Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Matrix Authorization Strategy MEDIUM 6.5
CVE-2021-21623

An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested …

Fix: after 2.6.5
Fix from $1,600 2021-03-18
Webrtc MEDIUM 5.3
CVE-2021-28681

Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to fail…

Fix: 3.0.15+
Fix from $1,600 2021-03-18
Portainer CRITICAL 9.8
CVE-2020-24264

Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bin…

Fix: after 1.24.1
Fix from $2,300 2021-03-16
Moodle MEDIUM 5.3
CVE-2021-20281

It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5,…

Fix: 3.5.17 / 3.8.8+
Fix from $1,600 2021-03-15
Moodle MEDIUM 5.3
CVE-2021-20282

When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10…

Fix: 3.5.17 / 3.8.8+
Fix from $1,600 2021-03-15
Sinema Remote Connect Server HIGH 8.8
CVE-2020-25240

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the …

Fix: 3.0+
Fix from $1,950 2021-03-15
Sinema Remote Connect Server HIGH 8.8
CVE-2020-25239

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special…

Fix: 3.0+
Fix from $1,950 2021-03-15
Certificate System HIGH 8.1
CVE-2021-20179

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …

Fix: 10.5.0 / 10.8.0+
Fix from $1,950 2021-03-15
Tiny Tiny Rss HIGH 7.5
CVE-2021-28373

The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE…

Fix: 2021-03-12+
Fix from $1,950 2021-03-13
Manageengine Servicedesk Plus HIGH 8.8
CVE-2020-35682EPSS 7%

Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

Fix: 11.1+
Fix from $1,950 2021-03-13
Fedora HIGH 8.1
CVE-2021-21367

Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When t…

Fix: 2.3.5+
Fix from $1,950 2021-03-12
Android MEDIUM 5.5
CVE-2021-0382

In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to l…

Patch available
Fix from $1,600 2021-03-10
Android HIGH 7.8
CVE-2021-0376

In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due to a permissions bypass. This…

Mitigation only
Fix from $1,950 2021-03-10
Chrome MEDIUM 6.5
CVE-2021-21182

Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer proc…

Fix: 89.0.4389.72+
Fix from $1,600 2021-03-09
Netweaver HIGH 8.8
CVE-2021-21481

The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This…

Mitigation only
Fix from $1,950 2021-03-09
Hana CRITICAL 9.8
CVE-2021-21484

LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bi…

Mitigation only
Fix from $2,300 2021-03-09
Minio MEDIUM 6.5
CVE-2021-21362

MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before versio…

Fix: 2021-03-04t00-53-13z+
Fix from $1,600 2021-03-08
Sitemanager Firmware HIGH 7.2
CVE-2020-29020

Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the c…

Fix: 9.4.620527004+
Fix from $1,950 2021-03-05
Spire MEDIUM 6.8
CVE-2021-27099

In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the age…

Fix: 0.8.5 / 0.9.4+
Fix from $1,600 2021-03-05
Zxhn H196q Firmware MEDIUM 5.7
CVE-2021-21725

A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directo…

Mitigation only
Fix from $1,600 2021-03-05
Airwave HIGH 7.1
CVE-2021-26964

A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnera…

Fix: 8.2.12.0+
Fix from $1,950 2021-03-05
Joomla\! MEDIUM 5.3
CVE-2021-26027

An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.

Fix: 3.9.25+
Fix from $1,600 2021-03-04
Data Science Studio MEDIUM 5.4
CVE-2021-27225

In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and …

Fix: 8.0.6+
Fix from $1,600 2021-03-01
Diskstation Manager MEDIUM 6.7
CVE-2021-26563

Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute ar…

Fix: 6.2.4-25553+
Fix from $1,600 2021-02-26
Spring Cloud Netflix Zuul MEDIUM 5.3
CVE-2021-22113

Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sen…

Fix: after 2.2.6
Fix from $1,600 2021-02-23
Jinjava MEDIUM 6.5
CVE-2020-12668

Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse o…

Fix: 2.5.4+
Fix from $1,600 2021-02-19
Myconnection Server HIGH 7.5
CVE-2021-27509

In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code.

Fix: after 11.0b
Fix from $1,950 2021-02-19
Opencast MEDIUM 5.4
CVE-2021-21318

Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a …

Fix: 9.2+
Fix from $1,600 2021-02-18
Nedi CRITICAL 9.9
CVE-2021-26753

NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parame…

No fix yet
Fix from $2,300 2021-02-12
Openshift Container Platform HIGH 7.0
CVE-2021-20188

A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw c…

Fix: 1.7.0+
Fix from $1,950 2021-02-11