Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android MEDIUM 5.5
CVE-2020-0372

In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2020-09-17
Android HIGH 7.8
CVE-2020-0341

In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no …

Mitigation only
Fix from $1,950 2020-09-17
Android MEDIUM 5.5
CVE-2020-0343

In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosu…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 5.5
CVE-2020-0314

In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execu…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 5.5
CVE-2020-0317

In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure…

Mitigation only
Fix from $1,600 2020-09-17
Android HIGH 7.8
CVE-2020-0277

In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2020-09-17
Android MEDIUM 5.5
CVE-2020-0288

In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional exe…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 5.5
CVE-2020-0289

In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution pri…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 5.5
CVE-2020-0290

In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution pri…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 5.5
CVE-2020-0293

In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could lead to local information dis…

No fix yet
Fix from $1,600 2020-09-17
Android HIGH 7.8
CVE-2020-0266

In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2020-09-17
Android HIGH 7.8
CVE-2020-0387

In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escala…

Mitigation only
Fix from $1,950 2020-09-17
Android HIGH 7.8
CVE-2020-0401

In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and g…

Mitigation only
Fix from $1,950 2020-09-17
Istio Operator HIGH 8.8
CVE-2020-14306

An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions through 1.1.3. This flaw allows …

Fix: after 1.1.3
Fix from $1,950 2020-09-16
Android CRITICAL 9.8
CVE-2020-25282

An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows a…

Mitigation only
Fix from $2,300 2020-09-11
Android CRITICAL 9.8
CVE-2020-25283

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access re…

Mitigation only
Fix from $2,300 2020-09-11
Windows 10 MEDIUM 5.5
CVE-2020-0989

<p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker w…

Patch available
Fix from $1,600 2020-09-11
Database MEDIUM 6.5
CVE-2020-2242

A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-…

Fix: after 1.6
Fix from $1,600 2020-09-01
Premid MEDIUM 5.3
CVE-2020-24928

managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origins, which allows attackers to…

Fix: after 2.1.3
Fix from $1,600 2020-08-29
Nx Os HIGH 7.8
CVE-2020-3394

A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could …

Mitigation only
Fix from $1,950 2020-08-27
Security Guardium Insights MEDIUM 5.9
CVE-2020-4175

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…

Patch available
Fix from $1,600 2020-08-27
Smart Software Manager On Prem HIGH 8.8
CVE-2020-3443

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute…

Mitigation only
Fix from $1,950 2020-08-26
Fedora HIGH 8.8
CVE-2020-24614

Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must ha…

Fix: 2.10.2 / 2.11.2+
Fix from $1,950 2020-08-25
Generic Market Data HIGH 8.1
CVE-2020-6298

SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Marke…

Mitigation only
Fix from $1,950 2020-08-12
Hcm Travel Management HIGH 8.1
CVE-2020-6301

SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify…

No fix yet
Fix from $1,950 2020-08-12
Pipeline Maven Integration MEDIUM 6.5
CVE-2020-2234

A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an atta…

Fix: after 3.8.2
Fix from $1,600 2020-08-12
Android MEDIUM 5.5
CVE-2020-0239

In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This c…

Mitigation only
Fix from $1,600 2020-08-11
Android MEDIUM 5.5
CVE-2020-0250

In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure …

Mitigation only
Fix from $1,600 2020-08-11
Solidus MEDIUM 5.3
CVE-2020-15109

In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerab…

Fix: 2.8.6 / 2.9.6+
Fix from $1,600 2020-08-04
Gantt Chart HIGH 8.1
CVE-2020-15943

An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the mo…

Fix: 5.5.4+
Fix from $1,950 2020-08-04