Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Debian Linux HIGH 7.5
CVE-2020-3811

qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.

Patch available
Fix from $1,950 2020-05-26
Documents MEDIUM 5.3
CVE-2019-20801

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin request…

Fix: 6.9.7+
Fix from $1,600 2020-05-18
Android HIGH 7.8
CVE-2020-0097

In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead t…

Patch available
Fix from $1,950 2020-05-14
Aptare MEDIUM 6.3
CVE-2020-12875

Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitiv…

Fix: 10.4+
Fix from $1,600 2020-05-14
Aptare HIGH 7.5
CVE-2020-12876

Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows …

Fix: 10.4+
Fix from $1,950 2020-05-14
Pan Os HIGH 8.8
CVE-2020-1998

An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions …

Fix: 7.1.26 / 8.1.13+
Fix from $1,950 2020-05-13
Active Resource HIGH 7.5
CVE-2020-8151

There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to acce…

Fix: 5.1.1+
Fix from $1,950 2020-05-12
Ubuntu Linux HIGH 8.8
CVE-2020-12691

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a pro…

Fix: 15.0.1+
Fix from $1,950 2020-05-07
MongoDB MEDIUM 5.3
CVE-2020-7921

Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credent…

Fix: 3.6.18 / 4.0.15+
Fix from $1,600 2020-05-06
Os Recovery Image For Microsoft Windows 10 HIGH 7.8
CVE-2020-5343

Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vuln…

Fix: 2019-12-20+
Fix from $1,950 2020-05-04
Teampass HIGH 7.5
CVE-2020-12477

The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For…

No fix yet
Fix from $1,950 2020-04-29
Vesta Control Panel HIGH 8.8
CVE-2020-10786

A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron…

Fix: after 0.9.8-26
Fix from $1,950 2020-04-21
Nexus Repository Manager 3 HIGH 8.8
CVE-2020-11753

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to …

Patch available
Fix from $1,950 2020-04-20
Prestashop MEDIUM 6.5
CVE-2020-5287

In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Prestashop MEDIUM 6.5
CVE-2020-5288

"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5.

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Prestashop MEDIUM 6.5
CVE-2020-5293

In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific pr…

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Prestashop MEDIUM 6.5
CVE-2020-5279

In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-d…

Fix: 1.7.6.5+
Fix from $1,600 2020-04-20
Windows 10 HIGH 8.8
CVE-2020-0981

A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the v…

Patch available
Fix from $1,950 2020-04-15
Provide Ftp Server HIGH 8.8
CVE-2020-11707

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result,…

Fix: after 13.1
Fix from $1,950 2020-04-12
Android HIGH 7.5
CVE-2018-21039

An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka Quic…

Mitigation only
Fix from $1,950 2020-04-08
Android HIGH 8.4
CVE-2018-21082

An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use scr…

Mitigation only
Fix from $1,950 2020-04-08
Ejbca MEDIUM 5.3
CVE-2020-11628

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, AC…

Fix: 6.15.2.6 / 7.3.1.2+
Fix from $1,600 2020-04-08
Revive Adserver MEDIUM 6.8
CVE-2020-8142

A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like…

Fix: 5.0.5+
Fix from $1,600 2020-04-03
Symfony HIGH 8.1
CVE-2020-5275

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and s…

Fix: 4.4.7 / 5.0.7+
Fix from $1,950 2020-03-30
Ehrd MEDIUM 6.5
CVE-2020-10510

Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a …

Mitigation only
Fix from $1,600 2020-03-27
Mate 20 Firmware MEDIUM 6.6
CVE-2020-1796

There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successf…

Fix: after 10.0.0.203
Fix from $1,600 2020-03-20
Manageengine Remote Access Plus HIGH 8.8
CVE-2019-11361

Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full ap…

Mitigation only
Fix from $1,950 2020-03-19
Joomla\! HIGH 8.8
CVE-2020-10239

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

Fix: 3.9.16+
Fix from $1,950 2020-03-16
Wagtail 2fa HIGH 8.5
CVE-2020-5240

In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does …

Fix: 1.4.1+
Fix from $1,950 2020-03-13
Mediawiki CRITICAL 9.8
CVE-2020-10534

In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-…

Fix: after 1.34.0
Fix from $2,300 2020-03-12