

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enab…

Fix: after 10.1.6
Fix from $1,600 2020-11-23
Forklift HIGH 7.8
CVE-2020-15349

BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool implements an XPC interface th…

Fix: 3.4+
Fix from $1,950 2020-11-17
Forklift HIGH 7.8
CVE-2020-27192

BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allowed a local attacker to injec…

Fix: after 3.4
Fix from $1,950 2020-11-17
Avideo HIGH 8.8
CVE-2020-23489

The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which l…

Fix: 8.9+
Fix from $1,950 2020-11-16
Netweaver Application Server Abap HIGH 8.8
CVE-2020-26818

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro compone…

Mitigation only
Fix from $1,950 2020-11-10
Android MEDIUM 5.5
CVE-2020-0454

In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to lo…

No fix yet
Fix from $1,600 2020-11-10