Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
CRITICAL 9.1 CVE-2021-21685 Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs. Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 CRITICAL 9.1 CVE-2020-25366 An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspe… Dir 823g Firmware Mitigation only Fix from $2,3002021-11-04 HIGH 7.5 CVE-2021-41238 Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process re… Hangfire Mitigation only Fix from $1,9502021-11-02 HIGH 7.5 CVE-2015-20067EPSS 8% The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data … Wp Attachment Export 0.2.4+ Fix from $1,9502021-11-01 HIGH 7.5 CVE-2018-25019 The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment… Learndash after 2.5.4 Fix from $1,9502021-11-01 HIGH 8.1 CVE-2021-39225 Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows ano… Deck 1.2.9 / 1.4.5+ Fix from $1,9502021-10-25 MEDIUM 6.5 CVE-2021-24779 The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF che… Wp Debugging 2.11.0+ Fix from $1,6002021-10-25 MEDIUM 5.5 CVE-2021-0706 In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This coul… Android Mitigation only Fix from $1,6002021-10-22 MEDIUM 5.5 CVE-2021-0643 In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due t… Android Mitigation only Fix from $1,6002021-10-22 CRITICAL 10.0 CVE-2021-31384 Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in … Junos Mitigation only Fix from $2,3002021-10-19 HIGH 8.5 CVE-2021-38486 InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any req… Ir615 Firmware Mitigation only Fix from $1,9502021-10-19 MEDIUM 5.3 CVE-2021-24677 The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enume… Find My Blocks 3.4.0+ Fix from $1,6002021-10-18 HIGH 7.5 CVE-2021-37738 A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10… Clearpass Policy Manager 6.10.2+ Fix from $1,9502021-10-15 MEDIUM 5.4 CVE-2021-42331 The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers… Xinhe Teaching Platform System Mitigation only Fix from $1,6002021-10-15 MEDIUM 6.1 CVE-2021-20834 Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 and Nike App for iOS versions p… Nike 2.177.1 / 2.177.3.3688+ Fix from $1,6002021-10-13 HIGH 8.6 CVE-2021-39184 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, … Electron 11.5.0 / 12.1.0+ Fix from $1,9502021-10-12 HIGH 8.1 CVE-2021-40884 Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php a… Projectsend No fix yet Fix from $1,9502021-10-11 MEDIUM 6.5 CVE-2021-37976 KEVEPSS 20% Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information f… Chrome 94.0.4606.71+ Fix from $1,6002021-10-08 CRITICAL 9.8 CVE-2021-32172EPSS 66% Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. Maian Cart No fix yet Fix from $2,3002021-10-07 MEDIUM 5.5 CVE-2021-0680 In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w… Android Mitigation only Fix from $1,6002021-10-06 MEDIUM 5.5 CVE-2021-0681 In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w… Android Mitigation only Fix from $1,6002021-10-06 MEDIUM 5.5 CVE-2021-0682 In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. … Android Patch available Fix from $1,6002021-10-06 MEDIUM 5.5 CVE-2021-0686 In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user d… Android Patch available Fix from $1,6002021-10-06 HIGH 7.3 CVE-2021-39226 KEVEPSS 100% Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit… Grafana 7.5.11 / 8.1.6+ Fix from $1,9502021-10-05 HIGH 8.8 CVE-2021-41554 ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endp… Web Central No fix yet Fix from $1,9502021-10-05 HIGH 7.5 CVE-2021-39893 A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation. GitLab 14.1.7 / 14.2.5+ Fix from $1,9502021-10-05 CRITICAL 9.1 CVE-2021-41729 BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through… Baicloud Cms No fix yet Fix from $2,3002021-09-30 HIGH 8.8 CVE-2021-3653 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control bl… Linux Kernel 4.4.282 / 4.9.281+ Fix from $1,9502021-09-29 CRITICAL 9.8 CVE-2021-33924 Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allow… Ansible Mitigation only Fix from $2,3002021-09-29 CRITICAL 9.8 CVE-2021-37270 There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly… Cms Enterprise Website Construction System Mitigation only Fix from $2,3002021-09-27