Vulnerability index

Browse CVEs

6,923 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 8.8 CVE-2020-5396 VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed… Gemfire 1.10.2 / 1.11.1+ Fix from $1,9502020-07-31 HIGH 7.5 CVE-2020-14520 The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all version… Ignition Gateway 8.0.13+ Fix from $1,9502020-07-31 MEDIUM 6.5 CVE-2020-15102 In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The … Dashboard Products 2.1.0+ Fix from $1,6002020-07-21 MEDIUM 6.5 CVE-2020-14491 OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to a… Openclinic Ga Mitigation only Fix from $1,6002020-07-20 MEDIUM 5.5 CVE-2020-0107 In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local … Android Patch available Fix from $1,6002020-07-17 HIGH 7.8 CVE-2020-0227 In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to loca… Android Patch available Fix from $1,9502020-07-17 CRITICAL 9.8 CVE-2020-14001 The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such … Kramdown 2.3.0+ Fix from $2,3002020-07-17 MEDIUM 6.7 CVE-2020-15780 An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be us… Linux Kernel 5.7.7+ Fix from $1,6002020-07-15 MEDIUM 5.3 CVE-2020-15001 An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set option… Yubikey 5 Nfc Firmware after 5.3.1 Fix from $1,6002020-07-09 HIGH 7.5 CVE-2020-5368 Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vul… Vxrail D560f Firmware Mitigation only Fix from $1,9502020-07-06 HIGH 8.8 CVE-2020-15518 VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged user… Veeam Availability Suite 10.0+ Fix from $1,9502020-07-03 MEDIUM 5.3 CVE-2020-15080 In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. … Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 MEDIUM 5.4 CVE-2020-2204 A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the glob… Fortify On Demand after 5.0.1 Fix from $1,6002020-07-02 HIGH 7.8 CVE-2020-15360 com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification. Docker Desktop No fix yet Fix from $1,9502020-06-27 MEDIUM 5.9 CVE-2020-4413 IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T… Security Secret Server 10.8+ Fix from $1,6002020-06-24 MEDIUM 5.4 CVE-2020-5345 Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMa… Emc Unisphere For Powermax 9.1.0.17+ Fix from $1,6002020-06-23 HIGH 7.8 CVE-2020-14971 Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them… Pi Hole after 5.0 Fix from $1,9502020-06-23 CRITICAL 9.8 CVE-2020-14944EPSS 6% Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeo… Bsa Radar after 1.6.7234.24750 Fix from $2,3002020-06-22 HIGH 7.5 CVE-2020-14969 app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, reveal… Misp Patch available Fix from $1,9502020-06-22 HIGH 7.5 CVE-2019-20885 An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file. Mattermost Server 5.8.0+ Fix from $1,9502020-06-19 CRITICAL 9.8 CVE-2018-21251 An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the param… Mattermost Server 5.1.1+ Fix from $2,3002020-06-19 MEDIUM 5.3 CVE-2018-21257 An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) vi… Mattermost Server 5.1.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2020-3245 A vulnerability in the web application of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to creat… Smart Software Manager On Prem 8-202004+ Fix from $1,6002020-06-18 MEDIUM 5.4 CVE-2020-14213 In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge). Zammad 3.3.1+ Fix from $1,6002020-06-16 HIGH 7.8 CVE-2020-0202 In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing pe… Android Patch available Fix from $1,9502020-06-11 MEDIUM 5.5 CVE-2020-0177 In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connectio… Android Patch available Fix from $1,6002020-06-11 MEDIUM 5.5 CVE-2020-0178 In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local informatio… Android Patch available Fix from $1,6002020-06-11 HIGH 7.8 CVE-2020-0137 In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This … Android Patch available Fix from $1,9502020-06-11 HIGH 8.8 CVE-2020-13445 In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not r… Liferay Portal Patch available Fix from $1,9502020-06-10 HIGH 8.8 CVE-2020-13270 Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on rest… GitLab 11.9.8 / 12.9.8+ Fix from $1,9502020-06-10