Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.8 CVE-2020-0475 In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. T… Android Mitigation only Fix from $1,9502020-12-15 MEDIUM 5.5 CVE-2020-0477 In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This c… Android Patch available Fix from $1,6002020-12-15 HIGH 7.8 CVE-2020-0480 In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escala… Android Patch available Fix from $1,9502020-12-15 HIGH 7.8 CVE-2020-0485 In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missing permission check. This cou… Android Patch available Fix from $1,9502020-12-15 MEDIUM 5.5 CVE-2020-0468 In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permissi… Android Patch available Fix from $1,6002020-12-14 HIGH 7.8 CVE-2020-0440 In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check.… Android Patch available Fix from $1,9502020-12-14 MEDIUM 5.3 CVE-2020-26408 A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows a… GitLab 13.4.7 / 13.5.5+ Fix from $1,6002020-12-11 CRITICAL 9.8 CVE-2020-28215 A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including … Easergy T300 Firmware after 2.7 Fix from $2,3002020-12-11 HIGH 8.8 CVE-2020-25499 TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality… A3002r Firmware 1.0.0-b20201028.1743 / 1.0.0-b20201103.1713+ Fix from $1,9502020-12-09 HIGH 8.1 CVE-2020-26830 SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due … Solution Manager No fix yet Fix from $1,9502020-12-09 HIGH 7.6 CVE-2020-26832 SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and S… Netweaver Application Server Abap No fix yet Fix from $1,9502020-12-09 MEDIUM 5.5 CVE-2020-27349 Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1… Ubuntu Linux Patch available Fix from $1,6002020-12-09 MEDIUM 5.3 CVE-2020-14205 The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An… Divebook No fix yet Fix from $1,6002020-12-08 HIGH 8.8 CVE-2020-25629 A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some … Moodle 3.5.14 / 3.7.8+ Fix from $1,9502020-12-08 HIGH 7.8 CVE-2020-23740 In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to incr… Drivergenius Mitigation only Fix from $1,9502020-12-03 HIGH 7.8 CVE-2020-23735 In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constructed program to increase user… Cyber Game Accelerator No fix yet Fix from $1,9502020-12-03 MEDIUM 6.5 CVE-2020-25711 A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When … Data Grid 11.0.6+ Fix from $1,6002020-12-03 HIGH 7.5 CVE-2020-2322 Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permis… Chaos Monkey after 0.3 Fix from $1,9502020-12-03 MEDIUM 5.3 CVE-2020-2323 Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission t… Chaos Monkey after 0.4 Fix from $1,6002020-12-03 MEDIUM 6.5 CVE-2017-15680 In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data. Crafter Cms 3.0.1+ Fix from $1,6002020-11-27 MEDIUM 6.5 CVE-2020-26212 GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk fe… Glpi 9.5.3+ Fix from $1,6002020-11-25 CRITICAL 9.8 CVE-2020-29006 MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php. Misp 2.4.135+ Fix from $2,3002020-11-24 MEDIUM 6.7 CVE-2020-26231 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 (fixed in 1.0.469 and 1.1.0) … October Patch available Fix from $1,6002020-11-23 MEDIUM 5.2 CVE-2020-15247 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1… October 1.0.469+ Fix from $1,6002020-11-23 MEDIUM 5.9 CVE-2020-4783 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enab… Spectrum Protect Plus after 10.1.6 Fix from $1,6002020-11-23 HIGH 7.8 CVE-2020-15349 BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool implements an XPC interface th… Forklift 3.4+ Fix from $1,9502020-11-17 HIGH 7.8 CVE-2020-27192 BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allowed a local attacker to injec… Forklift after 3.4 Fix from $1,9502020-11-17 HIGH 8.8 CVE-2020-23489 The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which l… Avideo 8.9+ Fix from $1,9502020-11-16 HIGH 8.8 CVE-2020-26818 SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro compone… Netweaver Application Server Abap Mitigation only Fix from $1,9502020-11-10 MEDIUM 5.5 CVE-2020-0454 In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to lo… Android No fix yet Fix from $1,6002020-11-10