Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Staros HIGH 8.8
CVE-2021-1539

Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to byp…

Fix: 21.16.9 / 21.17.10+
Fix from $1,950 2021-06-04
Staros HIGH 7.2
CVE-2021-1540

Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to byp…

Fix: 21.16.9 / 21.17.10+
Fix from $1,950 2021-06-04
Foreman MEDIUM 5.4
CVE-2021-3469

Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the …

Fix: 2.3.4+
Fix from $1,600 2021-06-03
Ovn Kubernetes MEDIUM 5.6
CVE-2021-3499

A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules wh…

Fix: after 0.3.0
Fix from $1,600 2021-06-02
Deno CRITICAL 9.8
CVE-2021-32619

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imp…

Fix: 1.10.2+
Fix from $2,300 2021-05-28
Xwiki HIGH 8.8
CVE-2021-32620

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 1…

Fix: 11.10.13 / 12.6.7+
Fix from $1,950 2021-05-28
FreeBSD HIGH 7.5
CVE-2021-29628

In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call tri…

No fix yet
Fix from $1,950 2021-05-28
Fedora MEDIUM 5.4
CVE-2020-26555

Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD…

Fix: after 5.2
Fix from $1,600 2021-05-24
Mesh Profile HIGH 8.8
CVE-2020-26559

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to id…

Mitigation only
Fix from $1,950 2021-05-24
Mesh Profile HIGH 8.1
CVE-2020-26560

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Pro…

Mitigation only
Fix from $1,950 2021-05-24
Windows 10 HIGH 8.8
CVE-2021-21552

Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicio…

Fix: after 2019
Fix from $1,950 2021-05-21
Couchbase Server MEDIUM 6.5
CVE-2021-31158

In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permiss…

Fix: 6.6.2+
Fix from $1,600 2021-05-19
Qradar User Behavior Analytics MEDIUM 5.3
CVE-2021-20429

IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force…

Fix: 4.1.1+
Fix from $1,600 2021-05-14
Redirection For Contact Form 7 HIGH 7.5
CVE-2021-24278EPSS 7%

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a val…

Fix: 2.3.4+
Fix from $1,950 2021-05-14
Redirection For Contact Form 7 MEDIUM 6.5
CVE-2021-24279

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX actio…

Fix: 2.3.4+
Fix from $1,600 2021-05-14
Redirection For Contact Form 7 MEDIUM 6.3
CVE-2021-24282

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions…

Fix: 2.3.4+
Fix from $1,600 2021-05-14
Bitcoin MEDIUM 6.5
CVE-2021-31876

Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to tri…

Fix: after 0.21.1
Fix from $1,600 2021-05-13
Smart Proxy Shell Hooks MEDIUM 6.1
CVE-2021-3457

An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions tha…

Fix: 0.9.2+
Fix from $1,600 2021-05-12
Data Center MEDIUM 5.3
CVE-2020-36289EPSS 99%

Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili…

Fix: 8.5.13 / 8.13.5+
Fix from $1,600 2021-05-12
Windows 10 HIGH 7.8
CVE-2021-31165

Windows Container Manager Service Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-05-11
Cloud Pak For Security CRITICAL 9.1
CVE-2021-20538

IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have acce…

Mitigation only
Fix from $2,300 2021-05-10
Big Ip Access Policy Manager HIGH 7.2
CVE-2021-23015

On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an aut…

Fix: 13.1.4 / 14.1.4+
Fix from $1,950 2021-05-10
Linux Kernel MEDIUM 5.5
CVE-2021-31829

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-chan…

Fix: after 5.12.1
Fix from $1,600 2021-05-06
GitLab HIGH 7.5
CVE-2021-22209

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which…

Fix: 13.9.7 / 13.10.4+
Fix from $1,950 2021-05-06
Wpbakery Page Builder Clipboard MEDIUM 6.5
CVE-2021-24244

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allo…

Fix: 4.5.8+
Fix from $1,600 2021-05-06
Amp MEDIUM 6.5
CVE-2021-31926

AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firew…

Fix: 2.1.1.2+
Fix from $1,600 2021-04-30
Virtual Gpu Manager HIGH 7.1
CVE-2021-1086

NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it allows guests to control unauthorized resources, which …

Fix: 8.7 / 11.4+
Fix from $1,950 2021-04-29
Mydomoathome HIGH 7.5
CVE-2020-21990

Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper acc…

No fix yet
Fix from $1,950 2021-04-29
Tapestry HIGH 7.5
CVE-2021-30638EPSS 7%

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia…

Fix: 5.6.4 / 5.7.2+
Fix from $1,950 2021-04-27
Mediawiki MEDIUM 6.5
CVE-2021-31548

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blocked or was unsuccessfully bl…

Fix: after 1.35.2
Fix from $1,600 2021-04-22