Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Mediawiki MEDIUM 5.4
CVE-2021-31552

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts…

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Mediawiki MEDIUM 5.4
CVE-2021-31554

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically cre…

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Restructuredtext CRITICAL 9.8
CVE-2021-28793

vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folder could execute arbitrary bin…

Fix: 147.0.0+
Fix from $2,300 2021-04-20
Ubuntu Linux HIGH 7.8
CVE-2021-3493 KEVEPSS 49%

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files …

Fix: 18.04 / 20.04+
Fix from $1,950 2021-04-17
A12n Server MEDIUM 6.5
CVE-2021-29452

a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0…

Fix: 0.18.2+
Fix from $1,600 2021-04-16
Messaging Eclipse Mosquitto Distribution Core HIGH 7.8
CVE-2021-28825

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Mes…

Fix: after 1.3.0
Fix from $1,950 2021-04-14
Messaging Eclipse Mosquitto Distribution Bridge HIGH 7.8
CVE-2021-28826

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO M…

Fix: after 1.3.0
Fix from $1,950 2021-04-14
Scratchoauth2 MEDIUM 6.8
CVE-2021-29437

ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and mod…

Fix: 2021-04-13+
Fix from $1,600 2021-04-13
Grav Admin HIGH 7.2
CVE-2021-29439

The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.logi…

Fix: 1.10.11+
Fix from $1,950 2021-04-13
Windows 10 HIGH 7.8
CVE-2021-27086

Windows Services and Controller App Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-04-13
Solr CRITICAL 9.1
CVE-2021-29943EPSS 5%

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests usi…

Fix: 8.8.2+
Fix from $2,300 2021-04-13
Lispbx HIGH 7.5
CVE-2019-15059

In Liberty lisPBX 2.0-4, configuration backup files can be retrieved remotely from /backup/lispbx-CONF-YYYY-MM-DD.tar or /backup/lispbx-CDR-YYYY-MM-D…

Mitigation only
Fix from $1,950 2021-04-12
Monitorr CRITICAL 9.8
CVE-2020-28872

An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to crea…

No fix yet
Fix from $2,300 2021-04-12
Android HIGH 8.8
CVE-2021-25356

An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary a…

No fix yet
Fix from $1,950 2021-04-09
Data Center MEDIUM 5.3
CVE-2020-36287EPSS 9%

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from ve…

Fix: 8.13.5 / 8.15.1+
Fix from $1,600 2021-04-09
Miui MEDIUM 5.5
CVE-2020-14106

The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.…

Fix: 2021.01.26+
Fix from $1,600 2021-04-08
macOS MEDIUM 6.3
CVE-2020-27901

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update…

Fix: 11.0.1 / 11.1.0+
Fix from $1,600 2021-04-02
Internet Security MEDIUM 5.5
CVE-2021-26718

KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.

Fix: 21.1+
Fix from $1,600 2021-04-01
Data Center MEDIUM 5.3
CVE-2020-36238

The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.…

Fix: 8.5.13 / 8.13.5+
Fix from $1,600 2021-04-01
Gistpad MEDIUM 5.3
CVE-2021-29642

GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of GitHub access tokens.

Fix: 0.2.7+
Fix from $1,600 2021-03-30
Wireless N Wifi Repeater Firmware HIGH 7.5
CVE-2021-28936

The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET …

No fix yet
Fix from $1,950 2021-03-29
Buddypress HIGH 8.8
CVE-2021-21389EPSS 14%

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-pr…

Fix: 7.2.1+
Fix from $1,950 2021-03-26
Oauth2 Proxy MEDIUM 5.5
CVE-2021-21411

OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group…

Fix: 7.1.0+
Fix from $1,600 2021-03-26
Vision Pro MEDIUM 5.9
CVE-2021-27195

Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.

Fix: after 9.7.1
Fix from $1,600 2021-03-25
Enterprise Message Service HIGH 7.8
CVE-2021-28821

The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, a…

Fix: after 8.5.1
Fix from $1,950 2021-03-23
Eftl HIGH 7.8
CVE-2021-28823

The Windows Installation component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterpri…

Fix: 6.6.0+
Fix from $1,950 2021-03-23
Activespaces HIGH 8.8
CVE-2021-28824

The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO…

Fix: 4.6.0+
Fix from $1,950 2021-03-23
Ftl HIGH 7.8
CVE-2021-28819

The Windows Installation component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise …

Fix: 6.6.0+
Fix from $1,950 2021-03-23
Grafana MEDIUM 6.5
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authent…

Fix: 7.4.5+
Fix from $1,600 2021-03-22
Swiftformat HIGH 7.8
CVE-2021-28791

The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a maliciou…

Fix: 1.3.7+
Fix from $1,950 2021-03-18