Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Intellispace Portal CRITICAL 9.8
CVE-2018-5472

Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unau…

Mitigation only
Fix from $2,300 2018-03-26
Seafile Server HIGH 7.8
CVE-2014-5443

Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling u…

Fix: 3.1.0 / 3.1.2+
Fix from $1,950 2018-03-19
Rational Collaborative Lifecycle Management HIGH 7.8
CVE-2015-7440

IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15,…

Fix: after 6.0.1
Fix from $1,950 2018-03-15
Pi Web Api CRITICAL 9.8
CVE-2018-7500

A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, gi…

Fix: after 2017
Fix from $2,300 2018-03-14
Keycloak MEDIUM 6.5
CVE-2016-8629

Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest serve…

Fix: 2.4.0+
Fix from $1,600 2018-03-12
Fedora HIGH 7.8
CVE-2014-7272

Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations…

Fix: 0.10.0+
Fix from $1,950 2018-03-08
Identity Services Engine HIGH 8.8
CVE-2018-0213

A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain …

Mitigation only
Fix from $1,950 2018-03-08
Safenet Authentication Service End User Software Tools For Windows HIGH 7.8
CVE-2015-7596

SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation directories and executable modules, w…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service Iis Agent HIGH 7.8
CVE-2015-7597

SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service Tokenvalidator Proxy Agent HIGH 7.8
CVE-2015-7598

SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allo…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service Remote Web Workplace Agent HIGH 7.8
CVE-2015-7961

SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allo…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service For Outlook Web App Agent HIGH 7.8
CVE-2015-7962

SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allow…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service For Ad Fs Agent HIGH 7.8
CVE-2015-7963

SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local us…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service For Nps Agent HIGH 7.8
CVE-2015-7964

SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local user…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service Windows Logon Agent HIGH 7.8
CVE-2015-7965

SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows loca…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service Windows Logon Agent HIGH 7.8
CVE-2015-7966

SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows loca…

Patch available
Fix from $1,950 2018-03-02
Safenet Authentication Service For Citrix Web Interface Agent HIGH 7.8
CVE-2015-7967

SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which …

Patch available
Fix from $1,950 2018-03-02
Zsh HIGH 7.8
CVE-2014-10070

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numb…

Fix: after 5.0.6
Fix from $1,950 2018-02-27
Virtual Managed Services CRITICAL 9.8
CVE-2018-0130

A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenti…

Mitigation only
Fix from $2,300 2018-02-22
Vcl HIGH 8.8
CVE-2013-0267

The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user…

Fix: 2.3.2+
Fix from $1,950 2018-02-21
Eucalyptus HIGH 8.8
CVE-2016-8528

A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found.

Fix: after 4.3.1
Fix from $1,950 2018-02-15
Matrix Operating Environment HIGH 8.8
CVE-2016-8533

A remote priviledge escalation vulnerability in HPE Matrix Operating Environment version 7.6 was found.

No fix yet
Fix from $1,950 2018-02-15
Matrix Operating Environment HIGH 8.8
CVE-2016-8534

A remote privilege elevation vulnerability in HPE Matrix Operating Environment version 7.6 was found.

No fix yet
Fix from $1,950 2018-02-15
Couchdb HIGH 7.8
CVE-2016-8742

The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…

No fix yet
Fix from $1,950 2018-02-12
FreeBSD HIGH 7.8
CVE-2015-1416

Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch befo…

Mitigation only
Fix from $1,950 2018-02-05
Totalprotection MEDIUM 6.7
CVE-2014-3752

The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights to execute arbitrary code wi…

Fix: after 24.0.2.1
Fix from $1,600 2018-02-01
Open Atrium MEDIUM 6.5
CVE-2014-9503

The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permi…

Fix: 7.x-2.26+
Fix from $1,600 2018-02-01
Eshop MEDIUM 5.4
CVE-2014-4919

OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition …

Fix: 4.7.13 / 4.8.7+
Fix from $1,600 2018-01-19
Policy Suite HIGH 7.5
CVE-2018-0089

A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to a…

Mitigation only
Fix from $1,950 2018-01-18
Nx Os HIGH 7.1
CVE-2018-0092

A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software could allow an authenticated, local attacker to impr…

Mitigation only
Fix from $1,950 2018-01-18