Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Channelmgnt MEDIUM 6.5
CVE-2020-15251

In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is a…

Fix: 1.0.3+
Fix from $1,600 2020-10-13
Identity Services Engine HIGH 7.7
CVE-2020-3467

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to modify…

Fix: after 2.4
Fix from $1,950 2020-10-08
GitLab HIGH 7.5
CVE-2020-13334

In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentia…

Fix: 13.2.10 / 13.3.7+
Fix from $1,950 2020-10-07
Maildepot HIGH 8.8
CVE-2019-19200

REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.

No fix yet
Fix from $1,950 2020-10-06
Firefox MEDIUM 6.5
CVE-2020-15664

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object w…

Fix: 68.12 / 78.2+
Fix from $1,600 2020-10-01
GitLab HIGH 7.2
CVE-2020-13322

A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete…

Fix: 12.10.13 / 13.0.8+
Fix from $1,950 2020-09-30
Fedora HIGH 7.5
CVE-2020-26121

An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protect…

Fix: 1.34.4+
Fix from $1,950 2020-09-27
Fedora HIGH 7.5
CVE-2020-25869

An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use…

Fix: 1.31.10 / 1.34.4+
Fix from $1,950 2020-09-27
Ios Xe HIGH 8.1
CVE-2020-3474

Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privil…

Mitigation only
Fix from $1,950 2020-09-24
iOS MEDIUM 5.5
CVE-2020-3477

A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from t…

Mitigation only
Fix from $1,600 2020-09-24
Ios Xe HIGH 7.8
CVE-2020-3404

A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell a…

Mitigation only
Fix from $1,950 2020-09-24
Data Risk Manager HIGH 8.8
CVE-2020-4621

IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization …

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Private Internet Access Vpn Client HIGH 7.5
CVE-2020-15590

A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill swi…

Fix: 2.4.0+
Fix from $1,950 2020-09-14
GitLab MEDIUM 6.5
CVE-2020-13284

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

Fix: 13.1.10 / 13.2.8+
Fix from $1,600 2020-09-14
GitLab CRITICAL 10.0
CVE-2020-13300

GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati…

Fix: 13.3.4+
Fix from $2,300 2020-09-14
The Update Framework HIGH 8.2
CVE-2020-15163

Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file w…

Fix: 0.12.0+
Fix from $1,950 2020-09-09
Bank Analyzer MEDIUM 6.5
CVE-2020-6311

Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly per…

Mitigation only
Fix from $1,600 2020-09-09
Ios Xr HIGH 7.8
CVE-2020-3473

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to el…

Fix: 6.5.29 / 6.6.3+
Fix from $1,950 2020-09-04
Ios Xr HIGH 8.4
CVE-2020-3530

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute …

Fix: 7.1.2+
Fix from $1,950 2020-09-04
Laravel HIGH 7.5
CVE-2020-24941

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests wi…

Fix: 6.18.35 / 7.24.0+
Fix from $1,950 2020-09-04
Android CRITICAL 9.8
CVE-2020-25055

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unp…

Mitigation only
Fix from $2,300 2020-08-31
Openzfs HIGH 7.8
CVE-2020-24716

OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.

Fix: after 0.8.4
Fix from $1,950 2020-08-27
Data Center Network Manager MEDIUM 6.3
CVE-2020-3522

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attac…

Fix: 11.4+
Fix from $1,600 2020-08-26
Zrlog MEDIUM 5.7
CVE-2020-19005

zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup …

Patch available
Fix from $1,600 2020-08-25
Acrobat Dc MEDIUM 5.5
CVE-2020-9712

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a secur…

Fix: after 20.009.20074
Fix from $1,600 2020-08-19
Webex Meetings Online MEDIUM 5.0
CVE-2020-3472

A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to acces…

Fix: 40.7.0+
Fix from $1,600 2020-08-17
Xenmobile Server CRITICAL 9.8
CVE-2020-8212

Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and …

Fix: after 10.9.0
Fix from $2,300 2020-08-17
Automation License Manager HIGH 7.8
CVE-2020-7583

A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The applica…

Fix: 6.0.8+
Fix from $1,950 2020-08-14
Data Loss Prevention MEDIUM 6.3
CVE-2020-7300

Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to chan…

Fix: 11.3.28 / 11.4.200+
Fix from $1,600 2020-08-12
Pipeline Maven Integration MEDIUM 6.5
CVE-2020-2233

A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credenti…

Fix: after 3.8.2
Fix from $1,600 2020-08-12