Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2021-36039 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil… Adobe Commerce after 2.4.2 Fix from $1,6002021-09-01 MEDIUM 5.3 CVE-2021-34434 In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is … Fedora after 2.0.11 Fix from $1,6002021-08-30 MEDIUM 6.8 CVE-2021-28696 IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to… Fedora Mitigation only Fix from $1,6002021-08-27 MEDIUM 5.4 CVE-2021-22256 Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-25 HIGH 8.8 CVE-2021-22236 Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability i… GitLab 14.1.2+ Fix from $1,9502021-08-25 HIGH 7.5 CVE-2021-39156 Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a… Istio 1.9.8 / 1.10.3+ Fix from $1,9502021-08-24 HIGH 7.5 CVE-2021-39155 Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies a… Istio 1.9.8 / 1.10.4+ Fix from $1,9502021-08-24 HIGH 8.3 CVE-2021-32779 Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrect… Envoy 1.16.5 / 1.17.4+ Fix from $1,9502021-08-24 HIGH 8.3 CVE-2021-32777 Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz … Envoy 1.16.5 / 1.17.4+ Fix from $1,9502021-08-24 HIGH 8.6 CVE-2021-30975 This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed in macOS Monterey 12.1, Securi… Mac Os X 10.15.7 / 11.6.2+ Fix from $1,9502021-08-24 MEDIUM 5.5 CVE-2021-30987 An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.1. A device may be passively tracked via BS… macOS 12.1+ Fix from $1,6002021-08-24 MEDIUM 5.5 CVE-2021-30972 This issue was addressed with improved checks. This issue is fixed in Security Update 2022-001 Catalina, macOS Big Sur 11.6.3. A malicious applicatio… Mac Os X 10.15.7 / 11.6.3+ Fix from $1,6002021-08-24 CRITICAL 9.1 CVE-2021-30925 The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious appl… Ipados 8.0 / 11.6+ Fix from $2,3002021-08-24 CRITICAL 9.1 CVE-2021-30856 This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS… macOS 11.3+ Fix from $2,3002021-08-24 CRITICAL 9.1 CVE-2021-26040 An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command. Joomla\! Mitigation only Fix from $2,3002021-08-24 MEDIUM 5.4 CVE-2021-22253 Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments t… GitLab 13.12.9 / 14.0.7+ Fix from $1,6002021-08-23 MEDIUM 5.3 CVE-2021-37598 WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character. Wp Cerber 8.9.3+ Fix from $1,6002021-08-19 MEDIUM 6.5 CVE-2021-39138 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup use… Parse Server 4.5.1+ Fix from $1,6002021-08-19 HIGH 7.8 CVE-2021-0645 In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, all… Android Patch available Fix from $1,9502021-08-17 CRITICAL 9.9 CVE-2021-32829 ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networki… Rest Api 3.8.21 / 3.10.8+ Fix from $2,3002021-08-17 CRITICAL 9.8 CVE-2020-18701 Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the applicatio… Lin Cms Flask No fix yet Fix from $2,3002021-08-16 CRITICAL 10.0 CVE-2021-37705 OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow… Onefuzz 2.31.0+ Fix from $2,3002021-08-13 MEDIUM 5.3 CVE-2021-27793 ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fa… Fabric Operating System 8.2.3 / 9.0.1+ Fix from $1,6002021-08-12 HIGH 8.8 CVE-2020-25564 In SapphireIMS 5.0, it is possible to create local administrator on any client with credentials of a non-privileged user by directly accessing Remote… Sapphireims No fix yet Fix from $1,9502021-08-11 MEDIUM 5.3 CVE-2020-28397 A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl… Cpu 1504d Tf Firmware 2.9.2 / 4.0+ Fix from $1,6002021-08-10 HIGH 8.1 CVE-2021-38137 Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform act… Securewatch Managed Services Mitigation only Fix from $1,9502021-08-06 HIGH 7.2 CVE-2021-33335 Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows re… Digital Experience Platform 7.3.5+ Fix from $1,9502021-08-03 CRITICAL 9.8 CVE-2020-19301 A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condi… Vaethink No fix yet Fix from $2,3002021-08-03 CRITICAL 9.6 CVE-2021-30571 Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious e… Chrome 92.0.4515.107+ Fix from $2,3002021-08-03 CRITICAL 9.8 CVE-2021-22389 There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed. Emui Mitigation only Fix from $2,3002021-08-02