Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2021-21623 An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested … Matrix Authorization Strategy after 2.6.5 Fix from $1,6002021-03-18 MEDIUM 5.3 CVE-2021-28681 Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to fail… Webrtc 3.0.15+ Fix from $1,6002021-03-18 CRITICAL 9.8 CVE-2020-24264 Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bin… Portainer after 1.24.1 Fix from $2,3002021-03-16 MEDIUM 5.3 CVE-2021-20281 It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5,… Moodle 3.5.17 / 3.8.8+ Fix from $1,6002021-03-15 MEDIUM 5.3 CVE-2021-20282 When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10… Moodle 3.5.17 / 3.8.8+ Fix from $1,6002021-03-15 HIGH 8.8 CVE-2020-25240 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the … Sinema Remote Connect Server 3.0+ Fix from $1,9502021-03-15 HIGH 8.8 CVE-2020-25239 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special… Sinema Remote Connect Server 3.0+ Fix from $1,9502021-03-15 HIGH 8.1 CVE-2021-20179 A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and … Certificate System 10.5.0 / 10.8.0+ Fix from $1,9502021-03-15 HIGH 7.5 CVE-2021-28373 The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE… Tiny Tiny Rss 2021-03-12+ Fix from $1,9502021-03-13 HIGH 8.8 CVE-2020-35682EPSS 7% Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login). Manageengine Servicedesk Plus 11.1+ Fix from $1,9502021-03-13 HIGH 8.1 CVE-2021-21367 Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When t… Fedora 2.3.5+ Fix from $1,9502021-03-12 MEDIUM 5.5 CVE-2021-0382 In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to l… Android Patch available Fix from $1,6002021-03-10 HIGH 7.8 CVE-2021-0376 In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due to a permissions bypass. This… Android Mitigation only Fix from $1,9502021-03-10 MEDIUM 6.5 CVE-2021-21182 Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer proc… Chrome 89.0.4389.72+ Fix from $1,6002021-03-09 HIGH 8.8 CVE-2021-21481 The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This… Netweaver Mitigation only Fix from $1,9502021-03-09 CRITICAL 9.8 CVE-2021-21484 LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bi… Hana Mitigation only Fix from $2,3002021-03-09 MEDIUM 6.5 CVE-2021-21362 MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before versio… Minio 2021-03-04t00-53-13z+ Fix from $1,6002021-03-08 HIGH 7.2 CVE-2020-29020 Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the c… Sitemanager Firmware 9.4.620527004+ Fix from $1,9502021-03-05 MEDIUM 6.8 CVE-2021-27099 In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the age… Spire 0.8.5 / 0.9.4+ Fix from $1,6002021-03-05 MEDIUM 5.7 CVE-2021-21725 A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directo… Zxhn H196q Firmware Mitigation only Fix from $1,6002021-03-05 HIGH 7.1 CVE-2021-26964 A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnera… Airwave 8.2.12.0+ Fix from $1,9502021-03-05 MEDIUM 5.3 CVE-2021-26027 An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article. Joomla\! 3.9.25+ Fix from $1,6002021-03-04 MEDIUM 5.4 CVE-2021-27225 In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and … Data Science Studio 8.0.6+ Fix from $1,6002021-03-01 MEDIUM 6.7 CVE-2021-26563 Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute ar… Diskstation Manager 6.2.4-25553+ Fix from $1,6002021-02-26 MEDIUM 5.3 CVE-2021-22113 Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sen… Spring Cloud Netflix Zuul after 2.2.6 Fix from $1,6002021-02-23 MEDIUM 6.5 CVE-2020-12668 Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse o… Jinjava 2.5.4+ Fix from $1,6002021-02-19 HIGH 7.5 CVE-2021-27509 In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code. Myconnection Server after 11.0b Fix from $1,9502021-02-19 MEDIUM 5.4 CVE-2021-21318 Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a … Opencast 9.2+ Fix from $1,6002021-02-18 CRITICAL 9.9 CVE-2021-26753 NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parame… Nedi No fix yet Fix from $2,3002021-02-12 HIGH 7.0 CVE-2021-20188 A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw c… Openshift Container Platform 1.7.0+ Fix from $1,9502021-02-11