Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2021-23204 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to… Command Centre 8.30.1359 / 8.40.1888+ Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2020-13938EPSS 12% Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows HTTP Server 5.10.0+ Fix from $1,6002021-06-10 MEDIUM 6.3 CVE-2021-21473 SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC… Netweaver Application Server Abap No fix yet Fix from $1,6002021-06-09 MEDIUM 6.0 CVE-2021-32015 In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to … Npct75x Firmware Mitigation only Fix from $1,6002021-06-08 CRITICAL 9.8 CVE-2021-31921 Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in th… Istio 1.8.6 / 1.9.5+ Fix from $2,3002021-06-02 MEDIUM 6.5 CVE-2020-10701 A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connec… Libvirt 6.2.0+ Fix from $1,6002021-05-27 CRITICAL 9.8 CVE-2021-22891 A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow un… Sharefile Storagezones Controller 5.7.3 / 5.9.3+ Fix from $2,3002021-05-27 HIGH 7.5 CVE-2018-10865 It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use… Certification Mitigation only Fix from $1,9502021-05-26 CRITICAL 9.1 CVE-2018-10866 It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use… Certification Mitigation only Fix from $2,3002021-05-26 CRITICAL 9.1 CVE-2020-4669 IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it … Planning Analytics Cloud Patch available Fix from $2,3002021-05-17 MEDIUM 5.3 CVE-2021-32917 An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP accou… Debian Linux 0.11.9+ Fix from $1,6002021-05-13 HIGH 8.8 CVE-2021-23014 On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for … Big Ip Advanced Web Application Firewall 14.1.4 / 15.1.3+ Fix from $1,9502021-05-10 CRITICAL 9.8 CVE-2021-27573 An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with n… Emote Remote Mouse after 4.0.0.0 Fix from $2,3002021-05-07 CRITICAL 9.8 CVE-2021-21984 VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious ac… Vrealize Business For Cloud 7.6.0+ Fix from $2,3002021-05-07 MEDIUM 6.5 CVE-2021-32093 The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the Con… Emissary No fix yet Fix from $1,6002021-05-07 HIGH 8.1 CVE-2021-32095 U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files. Emissary Mitigation only Fix from $1,9502021-05-07 HIGH 7.5 CVE-2020-18888 Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php. Puppycms No fix yet Fix from $1,9502021-05-06 HIGH 8.8 CVE-2021-1505 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to… Catalyst Sd Wan Manager 20.3.3 / 20.4.1+ Fix from $1,9502021-05-06 HIGH 7.2 CVE-2021-1506 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to… Catalyst Sd Wan Manager 20.3.3 / 20.4.1+ Fix from $1,9502021-05-06 HIGH 8.8 CVE-2021-1508 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to… Catalyst Sd Wan Manager 19.2.99 / 20.3.3+ Fix from $1,9502021-05-06 MEDIUM 5.2 CVE-2021-21264 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1… October after 1.1.1 Fix from $1,6002021-05-03 HIGH 7.5 CVE-2021-20693 Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and earlier allows a remote attacker… Gurunavi after 11.1.2 Fix from $1,9502021-04-26 MEDIUM 5.3 CVE-2021-27598 SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ… Netweaver Application Server Java Mitigation only Fix from $1,6002021-04-13 MEDIUM 6.5 CVE-2021-27609 SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData s… Focused Run Mitigation only Fix from $1,6002021-04-13 MEDIUM 5.5 CVE-2021-0428 In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could … Android Patch available Fix from $1,6002021-04-13 MEDIUM 6.5 CVE-2021-21432 Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0… Vela 0.7.5+ Fix from $1,6002021-04-09 MEDIUM 5.3 CVE-2020-36287EPSS 9% The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from ve… Data Center 8.13.5 / 8.15.1+ Fix from $1,6002021-04-09 MEDIUM 6.5 CVE-2021-22513 Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and ea… Application Automation Tools after 6.7 Fix from $1,6002021-04-08 HIGH 8.1 CVE-2021-27900 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. Th… Insider Threat Management 7.9.3 / 7.10.3+ Fix from $1,9502021-04-06 HIGH 8.1 CVE-2020-13422 OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions. Openiam 4.2.0.3+ Fix from $1,9502021-04-06