Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Asyncos HIGH 7.8
CVE-2018-0095

A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) …

Mitigation only
Fix from $1,950 2018-01-18
Prime Infrastructure MEDIUM 5.9
CVE-2018-0096

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Mitigation only
Fix from $1,600 2018-01-18
Security Identity Manager Virtual Appliance HIGH 7.8
CVE-2016-0327

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator p…

Patch available
Fix from $1,950 2018-01-12
Cloudforms Management Engine HIGH 8.8
CVE-2014-0087

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), al…

Fix: 5.3+
Fix from $1,950 2018-01-11
S350i Firmware HIGH 8.8
CVE-2014-5070

Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenticated users to the login page.

No fix yet
Fix from $1,950 2018-01-11
Clearpass HIGH 7.1
CVE-2014-2071

Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunnele…

Fix: 6.2.5.61640 / 6.3.0.61712+
Fix from $1,950 2018-01-08
GitLab MEDIUM 6.5
CVE-2014-8540

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging impro…

Fix: 7.4.3+
Fix from $1,600 2018-01-05
Desktop Central CRITICAL 9.8
CVE-2014-7862EPSS 81%

The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrat…

Fix: 90109+
Fix from $2,300 2018-01-04
Webex Meetings Server MEDIUM 5.3
CVE-2017-12363

A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affect…

Mitigation only
Fix from $1,600 2017-11-30
Nx Os MEDIUM 6.8
CVE-2017-12342

A vulnerability in the Open Agent Container (OAC) feature of Cisco Nexus Series Switches could allow an unauthenticated, local attacker to read and s…

Mitigation only
Fix from $1,600 2017-11-30
Nx Os MEDIUM 5.7
CVE-2017-12351

A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outsi…

Mitigation only
Fix from $1,600 2017-11-30
Cacti HIGH 8.8
CVE-2016-10700

auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging i…

Fix: 1.0.0+
Fix from $1,950 2017-11-24
Openoffice HIGH 7.8
CVE-2016-6804

The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that a…

Fix: 4.1.3+
Fix from $1,950 2017-11-20
Identity Services Engine HIGH 7.8
CVE-2017-12261

A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local at…

Mitigation only
Fix from $1,950 2017-11-02
Cordova In App Browser CRITICAL 9.8
CVE-2014-0073EPSS 8%

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap…

Fix: after 2.9.0
Fix from $2,300 2017-10-30
Cumulus Linux HIGH 7.8
CVE-2015-5699

The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute arbitrary commands via shell m…

Fix: after 2.5.3
Fix from $1,950 2017-10-22
Cloud Services Platform 2100 CRITICAL 9.9
CVE-2017-12251

A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciou…

Mitigation only
Fix from $2,300 2017-10-19
Spin Kickstarts MEDIUM 5.9
CVE-2015-3229

fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora A…

Patch available
Fix from $1,600 2017-10-16
Clearpass Policy Manager CRITICAL 9.8
CVE-2015-4650EPSS 6%

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code w…

Fix: after 6.4.6
Fix from $2,300 2017-10-16
Ovirt Engine HIGH 7.5
CVE-2014-7851

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowle…

Mitigation only
Fix from $1,950 2017-10-16
FreeBSD HIGH 7.8
CVE-2015-5675

The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial of service (kernel panic).

No fix yet
Fix from $1,950 2017-10-10
Wp Easycart HIGH 8.8
CVE-2015-2673EPSS 19%

The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0…

No fix yet
Fix from $1,950 2017-10-06
Anyconnect Secure Mobility Client MEDIUM 6.5
CVE-2017-12268

A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable…

Mitigation only
Fix from $1,600 2017-10-05
Fingerprint Manager MEDIUM 6.7
CVE-2015-3321

Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain pri…

Fix: after 8.01.41
Fix from $1,600 2017-10-03
Ciphershed HIGH 7.8
CVE-2015-7358

The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not pro…

Fix: after 1.14
Fix from $1,950 2017-10-03
Ciphershed HIGH 7.8
CVE-2015-7359

The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when runni…

Fix: after 1.14
Fix from $1,950 2017-10-03
Ios Xe MEDIUM 6.8
CVE-2017-12239

A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband…

Mitigation only
Fix from $1,600 2017-09-29
Ios Xe HIGH 8.8
CVE-2017-12226

A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Super…

Mitigation only
Fix from $1,950 2017-09-29
Ios Xe HIGH 8.8
CVE-2017-12230

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileg…

Mitigation only
Fix from $1,950 2017-09-29
Usb Creator HIGH 7.8
CVE-2015-3643

usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and b…

Fix: after 0.2.67
Fix from $1,950 2017-09-28