Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Logo Slider And Showcase MEDIUM 6.5
CVE-2021-24742

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action bec…

Fix: 1.3.37+
Fix from $1,600 2021-11-01
Stylish Price List MEDIUM 5.3
CVE-2021-24757

The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unau…

Fix: 6.9.0+
Fix from $1,600 2021-11-01
Stylish Price List MEDIUM 6.5
CVE-2021-24770

The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authentic…

Fix: 6.9.1+
Fix from $1,600 2021-11-01
Automatorwp HIGH 8.8
CVE-2021-24717

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, d…

Fix: 1.7.6+
Fix from $1,950 2021-11-01
Dspace HIGH 7.2
CVE-2021-41189

DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up t…

Patch available
Fix from $1,950 2021-10-29
Sassy Social Share HIGH 8.8
CVE-2021-39321

Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action…

Patch available
Fix from $1,950 2021-10-21
Brizy Page Builder MEDIUM 6.5
CVE-2021-38345

The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in…

Fix: 1.0.1.126+
Fix from $1,600 2021-10-14
Remote Service Manager MEDIUM 5.4
CVE-2021-20803

Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the dat…

Mitigation only
Fix from $1,600 2021-10-13
Windows Server MEDIUM 5.3
CVE-2021-40456

Windows AD FS Security Feature Bypass Vulnerability

Patch available
Fix from $1,600 2021-10-13
Zammad MEDIUM 5.3
CVE-2021-42137

An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of ticke…

Fix: 5.0.1+
Fix from $1,600 2021-10-11
Wire CRITICAL 9.8
CVE-2021-41093

Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by …

Fix: 3.86+
Fix from $2,300 2021-10-04
Postx Gutenberg Blocks For Post Grid MEDIUM 6.5
CVE-2021-24652

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform som…

Fix: 2.4.10+
Fix from $1,600 2021-09-27
Dir 615 Firmware MEDIUM 6.5
CVE-2021-40654

An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the /…

No fix yet
Fix from $1,600 2021-09-24
Dir 605l Firmware HIGH 7.5
CVE-2021-40655 KEVEPSS 87%

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a po…

Mitigation only
Fix from $1,950 2021-09-24
Druid MEDIUM 6.5
CVE-2021-36749EPSS 81%

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…

Fix: 0.22.0+
Fix from $1,600 2021-09-24
Ninja Forms MEDIUM 6.5
CVE-2021-34647

The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/R…

Fix: after 3.5.7
Fix from $1,600 2021-09-22
Wuzhicms HIGH 8.8
CVE-2020-19551

Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.

Fix: after 4.1.0
Fix from $1,950 2021-09-21
Discourse HIGH 7.5
CVE-2021-41082

Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user…

Fix: 2021-09-14+
Fix from $1,950 2021-09-20
15.4 Stack MEDIUM 6.8
CVE-2020-16630

TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just W…

No fix yet
Fix from $1,600 2021-09-20
Super Hub 3 Firmware MEDIUM 5.3
CVE-2019-16651

An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechani…

No fix yet
Fix from $1,600 2021-09-20
Jfinal Cms HIGH 7.5
CVE-2021-40639

Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.confi…

No fix yet
Fix from $1,950 2021-09-15
Ureport CRITICAL 9.8
CVE-2020-21124

UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.

No fix yet
Fix from $2,300 2021-09-15
Envoy HIGH 8.6
CVE-2021-39206

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-202…

Fix: 0.14.8 / 1.16.5+
Fix from $1,950 2021-09-09
Eibport Firmware CRITICAL 9.8
CVE-2021-28911

BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. devi…

Fix: 3.9.1+
Fix from $2,300 2021-09-09
Magento MEDIUM 6.5
CVE-2021-28567

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in …

Fix: after 2.4.2
Fix from $1,600 2021-09-08
Sdm600 Firmware HIGH 7.8
CVE-2021-35526

Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensi…

Fix: 1.2.14002.257+
Fix from $1,950 2021-09-08
Proofofdiligencetoken HIGH 7.5
CVE-2020-19765

An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a reentrancy attack.

No fix yet
Fix from $1,950 2021-09-07
Owncloud MEDIUM 5.3
CVE-2021-35949

The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list meta…

Fix: 10.8.0+
Fix from $1,600 2021-09-07
Gutenberg Template Library \& Redux Framework MEDIUM 6.5
CVE-2021-38312

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints regis…

Fix: after 4.2.11
Fix from $1,600 2021-09-02
Data Center MEDIUM 5.3
CVE-2021-39119

Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even afte…

Fix: 8.19.0+
Fix from $1,600 2021-09-01