Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.8 CVE-2021-45339 Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process wh… Antivirus 20.4+ Fix from $1,9502021-12-27 HIGH 8.2 CVE-2021-23175 NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls f… Geforce Experience 3.24.0.126+ Fix from $1,9502021-12-23 HIGH 8.8 CVE-2021-38016 Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via… Chrome 96.0.4664.45+ Fix from $1,9502021-12-23 HIGH 8.8 CVE-2021-38017 Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions … Chrome 96.0.4664.45+ Fix from $1,9502021-12-23 CRITICAL 9.8 CVE-2021-23803 This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When th… Latte 2.10.6+ Fix from $2,3002021-12-17 HIGH 8.8 CVE-2021-45102 An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may… Htcondor Mitigation only Fix from $1,9502021-12-16 HIGH 7.8 CVE-2021-0649 In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CO… Android Mitigation only Fix from $1,9502021-12-15 MEDIUM 6.5 CVE-2021-24872 The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validat… Get Custom Field Values 4.0+ Fix from $1,6002021-12-13 HIGH 8.8 CVE-2021-41805EPSS 35% HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default… Consul 1.8.17 / 1.9.11+ Fix from $1,9502021-12-12 HIGH 8.7 CVE-2021-29678 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access o… Db2 Mitigation only Fix from $1,9502021-12-09 CRITICAL 10.0 CVE-2021-38503 The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navig… Firefox 91.3 / 94.0+ Fix from $2,3002021-12-08 MEDIUM 5.3 CVE-2021-41013 An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Re… Fortiweb after 6.3.15 Fix from $1,6002021-12-08 HIGH 8.8 CVE-2021-42758 An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to … Fortiwlc after 8.5.5 Fix from $1,9502021-12-08 HIGH 7.5 CVE-2021-24917EPSS 72% The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a … Wps Hide Login 1.9.1+ Fix from $1,9502021-12-06 MEDIUM 5.4 CVE-2021-24842 The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private… Bulk Datetime Change 1.12+ Fix from $1,6002021-11-29 MEDIUM 5.3 CVE-2021-43560 A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks… Moodle 3.9.11 / 3.10.8+ Fix from $1,6002021-11-22 HIGH 8.8 CVE-2021-22966 Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulk… Concrete Cms 8.5.7+ Fix from $1,9502021-11-19 MEDIUM 6.8 CVE-2021-39234 In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blo… Ozone 1.2.0+ Fix from $1,6002021-11-19 HIGH 7.2 CVE-2021-41244 Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enable… Grafana 8.2.4+ Fix from $1,9502021-11-15 HIGH 8.8 CVE-2021-3577EPSS 60% An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on … Halo\+ Camera Firmware 03.40.00 / 03.40.02+ Fix from $1,9502021-11-12 MEDIUM 5.3 CVE-2021-1903 Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snap… Aqt1000 Firmware Mitigation only Fix from $1,6002021-11-12 HIGH 7.1 CVE-2021-20119 The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrato… Arris Surfboard Sb8200 Firmware No fix yet Fix from $1,9502021-11-09 MEDIUM 6.5 CVE-2021-42025 A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions… Mendix 8.18.13 / 9.6.2+ Fix from $1,6002021-11-09 MEDIUM 6.5 CVE-2021-24783 The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contr… Post Expirator 2.6.0+ Fix from $1,6002021-11-08 MEDIUM 6.5 CVE-2021-24788 The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a res… Batch Cat after 0.3 Fix from $1,6002021-11-08 MEDIUM 6.5 CVE-2021-22051 Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. User… Spring Cloud Gateway 2.2.10 / 3.0.5+ Fix from $1,6002021-11-08 HIGH 8.8 CVE-2021-41230 Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflect… Pomerium 0.15.6+ Fix from $1,9502021-11-05 MEDIUM 5.5 CVE-2021-25506 Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service. Health 6.19.1.0001+ Fix from $1,6002021-11-05 CRITICAL 9.8 CVE-2021-21693 When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earli… Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 HIGH 8.2 CVE-2021-39341EPSS 22% The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorizatio… Optinmonster after 2.6.4 Fix from $1,9502021-11-01