Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Erp \(ea Finserv\) HIGH 8.1
CVE-2020-6268

Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 10…

Mitigation only
Fix from $1,950 2020-06-10
Netweaver Application Server Abap MEDIUM 6.5
CVE-2020-6270

SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization …

Mitigation only
Fix from $1,600 2020-06-10
Nextgen Dvr Firmware HIGH 8.8
CVE-2020-11679

Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:U…

No fix yet
Fix from $1,950 2020-06-04
Nextgen Dvr Firmware MEDIUM 6.5
CVE-2020-11680

Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was…

No fix yet
Fix from $1,600 2020-06-04
Ignite CRITICAL 9.1
CVE-2020-1963

Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a fi…

Fix: after 2.8.0
Fix from $2,300 2020-06-03
Spectrum Scale MEDIUM 6.5
CVE-2020-4348

IBM Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.4 could allow an authenticated GUI user to perform unauthorized actions due to …

Fix: after 5.0.4.4
Fix from $1,600 2020-05-27
Trackr Firmware HIGH 7.1
CVE-2020-13425

TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when batte…

Fix: after 2020-05-06
Fix from $1,950 2020-05-23
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2020-13154

Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFil…

No fix yet
Fix from $1,600 2020-05-18
Open Edx Platform HIGH 8.8
CVE-2020-13144EPSS 11%

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new…

No fix yet
Fix from $1,950 2020-05-18
Documents MEDIUM 5.3
CVE-2019-20801

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin request…

Fix: 6.9.7+
Fix from $1,600 2020-05-18
Softpac Project CRITICAL 9.8
CVE-2020-10620

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to…

Fix: after 9.6
Fix from $2,300 2020-05-14
Android HIGH 7.8
CVE-2020-0105

In onKeyguardVisibilityChanged of key_store_service.cpp, there is a missing permission check. This could lead to local escalation of privilege, allow…

Patch available
Fix from $1,950 2020-05-14
Android MEDIUM 5.5
CVE-2020-0106

In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version check. This could lead to local …

Mitigation only
Fix from $1,600 2020-05-14
Android HIGH 7.8
CVE-2020-0109

In simulatePackageSuspendBroadcast of NotificationManagerService.java, there is a missing permission check. This could lead to local escalation of pr…

Patch available
Fix from $1,950 2020-05-14
Softpac Project CRITICAL 9.1
CVE-2020-10612

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open with…

Fix: after 9.6
Fix from $2,300 2020-05-14
Pan Os MEDIUM 5.3
CVE-2020-1996

A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages i…

Fix: after 9.0.8
Fix from $1,600 2020-05-13
Identity Management MEDIUM 6.5
CVE-2020-6258

SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certai…

Mitigation only
Fix from $1,600 2020-05-12
Adaptive Server Enterprise MEDIUM 6.5
CVE-2020-6259

Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information which would otherwise be restr…

Mitigation only
Fix from $1,600 2020-05-12
Android HIGH 7.5
CVE-2020-12745

An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and access clipbo…

Mitigation only
Fix from $1,950 2020-05-11
Doorkeeper HIGH 7.5
CVE-2020-10187

Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the client secret only intend…

Fix: 5.0.3 / 5.1.1+
Fix from $1,950 2020-05-04
Teampass HIGH 8.1
CVE-2020-11671

Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPa…

Fix: after 2.1.27.36
Fix from $1,950 2020-05-04
FreeBSD MEDIUM 5.5
CVE-2019-15876

In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driv…

Patch available
Fix from $1,600 2020-04-28
FreeBSD MEDIUM 5.5
CVE-2019-15877

In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver faile…

Patch available
Fix from $1,600 2020-04-28
Atillk64 HIGH 8.8
CVE-2020-12138

AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that ma…

No fix yet
Fix from $1,950 2020-04-27
Erp MEDIUM 5.4
CVE-2020-6212

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and…

Mitigation only
Fix from $1,600 2020-04-24
Firefox CRITICAL 9.8
CVE-2020-6823

A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise return…

Fix: 75.0+
Fix from $2,300 2020-04-24
Iqrouter Firmware CRITICAL 9.8
CVE-2020-11967

In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Not…

Fix: after 3.3.1
Fix from $2,300 2020-04-21
Ipq6018 Firmware HIGH 7.8
CVE-2019-14116

Privilege escalation by using an altered debug policy image can occur as the XPU protecting the debug policy regions are disabled during the crash du…

Mitigation only
Fix from $1,950 2020-04-16
Fs728tlp Firmware MEDIUM 6.0
CVE-2019-20676

Certain NETGEAR devices are affected by lack of access control at the function level. This affects FS728TLP before 1.0.1.26, GS105Ev2 before 1.6.0.4,…

Fix: 1.0.0.15 / 1.0.1.4+
Fix from $1,600 2020-04-15
Endpoint Security MEDIUM 6.5
CVE-2020-7278

Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to…

Mitigation only
Fix from $1,600 2020-04-15