Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Telegram Desktop HIGH 7.8
CVE-2020-17448

Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use o…

Fix: after 2.1.13
Fix from $1,950 2020-08-11
Itop HIGH 7.5
CVE-2020-12780

A security misconfiguration exists in Combodo iTop, which can expose sensitive information.

Fix: 2.7.1+
Fix from $1,950 2020-08-10
Data Center Network Manager HIGH 8.8
CVE-2020-3386

A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privile…

Fix: 11.4+
Fix from $1,950 2020-07-31
Sd Wan CRITICAL 9.9
CVE-2020-3374

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…

Fix: 18.4.5 / 19.2.2+
Fix from $2,300 2020-07-31
Openclinic Ga HIGH 8.8
CVE-2020-14486

An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which …

Mitigation only
Fix from $1,950 2020-07-29
Parse Server MEDIUM 6.5
CVE-2020-15126

In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User …

Fix: 4.3.0+
Fix from $1,600 2020-07-22
Kubespawner HIGH 8.1
CVE-2020-15110

In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default se…

Fix: 0.12+
Fix from $1,950 2020-07-17
Prime License Manager CRITICAL 9.8
CVE-2020-3140

A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain…

Fix: after 11.5
Fix from $2,300 2020-07-16
Rv110w Firmware MEDIUM 5.9
CVE-2020-3150

A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote…

Fix: 1.2.2.8 / 1.3.1.7+
Fix from $1,600 2020-07-16
Gitlab Authentication HIGH 8.8
CVE-2020-2228

Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulner…

Fix: after 1.5
Fix from $1,950 2020-07-15
Oauth Client Library For Java CRITICAL 9.1
CVE-2020-7692

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by…

Fix: 1.31.0+
Fix from $2,300 2020-07-09
Typo3 Forum MEDIUM 5.3
CVE-2020-15513

The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.

Fix: 1.2.1+
Fix from $1,600 2020-07-07
Emc Powerstore 1000 Firmware HIGH 7.5
CVE-2020-5372

Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthent…

Fix: 1.0.1.0.5.002+
Fix from $1,950 2020-07-06
Recursor MEDIUM 5.3
CVE-2020-14196

In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enfo…

Fix: after 4.3.1
Fix from $1,600 2020-07-01
Express Jwt CRITICAL 9.1
CVE-2020-15084

In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When al…

Fix: after 5.3.3
Fix from $2,300 2020-06-30
Stealth CRITICAL 9.8
CVE-2020-12053

In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized withou…

Fix: 5.0.026+
Fix from $2,300 2020-06-22
GitLab HIGH 8.8
CVE-2020-13263

An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unautho…

Fix: 12.9.8 / 12.10.7+
Fix from $1,950 2020-06-19
GitLab MEDIUM 6.5
CVE-2020-13277

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

Fix: after 13.0.5
Fix from $1,600 2020-06-19
Unified Ip Phone 6901 Firmware MEDIUM 5.3
CVE-2020-3360

A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sens…

Fix: after 12.8
Fix from $1,600 2020-06-18
Ios Xr MEDIUM 5.3
CVE-2020-3364

A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could all…

Mitigation only
Fix from $1,600 2020-06-18
Zammad MEDIUM 6.5
CVE-2020-14214

Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can registe…

Fix: 3.3.1+
Fix from $1,600 2020-06-16
Mtn6501 0001 Firmware MEDIUM 6.5
CVE-2020-7499

A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) …

Fix: 1.4.2+
Fix from $1,600 2020-06-16
Android HIGH 7.8
CVE-2020-0115

In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a…

Patch available
Fix from $1,950 2020-06-10
Android HIGH 7.5
CVE-2020-13834

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict …

Mitigation only
Fix from $1,950 2020-06-04
Application Policy Infrastructure Controller MEDIUM 5.5
CVE-2020-3335

A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive informa…

Fix: 1.1.2.20+
Fix from $1,600 2020-06-03
Ios Xe CRITICAL 9.8
CVE-2020-3227

A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenti…

Mitigation only
Fix from $2,300 2020-06-03
Ios Xe HIGH 8.8
CVE-2020-3229EPSS 5%

A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remo…

Patch available
Fix from $1,950 2020-06-03
Service Management Automation CRITICAL 9.8
CVE-2020-11844

Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions …

Mitigation only
Fix from $2,300 2020-05-29
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4249

IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to …

Patch available
Fix from $1,600 2020-05-28
Firefox HIGH 7.5
CVE-2020-12391

Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that …

Fix: 76.0+
Fix from $1,950 2020-05-26