Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.5 CVE-2020-0087 In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclo… Android Mitigation only Fix from $1,6002020-03-10 HIGH 7.8 CVE-2020-0036 In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass. This could lead to loc… Android Mitigation only Fix from $1,9502020-03-10 HIGH 8.8 CVE-2020-2134 Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor… Script Security after 1.70 Fix from $1,9502020-03-09 HIGH 8.8 CVE-2020-2135 Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement Gr… Script Security after 1.70 Fix from $1,9502020-03-09 MEDIUM 5.3 CVE-2020-5251 In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex o… Parse Server 4.1.0+ Fix from $1,6002020-03-04 HIGH 7.5 CVE-2020-9381 controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be expl… Total.js Cms Patch available Fix from $1,9502020-02-24 HIGH 8.1 CVE-2014-7914 btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote att… Android 5.1+ Fix from $1,9502020-02-21 HIGH 8.8 CVE-2020-5242 openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary comma… Openhab 2.5.2+ Fix from $1,9502020-02-20 MEDIUM 5.5 CVE-2020-7251 Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows loca… Endpoint Security 10.6.1+ Fix from $1,6002020-02-14 HIGH 8.8 CVE-2020-5239 In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Ma… Mailu 1.7+ Fix from $1,9502020-02-13 HIGH 8.8 CVE-2020-6380 Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer proc… Chrome 79.0.3945.130+ Fix from $1,9502020-02-11 HIGH 7.5 CVE-2020-5318 Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vuln… Emc Isilon Onefs Mitigation only Fix from $1,9502020-02-06 MEDIUM 6.8 CVE-2013-2673 Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate attackers to gain unauthorized … Mfc 9970cdw Firmware No fix yet Fix from $1,6002020-02-03 MEDIUM 5.3 CVE-2020-7955 HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended… Consul 1.6.2+ Fix from $1,6002020-01-31 CRITICAL 9.8 CVE-2013-2198 The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted… Login Security after 7.x-1.3 Fix from $2,3002020-01-30 CRITICAL 9.1 CVE-2013-1350 Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities Network Management System 2.1.0+ Fix from $2,3002020-01-30 HIGH 7.5 CVE-2013-2574EPSS 30% An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could l… Fi8620 Firmware No fix yet Fix from $1,9502020-01-29 CRITICAL 9.8 CVE-2020-8086 The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() f… Debian Linux after 2020-01-27 Fix from $2,3002020-01-28 HIGH 8.1 CVE-2013-4862 MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via … Veralite Firmware No fix yet Fix from $1,9502020-01-28 MEDIUM 6.5 CVE-2019-5474 An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden witho… GitLab 11.11.6 / 12.0.4+ Fix from $1,6002020-01-28 HIGH 7.8 CVE-2019-17190 A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the Avast… Secure Browser No fix yet Fix from $1,9502020-01-27 HIGH 8.8 CVE-2020-2097 Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read acc… Sounds after 0.5 Fix from $1,9502020-01-15 HIGH 7.5 CVE-2012-3822 Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' creden… Campaign Enterprise 11.0.551+ Fix from $1,9502020-01-10 HIGH 7.4 CVE-2019-17014 If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-o… Firefox 71.0+ Fix from $1,9502020-01-08 HIGH 7.1 CVE-2016-6591 A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local m… Norton App Lock after 1.0.3.186 Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-14843 A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a mal… Single Sign On Patch available Fix from $1,9502020-01-07 HIGH 7.3 CVE-2019-6855 Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M3… Ecostruxure Control Expert 3.10 / 14.1+ Fix from $1,9502020-01-06 MEDIUM 6.5 CVE-2014-0169 In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002020-01-02 HIGH 8.8 CVE-2010-3782 obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation. Obs Server 1.7.7+ Fix from $1,9502020-01-02 HIGH 7.5 CVE-2019-20213 D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnc… Dir 859 Firmware after 3.12b04 Fix from $1,9502020-01-02