Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Gemfire HIGH 8.8
CVE-2020-5396

VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed…

Fix: 1.10.2 / 1.11.1+
Fix from $1,950 2020-07-31
Ignition Gateway HIGH 7.5
CVE-2020-14520

The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all version…

Fix: 8.0.13+
Fix from $1,950 2020-07-31
Dashboard Products MEDIUM 6.5
CVE-2020-15102

In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The …

Fix: 2.1.0+
Fix from $1,600 2020-07-21
Openclinic Ga MEDIUM 6.5
CVE-2020-14491

OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to a…

Mitigation only
Fix from $1,600 2020-07-20
Android MEDIUM 5.5
CVE-2020-0107

In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local …

Patch available
Fix from $1,600 2020-07-17
Android HIGH 7.8
CVE-2020-0227

In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to loca…

Patch available
Fix from $1,950 2020-07-17
Kramdown CRITICAL 9.8
CVE-2020-14001

The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such …

Fix: 2.3.0+
Fix from $2,300 2020-07-17
Linux Kernel MEDIUM 6.7
CVE-2020-15780

An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be us…

Fix: 5.7.7+
Fix from $1,600 2020-07-15
Yubikey 5 Nfc Firmware MEDIUM 5.3
CVE-2020-15001

An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set option…

Fix: after 5.3.1
Fix from $1,600 2020-07-09
Vxrail D560f Firmware HIGH 7.5
CVE-2020-5368

Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vul…

Mitigation only
Fix from $1,950 2020-07-06
Veeam Availability Suite HIGH 8.8
CVE-2020-15518

VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged user…

Fix: 10.0+
Fix from $1,950 2020-07-03
Prestashop MEDIUM 5.3
CVE-2020-15080

In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. …

Fix: 1.7.6.6+
Fix from $1,600 2020-07-02
Fortify On Demand MEDIUM 5.4
CVE-2020-2204

A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the glob…

Fix: after 5.0.1
Fix from $1,600 2020-07-02
Docker Desktop HIGH 7.8
CVE-2020-15360

com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.

No fix yet
Fix from $1,950 2020-06-27
Security Secret Server MEDIUM 5.9
CVE-2020-4413

IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T…

Fix: 10.8+
Fix from $1,600 2020-06-24
Emc Unisphere For Powermax MEDIUM 5.4
CVE-2020-5345

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMa…

Fix: 9.1.0.17+
Fix from $1,600 2020-06-23
Pi Hole HIGH 7.8
CVE-2020-14971

Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them…

Fix: after 5.0
Fix from $1,950 2020-06-23
Bsa Radar CRITICAL 9.8
CVE-2020-14944EPSS 6%

Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeo…

Fix: after 1.6.7234.24750
Fix from $2,300 2020-06-22
Misp HIGH 7.5
CVE-2020-14969

app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, reveal…

Patch available
Fix from $1,950 2020-06-22
Mattermost Server HIGH 7.5
CVE-2019-20885

An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.

Fix: 5.8.0+
Fix from $1,950 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2018-21251

An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the param…

Fix: 5.1.1+
Fix from $2,300 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2018-21257

An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) vi…

Fix: 5.1.0+
Fix from $1,600 2020-06-19
Smart Software Manager On Prem MEDIUM 5.3
CVE-2020-3245

A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to creat…

Fix: 8-202004+
Fix from $1,600 2020-06-18
Zammad MEDIUM 5.4
CVE-2020-14213

In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).

Fix: 3.3.1+
Fix from $1,600 2020-06-16
Android HIGH 7.8
CVE-2020-0202

In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing pe…

Patch available
Fix from $1,950 2020-06-11
Android MEDIUM 5.5
CVE-2020-0177

In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connectio…

Patch available
Fix from $1,600 2020-06-11
Android MEDIUM 5.5
CVE-2020-0178

In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local informatio…

Patch available
Fix from $1,600 2020-06-11
Android HIGH 7.8
CVE-2020-0137

In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This …

Patch available
Fix from $1,950 2020-06-11
Liferay Portal HIGH 8.8
CVE-2020-13445

In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not r…

Patch available
Fix from $1,950 2020-06-10
GitLab HIGH 8.8
CVE-2020-13270

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on rest…

Fix: 11.9.8 / 12.9.8+
Fix from $1,950 2020-06-10