Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.8 CVE-2020-17448 Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use o… Telegram Desktop after 2.1.13 Fix from $1,9502020-08-11 HIGH 7.5 CVE-2020-12780 A security misconfiguration exists in Combodo iTop, which can expose sensitive information. Itop 2.7.1+ Fix from $1,9502020-08-10 HIGH 8.8 CVE-2020-3386 A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privile… Data Center Network Manager 11.4+ Fix from $1,9502020-07-31 CRITICAL 9.9 CVE-2020-3374 A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author… Sd Wan 18.4.5 / 19.2.2+ Fix from $2,3002020-07-31 HIGH 8.8 CVE-2020-14486 An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which … Openclinic Ga Mitigation only Fix from $1,9502020-07-29 MEDIUM 6.5 CVE-2020-15126 In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User … Parse Server 4.3.0+ Fix from $1,6002020-07-22 HIGH 8.1 CVE-2020-15110 In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default se… Kubespawner 0.12+ Fix from $1,9502020-07-17 CRITICAL 9.8 CVE-2020-3140 A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain… Prime License Manager after 11.5 Fix from $2,3002020-07-16 MEDIUM 5.9 CVE-2020-3150 A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote… Rv110w Firmware 1.2.2.8 / 1.3.1.7+ Fix from $1,6002020-07-16 HIGH 8.8 CVE-2020-2228 Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulner… Gitlab Authentication after 1.5 Fix from $1,9502020-07-15 CRITICAL 9.1 CVE-2020-7692 PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by… Oauth Client Library For Java 1.31.0+ Fix from $2,3002020-07-09 MEDIUM 5.3 CVE-2020-15513 The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control. Typo3 Forum 1.2.1+ Fix from $1,6002020-07-07 HIGH 7.5 CVE-2020-5372 Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthent… Emc Powerstore 1000 Firmware 1.0.1.0.5.002+ Fix from $1,9502020-07-06 MEDIUM 5.3 CVE-2020-14196 In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enfo… Recursor after 4.3.1 Fix from $1,6002020-07-01 CRITICAL 9.1 CVE-2020-15084 In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When al… Express Jwt after 5.3.3 Fix from $2,3002020-06-30 CRITICAL 9.8 CVE-2020-12053 In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized withou… Stealth 5.0.026+ Fix from $2,3002020-06-22 HIGH 8.8 CVE-2020-13263 An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unautho… GitLab 12.9.8 / 12.10.7+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2020-13277 An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5 GitLab after 13.0.5 Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2020-3360 A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sens… Unified Ip Phone 6901 Firmware after 12.8 Fix from $1,6002020-06-18 MEDIUM 5.3 CVE-2020-3364 A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could all… Ios Xr Mitigation only Fix from $1,6002020-06-18 MEDIUM 6.5 CVE-2020-14214 Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can registe… Zammad 3.3.1+ Fix from $1,6002020-06-16 MEDIUM 6.5 CVE-2020-7499 A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) … Mtn6501 0001 Firmware 1.4.2+ Fix from $1,6002020-06-16 HIGH 7.8 CVE-2020-0115 In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a… Android Patch available Fix from $1,9502020-06-10 HIGH 7.5 CVE-2020-13834 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict … Android Mitigation only Fix from $1,9502020-06-04 MEDIUM 5.5 CVE-2020-3335 A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive informa… Application Policy Infrastructure Controller 1.1.2.20+ Fix from $1,6002020-06-03 CRITICAL 9.8 CVE-2020-3227 A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenti… Ios Xe Mitigation only Fix from $2,3002020-06-03 HIGH 8.8 CVE-2020-3229EPSS 5% A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remo… Ios Xe Patch available Fix from $1,9502020-06-03 CRITICAL 9.8 CVE-2020-11844 Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions … Service Management Automation Mitigation only Fix from $2,3002020-05-29 MEDIUM 6.5 CVE-2020-4249 IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to … Security Identity Governance And Intelligence Patch available Fix from $1,6002020-05-28 HIGH 7.5 CVE-2020-12391 Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that … Firefox 76.0+ Fix from $1,9502020-05-26