Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2021-24742 The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action bec… Logo Slider And Showcase 1.3.37+ Fix from $1,6002021-11-01 MEDIUM 5.3 CVE-2021-24757 The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unau… Stylish Price List 6.9.0+ Fix from $1,6002021-11-01 MEDIUM 6.5 CVE-2021-24770 The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authentic… Stylish Price List 6.9.1+ Fix from $1,6002021-11-01 HIGH 8.8 CVE-2021-24717 The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, d… Automatorwp 1.7.6+ Fix from $1,9502021-11-01 HIGH 7.2 CVE-2021-41189 DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up t… Dspace Patch available Fix from $1,9502021-10-29 HIGH 8.8 CVE-2021-39321 Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action… Sassy Social Share Patch available Fix from $1,9502021-10-21 MEDIUM 6.5 CVE-2021-38345 The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in… Brizy Page Builder 1.0.1.126+ Fix from $1,6002021-10-14 MEDIUM 5.4 CVE-2021-20803 Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the dat… Remote Service Manager Mitigation only Fix from $1,6002021-10-13 MEDIUM 5.3 CVE-2021-40456 Windows AD FS Security Feature Bypass Vulnerability Windows Server Patch available Fix from $1,6002021-10-13 MEDIUM 5.3 CVE-2021-42137 An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requirement for viewing a list of ticke… Zammad 5.0.1+ Fix from $1,6002021-10-11 CRITICAL 9.8 CVE-2021-41093 Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by … Wire 3.86+ Fix from $2,3002021-10-04 MEDIUM 6.5 CVE-2021-24652 The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform som… Postx Gutenberg Blocks For Post Grid 2.4.10+ Fix from $1,6002021-09-27 MEDIUM 6.5 CVE-2021-40654 An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the /… Dir 615 Firmware No fix yet Fix from $1,6002021-09-24 HIGH 7.5 CVE-2021-40655 KEVEPSS 87% An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a po… Dir 605l Firmware Mitigation only Fix from $1,9502021-09-24 MEDIUM 6.5 CVE-2021-36749EPSS 81% In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate… Druid 0.22.0+ Fix from $1,6002021-09-24 MEDIUM 6.5 CVE-2021-34647 The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/R… Ninja Forms after 3.5.7 Fix from $1,6002021-09-22 HIGH 8.8 CVE-2020-19551 Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong. Wuzhicms after 4.1.0 Fix from $1,9502021-09-21 HIGH 7.5 CVE-2021-41082 Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user… Discourse 2021-09-14+ Fix from $1,9502021-09-20 MEDIUM 6.8 CVE-2020-16630 TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just W… 15.4 Stack No fix yet Fix from $1,6002021-09-20 MEDIUM 5.3 CVE-2019-16651 An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechani… Super Hub 3 Firmware No fix yet Fix from $1,6002021-09-20 HIGH 7.5 CVE-2021-40639 Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.confi… Jfinal Cms No fix yet Fix from $1,9502021-09-15 CRITICAL 9.8 CVE-2020-21124 UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page. Ureport No fix yet Fix from $2,3002021-09-15 HIGH 8.6 CVE-2021-39206 Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-202… Envoy 0.14.8 / 1.16.5+ Fix from $1,9502021-09-09 CRITICAL 9.8 CVE-2021-28911 BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. devi… Eibport Firmware 3.9.1+ Fix from $2,3002021-09-09 MEDIUM 6.5 CVE-2021-28567 Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in … Magento after 2.4.2 Fix from $1,6002021-09-08 HIGH 7.8 CVE-2021-35526 Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensi… Sdm600 Firmware 1.2.14002.257+ Fix from $1,9502021-09-08 HIGH 7.5 CVE-2020-19765 An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a reentrancy attack. Proofofdiligencetoken No fix yet Fix from $1,9502021-09-07 MEDIUM 5.3 CVE-2021-35949 The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list meta… Owncloud 10.8.0+ Fix from $1,6002021-09-07 MEDIUM 6.5 CVE-2021-38312 The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints regis… Gutenberg Template Library \& Redux Framework after 4.2.11 Fix from $1,6002021-09-02 MEDIUM 5.3 CVE-2021-39119 Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even afte… Data Center 8.19.0+ Fix from $1,6002021-09-01