Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.8 CVE-2016-20002 The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's securit… Rest\/json after 7.x-1.5 Fix from $2,3002021-01-01 CRITICAL 9.8 CVE-2016-20004 The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security … Rest\/json after 7.x-1.5 Fix from $2,3002021-01-01 CRITICAL 9.8 CVE-2016-20005 The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's secu… Rest\/json after 7.x-1.5 Fix from $2,3002021-01-01 MEDIUM 6.5 CVE-2020-26029 An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization… Zammad 3.4.1+ Fix from $1,6002020-12-28 HIGH 8.8 CVE-2020-24674 In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users c… Symphony \+ Historian Mitigation only Fix from $1,9502020-12-22 MEDIUM 5.4 CVE-2020-4794 IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6… Automation Workstream Services Patch available Fix from $1,6002020-12-21 HIGH 7.8 CVE-2020-0479 In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malic… Android Patch available Fix from $1,9502020-12-15 MEDIUM 6.3 CVE-2020-26250 OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2… Oauthenticator 0.12.2+ Fix from $1,6002020-12-01 HIGH 7.5 CVE-2020-15246 October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.421 and before version 1… October 1.0.469+ Fix from $1,9502020-11-23 MEDIUM 6.5 CVE-2020-28053 HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key conf… Consul 1.6.10 / 1.7.10+ Fix from $1,6002020-11-23 HIGH 7.8 CVE-2020-28211 A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cau… Ecostruxure Control Expert Patch available Fix from $1,9502020-11-19 HIGH 7.5 CVE-2020-25699 In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that … Moodle after 3.9.2 Fix from $1,9502020-11-19 MEDIUM 5.3 CVE-2020-25701 If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneousl… Moodle after 3.9.2 Fix from $1,6002020-11-19 MEDIUM 5.3 CVE-2020-8278 Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user. Social No fix yet Fix from $1,6002020-11-19 MEDIUM 6.5 CVE-2020-26223 Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12… Spree 3.7.13 / 4.0.5+ Fix from $1,6002020-11-13 MEDIUM 5.5 CVE-2020-11209 Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855… Sd820 Firmware No fix yet Fix from $1,6002020-11-12 MEDIUM 6.6 CVE-2020-17049EPSS 14% A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via… Windows Server 2012 4.13.13 / 4.14.9+ Fix from $1,6002020-11-11 MEDIUM 6.5 CVE-2020-25655 An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002020-11-09 MEDIUM 6.5 CVE-2020-24401 Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisio… Magento 2.3.5+ Fix from $1,6002020-11-09 MEDIUM 6.5 CVE-2020-3592 A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author… Catalyst Sd Wan Manager after 20.1.12 Fix from $1,6002020-11-06 HIGH 7.8 CVE-2020-3600 A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste… Sd Wan 20.1.2 / 20.3.2+ Fix from $1,9502020-11-06 HIGH 7.5 CVE-2020-15278 Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit allows Discord users with a hig… Red Discord Bot 3.4.1+ Fix from $1,9502020-10-28 MEDIUM 5.3 CVE-2020-3852 A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrectly ignored when determining … Safari 13.0.5+ Fix from $1,6002020-10-27 MEDIUM 6.5 CVE-2020-3578 A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c… Secure Firewall Threat Defense 6.3.0.6 / 6.4.0.10+ Fix from $1,6002020-10-21 MEDIUM 5.3 CVE-2020-27609 BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data stora… Bigbluebutton after 2.2.28 Fix from $1,6002020-10-21 MEDIUM 6.5 CVE-2020-6362 SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with othe… Banking Services Mitigation only Fix from $1,6002020-10-20 MEDIUM 5.3 CVE-2020-16904 <p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfull… Azure Functions Patch available Fix from $1,6002020-10-16 HIGH 7.2 CVE-2020-12503EPSS 23% Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES… Es7510 Xt Firmware No fix yet Fix from $1,9502020-10-15 CRITICAL 9.8 CVE-2020-27156 Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for remote code execution by an u… Aptare 10.5+ Fix from $2,3002020-10-15 CRITICAL 9.8 CVE-2020-13957EPSS 79% Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote co… Solr after 8.6.2 Fix from $2,3002020-10-13