Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.8 CVE-2021-1539 Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to byp… Staros 21.16.9 / 21.17.10+ Fix from $1,9502021-06-04 HIGH 7.2 CVE-2021-1540 Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to byp… Staros 21.16.9 / 21.17.10+ Fix from $1,9502021-06-04 MEDIUM 5.4 CVE-2021-3469 Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the … Foreman 2.3.4+ Fix from $1,6002021-06-03 MEDIUM 5.6 CVE-2021-3499 A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules wh… Ovn Kubernetes after 0.3.0 Fix from $1,6002021-06-02 CRITICAL 9.8 CVE-2021-32619 Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imp… Deno 1.10.2+ Fix from $2,3002021-05-28 HIGH 8.8 CVE-2021-32620 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 1… Xwiki 11.10.13 / 12.6.7+ Fix from $1,9502021-05-28 HIGH 7.5 CVE-2021-29628 In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call tri… FreeBSD No fix yet Fix from $1,9502021-05-28 MEDIUM 5.4 CVE-2020-26555 Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD… Fedora after 5.2 Fix from $1,6002021-05-24 HIGH 8.8 CVE-2020-26559 Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to id… Mesh Profile Mitigation only Fix from $1,9502021-05-24 HIGH 8.1 CVE-2020-26560 Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Pro… Mesh Profile Mitigation only Fix from $1,9502021-05-24 HIGH 8.8 CVE-2021-21552 Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicio… Windows 10 after 2019 Fix from $1,9502021-05-21 MEDIUM 6.5 CVE-2021-31158 In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permiss… Couchbase Server 6.6.2+ Fix from $1,6002021-05-19 MEDIUM 5.3 CVE-2021-20429 IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force… Qradar User Behavior Analytics 4.1.1+ Fix from $1,6002021-05-14 HIGH 7.5 CVE-2021-24278EPSS 7% In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a val… Redirection For Contact Form 7 2.3.4+ Fix from $1,9502021-05-14 MEDIUM 6.5 CVE-2021-24279 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX actio… Redirection For Contact Form 7 2.3.4+ Fix from $1,6002021-05-14 MEDIUM 6.3 CVE-2021-24282 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions… Redirection For Contact Form 7 2.3.4+ Fix from $1,6002021-05-14 MEDIUM 6.5 CVE-2021-31876 Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to tri… Bitcoin after 0.21.1 Fix from $1,6002021-05-13 MEDIUM 6.1 CVE-2021-3457 An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions tha… Smart Proxy Shell Hooks 0.9.2+ Fix from $1,6002021-05-12 MEDIUM 5.3 CVE-2020-36289EPSS 99% Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili… Data Center 8.5.13 / 8.13.5+ Fix from $1,6002021-05-12 HIGH 7.8 CVE-2021-31165 Windows Container Manager Service Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-05-11 CRITICAL 9.1 CVE-2021-20538 IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have acce… Cloud Pak For Security Mitigation only Fix from $2,3002021-05-10 HIGH 7.2 CVE-2021-23015 On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an aut… Big Ip Access Policy Manager 13.1.4 / 14.1.4+ Fix from $1,9502021-05-10 MEDIUM 5.5 CVE-2021-31829 kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-chan… Linux Kernel after 5.12.1 Fix from $1,6002021-05-06 HIGH 7.5 CVE-2021-22209 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which… GitLab 13.9.7 / 13.10.4+ Fix from $1,9502021-05-06 MEDIUM 6.5 CVE-2021-24244 An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allo… Wpbakery Page Builder Clipboard 4.5.8+ Fix from $1,6002021-05-06 MEDIUM 6.5 CVE-2021-31926 AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firew… Amp 2.1.1.2+ Fix from $1,6002021-04-30 HIGH 7.1 CVE-2021-1086 NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it allows guests to control unauthorized resources, which … Virtual Gpu Manager 8.7 / 11.4+ Fix from $1,9502021-04-29 HIGH 7.5 CVE-2020-21990 Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper acc… Mydomoathome No fix yet Fix from $1,9502021-04-29 HIGH 7.5 CVE-2021-30638EPSS 7% Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia… Tapestry 5.6.4 / 5.7.2+ Fix from $1,9502021-04-27 MEDIUM 6.5 CVE-2021-31548 An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blocked or was unsuccessfully bl… Mediawiki after 1.35.2 Fix from $1,6002021-04-22