Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2021-34647 The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/R… Ninja Forms after 3.5.7 Fix from $1,6002021-09-22 MEDIUM 5.4 CVE-2021-24635 The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all… Visual Link Preview 2.2.3+ Fix from $1,6002021-09-20 HIGH 8.1 CVE-2021-24639 The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which … Omgf 4.5.4+ Fix from $1,9502021-09-20 HIGH 8.8 CVE-2021-33704 The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricte… Business One Patch available Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-22149 Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate rou… Enterprise Search 7.14.0+ Fix from $1,9502021-09-15 MEDIUM 6.5 CVE-2021-22147 Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining… Elasticsearch 7.14.0+ Fix from $1,6002021-09-15 HIGH 7.5 CVE-2021-41077 The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not spec… Travis Ci after 2021-09-10 Fix from $1,9502021-09-14 CRITICAL 9.8 CVE-2021-37535 SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization… Netweaver Application Server Java Mitigation only Fix from $2,3002021-09-14 MEDIUM 5.4 CVE-2021-38164 SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE … Erp Financial Accounting Mitigation only Fix from $1,6002021-09-14 HIGH 8.8 CVE-2021-38388 Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project. Central Dogma 0.51.1+ Fix from $1,9502021-09-08 CRITICAL 9.8 CVE-2020-24672 A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This… Base Software after 6.1 Fix from $2,3002021-09-08 HIGH 7.8 CVE-2021-30713 KEVEPSS 7% A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass … Mac Os X 11.4+ Fix from $1,9502021-09-08 MEDIUM 5.5 CVE-2021-30657 KEVEPSS 69% A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious… Mac Os X 11.3+ Fix from $1,6002021-09-08 MEDIUM 6.5 CVE-2021-38698 HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service … Consul 1.8.15 / 1.9.9+ Fix from $1,6002021-09-07 HIGH 8.1 CVE-2021-40378EPSS 15% An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from t… Ip70 Firmware No fix yet Fix from $1,9502021-09-01 HIGH 7.5 CVE-2021-40379EPSS 22% An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization. Ip70 Firmware No fix yet Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-36232 Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges. Mik.starlight No fix yet Fix from $1,9502021-08-31 MEDIUM 5.4 CVE-2021-40088 An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling cli… Ejbca 7.6.0+ Fix from $1,6002021-08-25 HIGH 7.5 CVE-2021-30874 An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installe… Ipados 12.0.1 / 15.0+ Fix from $1,9502021-08-24 CRITICAL 9.1 CVE-2020-25359 An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted r… Rconfig No fix yet Fix from $2,3002021-08-20 HIGH 7.8 CVE-2020-27464 An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file. Rconfig after 3.9.6 Fix from $1,9502021-08-20 HIGH 7.8 CVE-2020-27466 An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a craf… Rconfig Mitigation only Fix from $1,9502021-08-20 MEDIUM 5.5 CVE-2021-0415 In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information discl… Android Mitigation only Fix from $1,6002021-08-18 MEDIUM 5.5 CVE-2021-0641 In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission … Android Patch available Fix from $1,6002021-08-17 MEDIUM 5.5 CVE-2021-0642 In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permis… Android Patch available Fix from $1,6002021-08-17 MEDIUM 5.3 CVE-2021-38755 Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php. Hospital Management System No fix yet Fix from $1,6002021-08-16 CRITICAL 9.8 CVE-2020-18753 An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted pa… Mac1100 Plc Firmware No fix yet Fix from $2,3002021-08-13 HIGH 7.5 CVE-2020-18757 An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet. Mac1100 Plc Firmware No fix yet Fix from $1,9502021-08-13 HIGH 8.1 CVE-2021-24500 Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer… Workreap 2.2.2+ Fix from $1,9502021-08-09 HIGH 8.1 CVE-2021-24501 The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform criti… Workreap 2.2.2+ Fix from $1,9502021-08-09