Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.7 CVE-2021-22521 A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all p… Zenworks Configuration Management 2020+ Fix from $1,6002021-07-30 MEDIUM 5.4 CVE-2021-28674 The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's pe… Orion Platform after 2020.2.5 Fix from $1,6002021-07-30 HIGH 8.8 CVE-2021-36230 HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the … Terraform 202107-1+ Fix from $1,9502021-07-20 MEDIUM 5.4 CVE-2021-36758 1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to per… Connect 1.2+ Fix from $1,6002021-07-16 HIGH 7.5 CVE-2020-12733 Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkad… Wifi Digital Microscope 3 Firmware No fix yet Fix from $1,9502021-07-15 MEDIUM 5.3 CVE-2021-33718 A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications using Mendix 8 (All versions… Mendix 7.23.22 / 8.18.7+ Fix from $1,6002021-07-13 MEDIUM 6.5 CVE-2021-22515 Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication ve… Netiq Advanced Authentication 6.3+ Fix from $1,6002021-07-12 HIGH 7.8 CVE-2021-26273 The Agent in NinjaRMM 5.0.909 has Incorrect Access Control. Ninjarmm No fix yet Fix from $1,9502021-07-07 MEDIUM 6.5 CVE-2021-24405EPSS 11% The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated … Easy Cookies Policy after 1.6.2 Fix from $1,6002021-07-06 HIGH 7.5 CVE-2021-35197 In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot accou… Debian Linux 1.31.15 / 1.35.3+ Fix from $1,9502021-07-02 HIGH 8.8 CVE-2021-36132 An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRig… Mediawiki after 1.36 Fix from $1,9502021-07-02 HIGH 8.8 CVE-2020-27362 An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configurat… Akkadian Provisioning Manager No fix yet Fix from $1,9502021-07-01 HIGH 8.8 CVE-2021-27661 Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an uninte… F4 Snc Firmware Mitigation only Fix from $1,9502021-07-01 HIGH 7.5 CVE-2021-22119EPSS 6% Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-S… Spring Security 5.2.11 / 5.3.10+ Fix from $1,9502021-06-29 HIGH 7.5 CVE-2021-32701 ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. When … Oathkeeper Patch available Fix from $1,9502021-06-22 HIGH 7.8 CVE-2010-2525 A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain a… Linux Kernel Patch available Fix from $1,9502021-06-22 HIGH 7.8 CVE-2021-0571 In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possi… Android Mitigation only Fix from $1,9502021-06-22 CRITICAL 9.8 CVE-2010-1435 Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subse… Joomla\! after 1.5.15 Fix from $2,3002021-06-21 MEDIUM 5.3 CVE-2021-24379 The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying th… Comments Like Dislike 1.1.4+ Fix from $1,6002021-06-21 HIGH 8.8 CVE-2020-20471 White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to … White Shark Systems No fix yet Fix from $1,9502021-06-21 CRITICAL 9.8 CVE-2020-20466 White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user. White Shark Systems No fix yet Fix from $2,3002021-06-21 HIGH 7.5 CVE-2021-26845 Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access … Esoms 6.0.4.2.2 / 6.1.4+ Fix from $1,9502021-06-14 HIGH 7.8 CVE-2021-0472 In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could l… Android Patch available Fix from $1,9502021-06-11 HIGH 7.1 CVE-2021-25410 Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an esc… Android No fix yet Fix from $1,9502021-06-11 HIGH 7.8 CVE-2021-25418 Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activit… Internet 14.0.1.62+ Fix from $1,9502021-06-11 MEDIUM 6.5 CVE-2021-25406 Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device inf… Gear S 2.2.05.20122441+ Fix from $1,6002021-06-11 MEDIUM 6.5 CVE-2021-21664 An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to … Xebialabs Xl Deploy after 10.0.1 Fix from $1,6002021-06-10 MEDIUM 6.5 CVE-2021-30533 KEVEPSS 17% Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions vi… Chrome 91.0.4472.77+ Fix from $1,6002021-06-07 MEDIUM 6.5 CVE-2021-30534 Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions v… Chrome 91.0.4472.77+ Fix from $1,6002021-06-07 MEDIUM 5.4 CVE-2021-30539 Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content securit… Chrome 91.0.4472.77+ Fix from $1,6002021-06-07