Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Jinjava MEDIUM 6.5
CVE-2020-12668

Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse o…

Fix: 2.5.4+
Fix from $1,600 2021-02-19
Myconnection Server HIGH 7.5
CVE-2021-27509

In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code.

Fix: after 11.0b
Fix from $1,950 2021-02-19
Opencast MEDIUM 5.4
CVE-2021-21318

Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a …

Fix: 9.2+
Fix from $1,600 2021-02-18
Nedi CRITICAL 9.9
CVE-2021-26753

NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parame…

No fix yet
Fix from $2,300 2021-02-12
Openshift Container Platform HIGH 7.0
CVE-2021-20188

A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw c…

Fix: 1.7.0+
Fix from $1,950 2021-02-11
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27177EPSS 20%

An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the Ggpo…

No fix yet
Fix from $2,300 2021-02-10
Zcashd HIGH 7.5
CVE-2020-8806

Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid chain could be incorrectly rej…

Fix: 2.1.1+
Fix from $1,950 2021-02-05
Ac2100 Firmware MEDIUM 6.5
CVE-2020-27873

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 rout…

Fix: 1.2.0.76+
Fix from $1,600 2021-02-04
Teamcity MEDIUM 5.3
CVE-2021-25777

In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.

Fix: 2020.2.1+
Fix from $1,600 2021-02-03
Krb5 Appl MEDIUM 5.9
CVE-2019-25017

An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which fi…

Fix: after 1.0.3
Fix from $1,600 2021-02-02
Avideo HIGH 8.8
CVE-2021-21286

AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform before version 10.2 there is a…

Fix: 10.2+
Fix from $1,950 2021-02-01
Polr CRITICAL 9.3
CVE-2021-21276EPSS 7%

Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to sit…

Fix: 2.3.0+
Fix from $2,300 2021-02-01
Hide Thread Content HIGH 7.5
CVE-2021-3337EPSS 11%

The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on rep…

No fix yet
Fix from $1,950 2021-01-28
Keycloak MEDIUM 5.4
CVE-2020-1725

A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycl…

Fix: 13.0.0+
Fix from $1,600 2021-01-28
Photo Studio 2021 HIGH 7.8
CVE-2021-26025

PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x000000000000…

Mitigation only
Fix from $1,950 2021-01-26
Photo Studio 2021 HIGH 7.8
CVE-2021-26026

PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c…

Mitigation only
Fix from $1,950 2021-01-26
Hadoop HIGH 8.8
CVE-2020-9492

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote UR…

Fix: after 3.2.1
Fix from $1,950 2021-01-26
Data Center Network Manager MEDIUM 6.3
CVE-2021-1269

Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attac…

Fix: 11.5+
Fix from $1,600 2021-01-20
Data Center Network Manager MEDIUM 6.5
CVE-2021-1270

Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attac…

Fix: 11.5+
Fix from $1,600 2021-01-20
Planning Analytics MEDIUM 5.3
CVE-2020-4873

IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.

Patch available
Fix from $1,600 2021-01-19
Magento HIGH 8.1
CVE-2021-21013

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR)…

Fix: after 2.4.1
Fix from $1,950 2021-01-13
Connected Mobile Experiences HIGH 8.8
CVE-2021-1144

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter t…

Mitigation only
Fix from $1,950 2021-01-13
Jenkins MEDIUM 5.3
CVE-2021-21609

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers…

Fix: after 2.274
Fix from $1,600 2021-01-13
Android HIGH 7.8
CVE-2021-0317

In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalat…

Patch available
Fix from $1,950 2021-01-11
Android HIGH 7.3
CVE-2021-0319

In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without approp…

Patch available
Fix from $1,950 2021-01-11
Antivrius HIGH 7.8
CVE-2018-8044

K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The compo…

Fix: 14.2.0001 / 16.0.0001+
Fix from $1,950 2021-01-11
Antivrius HIGH 7.8
CVE-2018-8724

K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is:…

Fix: 14.2.0001 / 16.0.0001+
Fix from $1,950 2021-01-11
Gpu Driver MEDIUM 5.5
CVE-2021-1054

NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in wh…

Fix: 392.63 / 427.11+
Fix from $1,600 2021-01-08
Xcloner HIGH 8.8
CVE-2020-35948EPSS 25%

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify a…

Fix: 4.2.13+
Fix from $1,950 2021-01-01
Rest\/json CRITICAL 9.8
CVE-2016-20001

The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security a…

Fix: after 7.x-1.5
Fix from $2,300 2021-01-01