Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2020-3811 qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. Debian Linux Patch available Fix from $1,9502020-05-26 MEDIUM 5.3 CVE-2019-20801 An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin request… Documents 6.9.7+ Fix from $1,6002020-05-18 HIGH 7.8 CVE-2020-0097 In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead t… Android Patch available Fix from $1,9502020-05-14 MEDIUM 6.3 CVE-2020-12875 Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitiv… Aptare 10.4+ Fix from $1,6002020-05-14 HIGH 7.5 CVE-2020-12876 Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows … Aptare 10.4+ Fix from $1,9502020-05-14 HIGH 8.8 CVE-2020-1998 An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions … Pan Os 7.1.26 / 8.1.13+ Fix from $1,9502020-05-13 HIGH 7.5 CVE-2020-8151 There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to acce… Active Resource 5.1.1+ Fix from $1,9502020-05-12 HIGH 8.8 CVE-2020-12691 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a pro… Ubuntu Linux 15.0.1+ Fix from $1,9502020-05-07 MEDIUM 5.3 CVE-2020-7921 Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credent… MongoDB 3.6.18 / 4.0.15+ Fix from $1,6002020-05-06 HIGH 7.8 CVE-2020-5343 Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vuln… Os Recovery Image For Microsoft Windows 10 2019-12-20+ Fix from $1,9502020-05-04 HIGH 7.5 CVE-2020-12477 The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For… Teampass No fix yet Fix from $1,9502020-04-29 HIGH 8.8 CVE-2020-10786 A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron… Vesta Control Panel after 0.9.8-26 Fix from $1,9502020-04-21 HIGH 8.8 CVE-2020-11753 An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to … Nexus Repository Manager 3 Patch available Fix from $1,9502020-04-20 MEDIUM 6.5 CVE-2020-5287 In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5. Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5288 "In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5. Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5293 In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific pr… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 MEDIUM 6.5 CVE-2020-5279 In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-d… Prestashop 1.7.6.5+ Fix from $1,6002020-04-20 HIGH 8.8 CVE-2020-0981 A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the v… Windows 10 Patch available Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-11707 An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result,… Provide Ftp Server after 13.1 Fix from $1,9502020-04-12 HIGH 7.5 CVE-2018-21039 An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka Quic… Android Mitigation only Fix from $1,9502020-04-08 HIGH 8.4 CVE-2018-21082 An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use scr… Android Mitigation only Fix from $1,9502020-04-08 MEDIUM 5.3 CVE-2020-11628 An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, AC… Ejbca 6.15.2.6 / 7.3.1.2+ Fix from $1,6002020-04-08 MEDIUM 6.8 CVE-2020-8142 A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like… Revive Adserver 5.0.5+ Fix from $1,6002020-04-03 HIGH 8.1 CVE-2020-5275 In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and s… Symfony 4.4.7 / 5.0.7+ Fix from $1,9502020-03-30 MEDIUM 6.5 CVE-2020-10510 Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a … Ehrd Mitigation only Fix from $1,6002020-03-27 MEDIUM 6.6 CVE-2020-1796 There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successf… Mate 20 Firmware after 10.0.0.203 Fix from $1,6002020-03-20 HIGH 8.8 CVE-2019-11361 Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full ap… Manageengine Remote Access Plus Mitigation only Fix from $1,9502020-03-19 HIGH 8.8 CVE-2020-10239 An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users. Joomla\! 3.9.16+ Fix from $1,9502020-03-16 HIGH 8.5 CVE-2020-5240 In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does … Wagtail 2fa 1.4.1+ Fix from $1,9502020-03-13 CRITICAL 9.8 CVE-2020-10534 In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-… Mediawiki after 1.34.0 Fix from $2,3002020-03-12