Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2020-0448

In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. …

Patch available
Fix from $1,600 2020-11-10
Android MEDIUM 5.5
CVE-2020-0437

In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial …

Patch available
Fix from $1,600 2020-11-10
Android HIGH 7.8
CVE-2020-0439

In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to…

Patch available
Fix from $1,950 2020-11-10
WordPress CRITICAL 9.8
CVE-2020-28036EPSS 5%

wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

Fix: 5.5.2+
Fix from $2,300 2020-11-02
Fastreport CRITICAL 9.8
CVE-2020-27998

An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, T…

Fix: 2020.4.0+
Fix from $2,300 2020-10-29
Winston Firmware HIGH 7.5
CVE-2020-16260

Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote …

No fix yet
Fix from $1,950 2020-10-28
Atomxcms 2 HIGH 8.1
CVE-2020-26649

AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php

No fix yet
Fix from $1,950 2020-10-22
Infinispan Server Runtime MEDIUM 6.1
CVE-2020-10746

A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to controls via both REST and Hot…

Mitigation only
Fix from $1,600 2020-10-19
Com465ip Firmware CRITICAL 9.1
CVE-2019-19885

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and …

Fix: 4.2.0+
Fix from $2,300 2020-10-16
Jira MEDIUM 5.3
CVE-2020-14185

Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOper…

Fix: 7.13.18 / 8.5.9+
Fix from $1,600 2020-10-15
Android MEDIUM 5.5
CVE-2020-0419

In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permissi…

Patch available
Fix from $1,600 2020-10-14
Android HIGH 7.8
CVE-2020-0420

In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escala…

Patch available
Fix from $1,950 2020-10-14
Android MEDIUM 5.5
CVE-2020-0378

In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local information disclosure of location data…

Mitigation only
Fix from $1,600 2020-10-14
Android MEDIUM 5.5
CVE-2020-0246

In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local information disclosure of EID data…

Mitigation only
Fix from $1,600 2020-10-14
Channelmgnt MEDIUM 6.5
CVE-2020-15251

In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is a…

Fix: 1.0.3+
Fix from $1,600 2020-10-13
Android HIGH 7.5
CVE-2020-26598

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized…

Mitigation only
Fix from $1,950 2020-10-06
GitLab HIGH 8.8
CVE-2020-13296

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tok…

Fix: 13.0.14 / 13.1.8+
Fix from $1,950 2020-09-30
FreeBSD HIGH 8.2
CVE-2020-24718

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restr…

Fix: after 11.2
Fix from $1,950 2020-09-25
Ios Xe Rom Monitor MEDIUM 6.8
CVE-2020-3524

A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cisco ASR 920 Series Aggregation…

Fix: 15.6 / 16.2+
Fix from $1,600 2020-09-24
Ios Xe HIGH 8.8
CVE-2020-3400

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize parts of the web UI for which…

Mitigation only
Fix from $1,950 2020-09-24
Android HIGH 7.8
CVE-2020-0299

In Bluetooth, there is a possible spoofing of bluetooth device metadata due to a missing permission check. This could lead to local escalation of pri…

Mitigation only
Fix from $1,950 2020-09-18
Android MEDIUM 5.5
CVE-2020-0316

In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privile…

Mitigation only
Fix from $1,600 2020-09-18
Android MEDIUM 5.5
CVE-2020-0327

In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution pri…

Mitigation only
Fix from $1,600 2020-09-18
Android MEDIUM 5.5
CVE-2020-0276

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additi…

Mitigation only
Fix from $1,600 2020-09-18
Android MEDIUM 5.5
CVE-2020-0284

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additi…

Mitigation only
Fix from $1,600 2020-09-18
Android MEDIUM 5.5
CVE-2020-0285

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additi…

Mitigation only
Fix from $1,600 2020-09-18
Android HIGH 7.8
CVE-2020-0298

In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing permission check. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2020-09-18
Android MEDIUM 5.5
CVE-2020-0265

In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no ad…

Mitigation only
Fix from $1,600 2020-09-18
Android HIGH 7.8
CVE-2020-0089

In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additiona…

Mitigation only
Fix from $1,950 2020-09-18
Android HIGH 7.8
CVE-2020-0375

In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setti…

Mitigation only
Fix from $1,950 2020-09-17