Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2021-24184 Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to m… Tutor Lms 1.7.7+ Fix from $1,9502021-04-05 HIGH 8.8 CVE-2021-24163 The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, ther… Ninja Forms 3.4.34+ Fix from $1,9502021-04-05 MEDIUM 5.5 CVE-2020-29621 This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007… Mac Os X 10.14.6 / 10.15.7+ Fix from $1,6002021-04-02 MEDIUM 5.3 CVE-2020-36238 The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.… Data Center 8.5.13 / 8.13.5+ Fix from $1,6002021-04-01 MEDIUM 6.5 CVE-2021-21632 A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an … Owasp Dependency Track after 3.1.0 Fix from $1,6002021-03-30 MEDIUM 6.5 CVE-2021-21637 A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to connect to a… Team Foundation Server after 5.157.1 Fix from $1,6002021-03-30 HIGH 7.5 CVE-2021-28669 Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.02… Altalink B8045 Firmware 103.001.020.23120 / 103.002.020.23120+ Fix from $1,9502021-03-29 CRITICAL 9.1 CVE-2021-26990 Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files. Cloud Manager 3.9.4+ Fix from $2,3002021-03-19 HIGH 7.5 CVE-2021-27656 A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exa… Exacqvision Web Service after 20.12.2.0 Fix from $1,9502021-03-18 HIGH 7.5 CVE-2021-24146EPSS 31% Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the exp… Modern Events Calendar Lite 5.16.5+ Fix from $1,9502021-03-18 HIGH 7.8 CVE-2021-28375 An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from… Linux Kernel 5.4.106 / 5.10.24+ Fix from $1,9502021-03-15 CRITICAL 9.1 CVE-2021-28154 Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vul… Modeler after 4.6.0 Fix from $2,3002021-03-11 HIGH 7.2 CVE-2020-14987 An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because th… Experience Manager after 14.2.2 Fix from $1,9502021-03-11 CRITICAL 9.8 CVE-2021-28141 An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web… Telerik Ui For Asp.net Ajax No fix yet Fix from $2,3002021-03-11 HIGH 7.8 CVE-2021-0380 In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony settings due to a missing permission… Android Patch available Fix from $1,9502021-03-10 HIGH 7.8 CVE-2021-0385 In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connection to untrusted WiFi networks… Android Patch available Fix from $1,9502021-03-10 HIGH 7.8 CVE-2021-0388 In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast handler. This could lead to … Android Patch available Fix from $1,9502021-03-10 HIGH 7.8 CVE-2021-0389 In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no … Android Patch available Fix from $1,9502021-03-10 HIGH 7.8 CVE-2021-0390 In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check. T… Android Mitigation only Fix from $1,9502021-03-10 HIGH 8.8 CVE-2021-21487 SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Payment Engine Mitigation only Fix from $1,9502021-03-09 HIGH 8.8 CVE-2021-21486 SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authoriz… Enterprise Financial Services Mitigation only Fix from $1,9502021-03-09 MEDIUM 6.5 CVE-2021-21326 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi 9.5.4+ Fix from $1,6002021-03-08 HIGH 7.5 CVE-2021-21327 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi 9.5.4+ Fix from $1,9502021-03-08 MEDIUM 5.5 CVE-2021-25344 Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without per… Android Mitigation only Fix from $1,6002021-03-04 CRITICAL 9.8 CVE-2021-21978EPSS 99% VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authoriza… View Planner 4.6+ Fix from $2,3002021-03-03 MEDIUM 6.5 CVE-2021-22877 A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration whe… Nextcloud Server 20.0.6+ Fix from $1,6002021-03-03 MEDIUM 5.7 CVE-2021-21255 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi Patch available Fix from $1,6002021-03-02 MEDIUM 6.5 CVE-2021-23975 The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function … Firefox 86.0+ Fix from $1,6002021-02-26 CRITICAL 9.8 CVE-2021-21307EPSS 89% Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before version… Lucee Server 5.3.5.96 / 5.3.6.68+ Fix from $2,3002021-02-11 HIGH 7.8 CVE-2021-0328 In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to… Android Patch available Fix from $1,9502021-02-10