Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Rest\/json CRITICAL 9.8
CVE-2016-20002

The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's securit…

Fix: after 7.x-1.5
Fix from $2,300 2021-01-01
Rest\/json CRITICAL 9.8
CVE-2016-20004

The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security …

Fix: after 7.x-1.5
Fix from $2,300 2021-01-01
Rest\/json CRITICAL 9.8
CVE-2016-20005

The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's secu…

Fix: after 7.x-1.5
Fix from $2,300 2021-01-01
Zammad MEDIUM 6.5
CVE-2020-26029

An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization…

Fix: 3.4.1+
Fix from $1,600 2020-12-28
Symphony \+ Historian HIGH 8.8
CVE-2020-24674

In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users c…

Mitigation only
Fix from $1,950 2020-12-22
Automation Workstream Services MEDIUM 5.4
CVE-2020-4794

IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6…

Patch available
Fix from $1,600 2020-12-21
Android HIGH 7.8
CVE-2020-0479

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malic…

Patch available
Fix from $1,950 2020-12-15
Oauthenticator MEDIUM 6.3
CVE-2020-26250

OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2…

Fix: 0.12.2+
Fix from $1,600 2020-12-01
October HIGH 7.5
CVE-2020-15246

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1…

Fix: 1.0.469+
Fix from $1,950 2020-11-23
Consul MEDIUM 6.5
CVE-2020-28053

HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key conf…

Fix: 1.6.10 / 1.7.10+
Fix from $1,600 2020-11-23
Ecostruxure Control Expert HIGH 7.8
CVE-2020-28211

A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cau…

Patch available
Fix from $1,950 2020-11-19
Moodle HIGH 7.5
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that …

Fix: after 3.9.2
Fix from $1,950 2020-11-19
Moodle MEDIUM 5.3
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneousl…

Fix: after 3.9.2
Fix from $1,600 2020-11-19
Social MEDIUM 5.3
CVE-2020-8278

Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.

No fix yet
Fix from $1,600 2020-11-19
Spree MEDIUM 6.5
CVE-2020-26223

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12…

Fix: 3.7.13 / 4.0.5+
Fix from $1,600 2020-11-13
Sd820 Firmware MEDIUM 5.5
CVE-2020-11209

Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855…

No fix yet
Fix from $1,600 2020-11-12
Windows Server 2012 MEDIUM 6.6
CVE-2020-17049EPSS 14%

A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via…

Fix: 4.13.13 / 4.14.9+
Fix from $1,600 2020-11-11
Advanced Cluster Management For Kubernetes MEDIUM 6.5
CVE-2020-25655

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f…

Mitigation only
Fix from $1,600 2020-11-09
Magento MEDIUM 6.5
CVE-2020-24401

Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisio…

Fix: 2.3.5+
Fix from $1,600 2020-11-09
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2020-3592

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…

Fix: after 20.1.12
Fix from $1,600 2020-11-06
Sd Wan HIGH 7.8
CVE-2020-3600

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste…

Fix: 20.1.2 / 20.3.2+
Fix from $1,950 2020-11-06
Red Discord Bot HIGH 7.5
CVE-2020-15278

Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit allows Discord users with a hig…

Fix: 3.4.1+
Fix from $1,950 2020-10-28
Safari MEDIUM 5.3
CVE-2020-3852

A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrectly ignored when determining …

Fix: 13.0.5+
Fix from $1,600 2020-10-27
Secure Firewall Threat Defense MEDIUM 6.5
CVE-2020-3578

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c…

Fix: 6.3.0.6 / 6.4.0.10+
Fix from $1,600 2020-10-21
Bigbluebutton MEDIUM 5.3
CVE-2020-27609

BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data stora…

Fix: after 2.2.28
Fix from $1,600 2020-10-21
Banking Services MEDIUM 6.5
CVE-2020-6362

SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with othe…

Mitigation only
Fix from $1,600 2020-10-20
Azure Functions MEDIUM 5.3
CVE-2020-16904

<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfull…

Patch available
Fix from $1,600 2020-10-16
Es7510 Xt Firmware HIGH 7.2
CVE-2020-12503EPSS 23%

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

No fix yet
Fix from $1,950 2020-10-15
Aptare CRITICAL 9.8
CVE-2020-27156

Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for remote code execution by an u…

Fix: 10.5+
Fix from $2,300 2020-10-15
Solr CRITICAL 9.8
CVE-2020-13957EPSS 79%

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote co…

Fix: after 8.6.2
Fix from $2,300 2020-10-13