Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Adobe Commerce MEDIUM 6.5
CVE-2021-36039

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,600 2021-09-01
Fedora MEDIUM 5.3
CVE-2021-34434

In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is …

Fix: after 2.0.11
Fix from $1,600 2021-08-30
Fedora MEDIUM 6.8
CVE-2021-28696

IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to…

Mitigation only
Fix from $1,600 2021-08-27
GitLab MEDIUM 5.4
CVE-2021-22256

Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-25
GitLab HIGH 8.8
CVE-2021-22236

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability i…

Fix: 14.1.2+
Fix from $1,950 2021-08-25
Istio HIGH 7.5
CVE-2021-39156

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a…

Fix: 1.9.8 / 1.10.3+
Fix from $1,950 2021-08-24
Istio HIGH 7.5
CVE-2021-39155

Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a…

Fix: 1.9.8 / 1.10.4+
Fix from $1,950 2021-08-24
Envoy HIGH 8.3
CVE-2021-32779

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrect…

Fix: 1.16.5 / 1.17.4+
Fix from $1,950 2021-08-24
Envoy HIGH 8.3
CVE-2021-32777

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz …

Fix: 1.16.5 / 1.17.4+
Fix from $1,950 2021-08-24
Mac Os X HIGH 8.6
CVE-2021-30975

This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed in macOS Monterey 12.1, Securi…

Fix: 10.15.7 / 11.6.2+
Fix from $1,950 2021-08-24
macOS MEDIUM 5.5
CVE-2021-30987

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.1. A device may be passively tracked via BS…

Fix: 12.1+
Fix from $1,600 2021-08-24
Mac Os X MEDIUM 5.5
CVE-2021-30972

This issue was addressed with improved checks. This issue is fixed in Security Update 2022-001 Catalina, macOS Big Sur 11.6.3. A malicious applicatio…

Fix: 10.15.7 / 11.6.3+
Fix from $1,600 2021-08-24
Ipados CRITICAL 9.1
CVE-2021-30925

The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious appl…

Fix: 8.0 / 11.6+
Fix from $2,300 2021-08-24
macOS CRITICAL 9.1
CVE-2021-30856

This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS…

Fix: 11.3+
Fix from $2,300 2021-08-24
Joomla\! CRITICAL 9.1
CVE-2021-26040

An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.

Mitigation only
Fix from $2,300 2021-08-24
GitLab MEDIUM 5.4
CVE-2021-22253

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments t…

Fix: 13.12.9 / 14.0.7+
Fix from $1,600 2021-08-23
Wp Cerber MEDIUM 5.3
CVE-2021-37598

WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

Fix: 8.9.3+
Fix from $1,600 2021-08-19
Parse Server MEDIUM 6.5
CVE-2021-39138

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup use…

Fix: 4.5.1+
Fix from $1,600 2021-08-19
Android HIGH 7.8
CVE-2021-0645

In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, all…

Patch available
Fix from $1,950 2021-08-17
Rest Api CRITICAL 9.9
CVE-2021-32829

ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networki…

Fix: 3.8.21 / 3.10.8+
Fix from $2,300 2021-08-17
Lin Cms Flask CRITICAL 9.8
CVE-2020-18701

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the applicatio…

No fix yet
Fix from $2,300 2021-08-16
Onefuzz CRITICAL 10.0
CVE-2021-37705

OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow…

Fix: 2.31.0+
Fix from $2,300 2021-08-13
Fabric Operating System MEDIUM 5.3
CVE-2021-27793

ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fa…

Fix: 8.2.3 / 9.0.1+
Fix from $1,600 2021-08-12
Sapphireims HIGH 8.8
CVE-2020-25564

In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing Remote…

No fix yet
Fix from $1,950 2021-08-11
Cpu 1504d Tf Firmware MEDIUM 5.3
CVE-2020-28397

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl…

Fix: 2.9.2 / 4.0+
Fix from $1,600 2021-08-10
Securewatch Managed Services HIGH 8.1
CVE-2021-38137

Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform act…

Mitigation only
Fix from $1,950 2021-08-06
Digital Experience Platform HIGH 7.2
CVE-2021-33335

Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows re…

Fix: 7.3.5+
Fix from $1,950 2021-08-03
Vaethink CRITICAL 9.8
CVE-2020-19301

A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condi…

No fix yet
Fix from $2,300 2021-08-03
Chrome CRITICAL 9.6
CVE-2021-30571

Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious e…

Fix: 92.0.4515.107+
Fix from $2,300 2021-08-03
Emui CRITICAL 9.8
CVE-2021-22389

There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.

Mitigation only
Fix from $2,300 2021-08-02