Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Zenworks Configuration Management MEDIUM 6.7
CVE-2021-22521

A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all p…

Fix: 2020+
Fix from $1,600 2021-07-30
Orion Platform MEDIUM 5.4
CVE-2021-28674

The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's pe…

Fix: after 2020.2.5
Fix from $1,600 2021-07-30
Terraform HIGH 8.8
CVE-2021-36230

HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the …

Fix: 202107-1+
Fix from $1,950 2021-07-20
Connect MEDIUM 5.4
CVE-2021-36758

1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to per…

Fix: 1.2+
Fix from $1,600 2021-07-16
Wifi Digital Microscope 3 Firmware HIGH 7.5
CVE-2020-12733

Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkad…

No fix yet
Fix from $1,950 2021-07-15
Mendix MEDIUM 5.3
CVE-2021-33718

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications using Mendix 8 (All versions…

Fix: 7.23.22 / 8.18.7+
Fix from $1,600 2021-07-13
Netiq Advanced Authentication MEDIUM 6.5
CVE-2021-22515

Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication ve…

Fix: 6.3+
Fix from $1,600 2021-07-12
Ninjarmm HIGH 7.8
CVE-2021-26273

The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.

No fix yet
Fix from $1,950 2021-07-07
Easy Cookies Policy MEDIUM 6.5
CVE-2021-24405EPSS 11%

The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated …

Fix: after 1.6.2
Fix from $1,600 2021-07-06
Debian Linux HIGH 7.5
CVE-2021-35197

In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot accou…

Fix: 1.31.15 / 1.35.3+
Fix from $1,950 2021-07-02
Mediawiki HIGH 8.8
CVE-2021-36132

An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRig…

Fix: after 1.36
Fix from $1,950 2021-07-02
Akkadian Provisioning Manager HIGH 8.8
CVE-2020-27362

An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configurat…

No fix yet
Fix from $1,950 2021-07-01
F4 Snc Firmware HIGH 8.8
CVE-2021-27661

Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an uninte…

Mitigation only
Fix from $1,950 2021-07-01
Spring Security HIGH 7.5
CVE-2021-22119EPSS 6%

Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-S…

Fix: 5.2.11 / 5.3.10+
Fix from $1,950 2021-06-29
Oathkeeper HIGH 7.5
CVE-2021-32701

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. When …

Patch available
Fix from $1,950 2021-06-22
Linux Kernel HIGH 7.8
CVE-2010-2525

A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain a…

Patch available
Fix from $1,950 2021-06-22
Android HIGH 7.8
CVE-2021-0571

In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possi…

Mitigation only
Fix from $1,950 2021-06-22
Joomla\! CRITICAL 9.8
CVE-2010-1435

Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subse…

Fix: after 1.5.15
Fix from $2,300 2021-06-21
Comments Like Dislike MEDIUM 5.3
CVE-2021-24379

The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying th…

Fix: 1.1.4+
Fix from $1,600 2021-06-21
White Shark Systems HIGH 8.8
CVE-2020-20471

White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to …

No fix yet
Fix from $1,950 2021-06-21
White Shark Systems CRITICAL 9.8
CVE-2020-20466

White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.

No fix yet
Fix from $2,300 2021-06-21
Esoms HIGH 7.5
CVE-2021-26845

Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access …

Fix: 6.0.4.2.2 / 6.1.4+
Fix from $1,950 2021-06-14
Android HIGH 7.8
CVE-2021-0472

In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could l…

Patch available
Fix from $1,950 2021-06-11
Android HIGH 7.1
CVE-2021-25410

Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an esc…

No fix yet
Fix from $1,950 2021-06-11
Internet HIGH 7.8
CVE-2021-25418

Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activit…

Fix: 14.0.1.62+
Fix from $1,950 2021-06-11
Gear S MEDIUM 6.5
CVE-2021-25406

Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device inf…

Fix: 2.2.05.20122441+
Fix from $1,600 2021-06-11
Xebialabs Xl Deploy MEDIUM 6.5
CVE-2021-21664

An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to …

Fix: after 10.0.1
Fix from $1,600 2021-06-10
Chrome MEDIUM 6.5
CVE-2021-30533 KEVEPSS 17%

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions vi…

Fix: 91.0.4472.77+
Fix from $1,600 2021-06-07
Chrome MEDIUM 6.5
CVE-2021-30534

Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions v…

Fix: 91.0.4472.77+
Fix from $1,600 2021-06-07
Chrome MEDIUM 5.4
CVE-2021-30539

Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content securit…

Fix: 91.0.4472.77+
Fix from $1,600 2021-06-07