Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2020-10858 Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler. Zulip Desktop 5.0.0+ Fix from $1,6002021-02-05 MEDIUM 6.5 CVE-2020-29604 An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues… Mantisbt 2.24.4+ Fix from $1,6002021-01-29 MEDIUM 5.9 CVE-2020-4816 IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTT… Cloud Pak For Security Patch available Fix from $1,6002021-01-27 MEDIUM 5.5 CVE-2020-7343 Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulatin… Agent 5.7.1+ Fix from $1,6002021-01-18 HIGH 7.5 CVE-2021-21246EPSS 49% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that o… Onedev 4.0.3+ Fix from $1,9502021-01-15 HIGH 8.8 CVE-2020-27220 The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control mess… Hono after 1.4.4 Fix from $1,9502021-01-14 MEDIUM 6.7 CVE-2020-9209 There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located improperly. It does not apply the … Smc2.0 Firmware Mitigation only Fix from $1,6002021-01-13 MEDIUM 5.3 CVE-2021-23123 An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublishe… Joomla\! after 3.9.23 Fix from $1,6002021-01-12 MEDIUM 6.5 CVE-2021-21468 The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allow… Business Warehouse No fix yet Fix from $1,6002021-01-12 MEDIUM 5.3 CVE-2020-5022 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtai… Spectrum Protect Plus 10.1.7+ Fix from $1,6002021-01-08 MEDIUM 6.5 CVE-2020-16027 Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malic… Chrome 87.0.4280.66+ Fix from $1,6002021-01-08 HIGH 8.8 CVE-2020-16029 Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a craft… Chrome 87.0.4280.66+ Fix from $1,9502021-01-08 HIGH 8.8 CVE-2020-35745 PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of us… Hospital Management System No fix yet Fix from $1,9502021-01-07 HIGH 7.5 CVE-2020-29160 An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing. Zammad 3.5.1+ Fix from $1,9502020-12-28 HIGH 8.8 CVE-2020-25917 Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "hel… Notouch Center 4.4.68+ Fix from $1,9502020-12-26 MEDIUM 6.5 CVE-2019-11783 Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote auth… Odoo after 14.0 Fix from $1,6002020-12-22 MEDIUM 6.5 CVE-2019-11784 Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authent… Odoo after 14.0 Fix from $1,6002020-12-22 HIGH 8.8 CVE-2020-35625 An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace c… Mediawiki after 1.35.1 Fix from $1,9502020-12-21 MEDIUM 5.9 CVE-2020-4841 IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T… Security Secret Server Patch available Fix from $1,6002020-12-21 HIGH 8.8 CVE-2020-13512 A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted … Cam No fix yet Fix from $1,9502020-12-18 HIGH 8.8 CVE-2020-13513 A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted … Cam No fix yet Fix from $1,9502020-12-18 HIGH 8.8 CVE-2020-13514 A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted … Cam No fix yet Fix from $1,9502020-12-18 HIGH 8.8 CVE-2020-13515 A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/O request… Cam No fix yet Fix from $1,9502020-12-18 HIGH 8.8 CVE-2020-13519 A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/O request… Cam No fix yet Fix from $1,9502020-12-18 HIGH 8.8 CVE-2020-29479 An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for t… Debian Linux after 4.14.0 Fix from $1,9502020-12-15 MEDIUM 6.7 CVE-2020-27777 A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest sy… Linux Kernel 4.14.204 / 4.19.155+ Fix from $1,6002020-12-15 HIGH 7.8 CVE-2020-27052 In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a permissions bypass. This cou… Android Patch available Fix from $1,9502020-12-15 HIGH 7.8 CVE-2020-27054 In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no addi… Android Patch available Fix from $1,9502020-12-15 MEDIUM 5.5 CVE-2020-27032 In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing permission check. This could lead… Android Mitigation only Fix from $1,6002020-12-15 MEDIUM 5.5 CVE-2020-0497 In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information disclosure with no additional e… Android Mitigation only Fix from $1,6002020-12-15