Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Antivirus HIGH 7.8
CVE-2021-45339

Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process wh…

Fix: 20.4+
Fix from $1,950 2021-12-27
Geforce Experience HIGH 8.2
CVE-2021-23175

NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls f…

Fix: 3.24.0.126+
Fix from $1,950 2021-12-23
Chrome HIGH 8.8
CVE-2021-38016

Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via…

Fix: 96.0.4664.45+
Fix from $1,950 2021-12-23
Chrome HIGH 8.8
CVE-2021-38017

Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions …

Fix: 96.0.4664.45+
Fix from $1,950 2021-12-23
Latte CRITICAL 9.8
CVE-2021-23803

This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When th…

Fix: 2.10.6+
Fix from $2,300 2021-12-17
Htcondor HIGH 8.8
CVE-2021-45102

An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may…

Mitigation only
Fix from $1,950 2021-12-16
Android HIGH 7.8
CVE-2021-0649

In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CO…

Mitigation only
Fix from $1,950 2021-12-15
Get Custom Field Values MEDIUM 6.5
CVE-2021-24872

The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validat…

Fix: 4.0+
Fix from $1,600 2021-12-13
Consul HIGH 8.8
CVE-2021-41805EPSS 35%

HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default…

Fix: 1.8.17 / 1.9.11+
Fix from $1,950 2021-12-12
Db2 HIGH 8.7
CVE-2021-29678

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access o…

Mitigation only
Fix from $1,950 2021-12-09
Firefox CRITICAL 10.0
CVE-2021-38503

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navig…

Fix: 91.3 / 94.0+
Fix from $2,300 2021-12-08
Fortiweb MEDIUM 5.3
CVE-2021-41013

An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Re…

Fix: after 6.3.15
Fix from $1,600 2021-12-08
Fortiwlc HIGH 8.8
CVE-2021-42758

An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to …

Fix: after 8.5.5
Fix from $1,950 2021-12-08
Wps Hide Login HIGH 7.5
CVE-2021-24917EPSS 72%

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a …

Fix: 1.9.1+
Fix from $1,950 2021-12-06
Bulk Datetime Change MEDIUM 5.4
CVE-2021-24842

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private…

Fix: 1.12+
Fix from $1,600 2021-11-29
Moodle MEDIUM 5.3
CVE-2021-43560

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks…

Fix: 3.9.11 / 3.10.8+
Fix from $1,600 2021-11-22
Concrete Cms HIGH 8.8
CVE-2021-22966

Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulk…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
Ozone MEDIUM 6.8
CVE-2021-39234

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blo…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Grafana HIGH 7.2
CVE-2021-41244

Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enable…

Fix: 8.2.4+
Fix from $1,950 2021-11-15
Halo\+ Camera Firmware HIGH 8.8
CVE-2021-3577EPSS 60%

An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on …

Fix: 03.40.00 / 03.40.02+
Fix from $1,950 2021-11-12
Aqt1000 Firmware MEDIUM 5.3
CVE-2021-1903

Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snap…

Mitigation only
Fix from $1,600 2021-11-12
Arris Surfboard Sb8200 Firmware HIGH 7.1
CVE-2021-20119

The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrato…

No fix yet
Fix from $1,950 2021-11-09
Mendix MEDIUM 6.5
CVE-2021-42025

A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions…

Fix: 8.18.13 / 9.6.2+
Fix from $1,600 2021-11-09
Post Expirator MEDIUM 6.5
CVE-2021-24783

The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contr…

Fix: 2.6.0+
Fix from $1,600 2021-11-08
Batch Cat MEDIUM 6.5
CVE-2021-24788

The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a res…

Fix: after 0.3
Fix from $1,600 2021-11-08
Spring Cloud Gateway MEDIUM 6.5
CVE-2021-22051

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. User…

Fix: 2.2.10 / 3.0.5+
Fix from $1,600 2021-11-08
Pomerium HIGH 8.8
CVE-2021-41230

Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflect…

Fix: 0.15.6+
Fix from $1,950 2021-11-05
Health MEDIUM 5.5
CVE-2021-25506

Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

Fix: 6.19.1.0001+
Fix from $1,600 2021-11-05
Jenkins CRITICAL 9.8
CVE-2021-21693

When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earli…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Optinmonster HIGH 8.2
CVE-2021-39341EPSS 22%

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorizatio…

Fix: after 2.6.4
Fix from $1,950 2021-11-01