Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Solutions Business Manager HIGH 8.0
CVE-2019-18945

Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability.

Fix: 11.7.1+
Fix from $1,950 2021-02-26
Anyconnect Secure Mobility Client MEDIUM 5.5
CVE-2021-1258

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges …

Fix: 4.9.03047 / 4.9.03049+
Fix from $1,600 2021-01-13
Dolphinscheduler MEDIUM 6.5
CVE-2020-13922

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter…

Mitigation only
Fix from $1,600 2021-01-11
iOS CRITICAL 9.1
CVE-2020-3426

A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated S…

Mitigation only
Fix from $2,300 2020-09-24
Unified Customer Voice Portal MEDIUM 6.8
CVE-2019-16017

A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP…

Fix: 11.6 / 12.0+
Fix from $1,600 2020-09-23
Ios Xr HIGH 7.8
CVE-2020-3473

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to el…

Fix: 6.5.29 / 6.6.3+
Fix from $1,950 2020-09-04
Ios Xr HIGH 8.4
CVE-2020-3530

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute …

Fix: 7.1.2+
Fix from $1,950 2020-09-04
Smart Software Manager On Prem HIGH 8.8
CVE-2020-3443

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute…

Mitigation only
Fix from $1,950 2020-08-26
Vision Dynamic Signage Director MEDIUM 6.3
CVE-2020-3485

A vulnerability in the role-based access control (RBAC) functionality of the web management software of Cisco Vision Dynamic Signage Director could a…

Mitigation only
Fix from $1,600 2020-08-26
Galaxy HIGH 8.8
CVE-2020-7352

The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embe…

Fix: after 2.0.12
Fix from $1,950 2020-08-06
Snapd MEDIUM 6.8
CVE-2020-11933

cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker cou…

Fix: 2.45.2+
Fix from $1,600 2020-07-29
Factorytalk View HIGH 8.1
CVE-2020-12028EPSS 53%

In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the re…

No fix yet
Fix from $1,950 2020-07-20
Sd Wan Firmware HIGH 7.8
CVE-2020-3379

A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlyi…

Fix: 18.3.0+
Fix from $1,950 2020-07-16
Sd Wan HIGH 7.8
CVE-2020-3180

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account tha…

Fix: 18.3.6 / 18.4.5+
Fix from $1,950 2020-07-16
Ios Xe CRITICAL 9.8
CVE-2020-3227

A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenti…

Mitigation only
Fix from $2,300 2020-06-03
Ios Xe HIGH 8.8
CVE-2020-3229EPSS 5%

A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remo…

Patch available
Fix from $1,950 2020-06-03
Ios Xe MEDIUM 6.7
CVE-2020-3213

A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to those of the root user o…

Patch available
Fix from $1,600 2020-06-03
Ios Xe MEDIUM 6.7
CVE-2020-3214

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileg…

Mitigation only
Fix from $1,600 2020-06-03
Ios Xe MEDIUM 6.7
CVE-2020-3215

A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges…

No fix yet
Fix from $1,600 2020-06-03
iOS MEDIUM 6.7
CVE-2020-3208

A vulnerability in the image verification feature of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs…

Patch available
Fix from $1,600 2020-06-03
Automation Studio HIGH 7.1
CVE-2019-19100

A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.4SP, …

Fix: 4.3.11 / 4.4.9+
Fix from $1,950 2020-04-29
800xa HIGH 7.8
CVE-2020-8484

Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authent…

Mitigation only
Fix from $1,950 2020-04-29
800xa HIGH 7.8
CVE-2020-8485

Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker aut…

Mitigation only
Fix from $1,950 2020-04-29
800xa Rnrp HIGH 7.8
CVE-2020-8486

Insufficient protection of the inter-process communication functions in ABB System 800xA RNRP (all published versions) enables an attacker authentica…

Mitigation only
Fix from $1,950 2020-04-29
800xa Base System HIGH 7.8
CVE-2020-8487

Insufficient protection of the inter-process communication functions in ABB System 800xA Base (all published versions) enables an attacker authentica…

Mitigation only
Fix from $1,950 2020-04-29
800xa Batch Management HIGH 7.8
CVE-2020-8488

Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacke…

No fix yet
Fix from $1,950 2020-04-29
800xa Information Management HIGH 7.8
CVE-2020-8489

Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an a…

Mitigation only
Fix from $1,950 2020-04-29
Tg\/s3.2 Firmware CRITICAL 9.1
CVE-2019-19106

Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to a…

Mitigation only
Fix from $2,300 2020-04-22
Tg\/s3.2 Firmware MEDIUM 5.5
CVE-2019-19107

The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the passwo…

Mitigation only
Fix from $1,600 2020-04-22
Endpoint Security HIGH 7.8
CVE-2020-7259

Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to by…

Mitigation only
Fix from $1,950 2020-04-15