Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.8 CVE-2021-27177EPSS 20% An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the Ggpo… Hg6245d Firmware No fix yet Fix from $2,3002021-02-10 HIGH 7.5 CVE-2020-8806 Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid chain could be incorrectly rej… Zcashd 2.1.1+ Fix from $1,9502021-02-05 MEDIUM 6.5 CVE-2020-27873 This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 rout… Ac2100 Firmware 1.2.0.76+ Fix from $1,6002021-02-04 MEDIUM 5.3 CVE-2021-25777 In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. Teamcity 2020.2.1+ Fix from $1,6002021-02-03 MEDIUM 5.9 CVE-2019-25017 An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which fi… Krb5 Appl after 1.0.3 Fix from $1,6002021-02-02 HIGH 8.8 CVE-2021-21286 AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform before version 10.2 there is a… Avideo 10.2+ Fix from $1,9502021-02-01 CRITICAL 9.3 CVE-2021-21276EPSS 7% Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to sit… Polr 2.3.0+ Fix from $2,3002021-02-01 HIGH 7.5 CVE-2021-3337EPSS 11% The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on rep… Hide Thread Content No fix yet Fix from $1,9502021-01-28 MEDIUM 5.4 CVE-2020-1725 A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycl… Keycloak 13.0.0+ Fix from $1,6002021-01-28 HIGH 7.8 CVE-2021-26025 PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x000000000000… Photo Studio 2021 Mitigation only Fix from $1,9502021-01-26 HIGH 7.8 CVE-2021-26026 PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c… Photo Studio 2021 Mitigation only Fix from $1,9502021-01-26 HIGH 8.8 CVE-2020-9492 In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote UR… Hadoop after 3.2.1 Fix from $1,9502021-01-26 MEDIUM 6.3 CVE-2021-1269 Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attac… Data Center Network Manager 11.5+ Fix from $1,6002021-01-20 MEDIUM 6.5 CVE-2021-1270 Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attac… Data Center Network Manager 11.5+ Fix from $1,6002021-01-20 MEDIUM 5.3 CVE-2020-4873 IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836. Planning Analytics Patch available Fix from $1,6002021-01-19 HIGH 8.1 CVE-2021-21013 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR)… Magento after 2.4.1 Fix from $1,9502021-01-13 HIGH 8.8 CVE-2021-1144 A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter t… Connected Mobile Experiences Mitigation only Fix from $1,9502021-01-13 MEDIUM 5.3 CVE-2021-21609 Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers… Jenkins after 2.274 Fix from $1,6002021-01-13 HIGH 7.8 CVE-2021-0317 In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalat… Android Patch available Fix from $1,9502021-01-11 HIGH 7.3 CVE-2021-0319 In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without approp… Android Patch available Fix from $1,9502021-01-11 HIGH 7.8 CVE-2018-8044 K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The compo… Antivrius 14.2.0001 / 16.0.0001+ Fix from $1,9502021-01-11 HIGH 7.8 CVE-2018-8724 K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is:… Antivrius 14.2.0001 / 16.0.0001+ Fix from $1,9502021-01-11 MEDIUM 5.5 CVE-2021-1054 NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in wh… Gpu Driver 392.63 / 427.11+ Fix from $1,6002021-01-08 HIGH 8.8 CVE-2020-35948EPSS 25% An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify a… Xcloner 4.2.13+ Fix from $1,9502021-01-01 CRITICAL 9.8 CVE-2016-20001 The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security a… Rest\/json after 7.x-1.5 Fix from $2,3002021-01-01 CRITICAL 9.8 CVE-2016-20002 The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's securit… Rest\/json after 7.x-1.5 Fix from $2,3002021-01-01 CRITICAL 9.8 CVE-2016-20004 The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security … Rest\/json after 7.x-1.5 Fix from $2,3002021-01-01 CRITICAL 9.8 CVE-2016-20005 The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's secu… Rest\/json after 7.x-1.5 Fix from $2,3002021-01-01 MEDIUM 6.5 CVE-2020-26029 An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization… Zammad 3.4.1+ Fix from $1,6002020-12-28 HIGH 8.8 CVE-2020-24674 In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users c… Symphony \+ Historian Mitigation only Fix from $1,9502020-12-22