Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2020-15251 In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is a… Channelmgnt 1.0.3+ Fix from $1,6002020-10-13 HIGH 7.7 CVE-2020-3467 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to modify… Identity Services Engine after 2.4 Fix from $1,9502020-10-08 HIGH 7.5 CVE-2020-13334 In GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, improper authorization checks allow a non-member of a project/group to change the confidentia… GitLab 13.2.10 / 13.3.7+ Fix from $1,9502020-10-07 HIGH 8.8 CVE-2019-19200 REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users. Maildepot No fix yet Fix from $1,9502020-10-06 MEDIUM 6.5 CVE-2020-15664 By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object w… Firefox 68.12 / 78.2+ Fix from $1,6002020-10-01 HIGH 7.2 CVE-2020-13322 A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete… GitLab 12.10.13 / 13.0.8+ Fix from $1,9502020-09-30 HIGH 7.5 CVE-2020-26121 An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protect… Fedora 1.34.4+ Fix from $1,9502020-09-27 HIGH 7.5 CVE-2020-25869 An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use… Fedora 1.31.10 / 1.34.4+ Fix from $1,9502020-09-27 HIGH 8.1 CVE-2020-3474 Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privil… Ios Xe Mitigation only Fix from $1,9502020-09-24 MEDIUM 5.5 CVE-2020-3477 A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from t… iOS Mitigation only Fix from $1,6002020-09-24 HIGH 7.8 CVE-2020-3404 A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell a… Ios Xe Mitigation only Fix from $1,9502020-09-24 HIGH 8.8 CVE-2020-4621 IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization … Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 HIGH 7.5 CVE-2020-15590 A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill swi… Private Internet Access Vpn Client 2.4.0+ Fix from $1,9502020-09-14 MEDIUM 6.5 CVE-2020-13284 A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token GitLab 13.1.10 / 13.2.8+ Fix from $1,6002020-09-14 CRITICAL 10.0 CVE-2020-13300 GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati… GitLab 13.3.4+ Fix from $2,3002020-09-14 HIGH 8.2 CVE-2020-15163 Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file w… The Update Framework 0.12.0+ Fix from $1,9502020-09-09 MEDIUM 6.5 CVE-2020-6311 Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly per… Bank Analyzer Mitigation only Fix from $1,6002020-09-09 HIGH 7.8 CVE-2020-3473 A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to el… Ios Xr 6.5.29 / 6.6.3+ Fix from $1,9502020-09-04 HIGH 8.4 CVE-2020-3530 A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute … Ios Xr 7.1.2+ Fix from $1,9502020-09-04 HIGH 7.5 CVE-2020-24941 An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests wi… Laravel 6.18.35 / 7.24.0+ Fix from $1,9502020-09-04 CRITICAL 9.8 CVE-2020-25055 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unp… Android Mitigation only Fix from $2,3002020-08-31 HIGH 7.8 CVE-2020-24716 OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories. Openzfs after 0.8.4 Fix from $1,9502020-08-27 MEDIUM 6.3 CVE-2020-3522 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attac… Data Center Network Manager 11.4+ Fix from $1,6002020-08-26 MEDIUM 5.7 CVE-2020-19005 zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup … Zrlog Patch available Fix from $1,6002020-08-25 MEDIUM 5.5 CVE-2020-9712 Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a secur… Acrobat Dc after 20.009.20074 Fix from $1,6002020-08-19 MEDIUM 5.0 CVE-2020-3472 A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to acces… Webex Meetings Online 40.7.0+ Fix from $1,6002020-08-17 CRITICAL 9.8 CVE-2020-8212 Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and … Xenmobile Server after 10.9.0 Fix from $2,3002020-08-17 HIGH 7.8 CVE-2020-7583 A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The applica… Automation License Manager 6.0.8+ Fix from $1,9502020-08-14 MEDIUM 6.3 CVE-2020-7300 Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to chan… Data Loss Prevention 11.3.28 / 11.4.200+ Fix from $1,6002020-08-12 MEDIUM 6.5 CVE-2020-2233 A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credenti… Pipeline Maven Integration after 3.8.2 Fix from $1,6002020-08-12