Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Endpoint Security MEDIUM 6.3
CVE-2020-7257

Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to cause the…

Mitigation only
Fix from $1,600 2020-04-15
Junos MEDIUM 5.5
CVE-2020-1630

A privilege escalation vulnerability in Juniper Networks Junos OS devices configured with dual Routing Engines (RE), Virtual Chassis (VC) or high-ava…

Mitigation only
Fix from $1,600 2020-04-08
Junos MEDIUM 6.7
CVE-2020-1619

A privilege escalation vulnerability in Juniper Networks QFX10K Series, EX9200 Series, MX Series, and PTX Series with Next-Generation Routing Engine …

Mitigation only
Fix from $1,600 2020-04-08
Endpoint Security MEDIUM 6.7
CVE-2020-7263

Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrat…

Mitigation only
Fix from $1,600 2020-04-01
Application And Change Control HIGH 7.8
CVE-2020-7260

DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary…

Fix: 8.3.0+
Fix from $1,950 2020-03-26
Sd Wan Firmware HIGH 7.8
CVE-2020-3265

A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to root on the underlying operat…

Fix: 18.4.5 / 19.2.2+
Fix from $1,950 2020-03-19
Advanced Threat Defense HIGH 7.8
CVE-2020-7254

Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to exe…

Fix: 4.8.2+
Fix from $1,950 2020-03-12
Data Center Network Manager HIGH 8.8
CVE-2020-3112

A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to elevate privile…

Fix: 11.3+
Fix from $1,950 2020-02-19
Antivirus HIGH 7.8
CVE-2020-8093

A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment …

Fix: 8.0.0+
Fix from $1,950 2020-01-30
Antivirus MEDIUM 5.5
CVE-2020-8092

A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens fo…

Fix: 8.0.0+
Fix from $1,600 2020-01-30
Sd Wan Firmware HIGH 8.8
CVE-2020-3115

A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-l…

Mitigation only
Fix from $1,950 2020-01-26
Moodle MEDIUM 5.4
CVE-2019-14879

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed…

Fix: after 3.7.2
Fix from $1,600 2020-01-07
Dna Spaces\ MEDIUM 6.7
CVE-2019-15996

A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on t…

Fix: 2.1+
Fix from $1,600 2019-11-26
Webex Meetings MEDIUM 5.4
CVE-2019-15960

A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges…

Fix: 39.7.0+
Fix from $1,600 2019-11-26
Firepower Services Software For Asa MEDIUM 5.8
CVE-2019-1978EPSS 9%

A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco F…

Fix: after 2.9.14.5
Fix from $1,600 2019-11-05
Firepower Services Software For Asa MEDIUM 5.3
CVE-2019-1980

A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco …

Fix: after 2.9.14.5
Fix from $1,600 2019-11-05
Firepower Services Software For Asa MEDIUM 5.8
CVE-2019-1981

A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco F…

Fix: after 2.9.14.5
Fix from $1,600 2019-11-05
Firepower Services Software For Asa MEDIUM 5.3
CVE-2019-1982

A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Ci…

Mitigation only
Fix from $1,600 2019-11-05
Rexpert MEDIUM 6.5
CVE-2019-17326

ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET request with a specially craft…

Fix: after 1.0.0.527
Fix from $1,600 2019-10-30
Rexpert MEDIUM 6.5
CVE-2019-17322

ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be writte…

Fix: after 1.0.0.527
Fix from $1,600 2019-10-30
Telepresence Collaboration Endpoint MEDIUM 6.7
CVE-2019-15277

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute code wi…

Fix: 9.8.0+
Fix from $1,600 2019-10-16
Telepresence Collaboration Endpoint MEDIUM 6.7
CVE-2019-15275

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute arbitra…

Fix: 9.8.1+
Fix from $1,600 2019-10-16
Unified Communications Manager MEDIUM 6.5
CVE-2019-15272

A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Editio…

Mitigation only
Fix from $1,600 2019-10-02
Omr HIGH 7.8
CVE-2019-11773

Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

Fix: 0.1+
Fix from $1,950 2019-09-12
Precision Touchpad CRITICAL 9.8
CVE-2019-10709EPSS 12%

AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potent…

No fix yet
Fix from $2,300 2019-09-04
Nx Os HIGH 7.8
CVE-2019-1966

A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an …

Fix: after 3.2
Fix from $1,950 2019-08-30
Nx Os MEDIUM 5.3
CVE-2019-1969

A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software coul…

Mitigation only
Fix from $1,600 2019-08-30
Kubernetes HIGH 7.8
CVE-2019-11245

In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or…

Patch available
Fix from $1,950 2019-08-29
Store Exporter For Woocommerce CRITICAL 9.8
CVE-2016-10935

The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.

Fix: 1.8.4+
Fix from $2,300 2019-08-27
Little Snitch MEDIUM 5.5
CVE-2019-13013

Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool imp…

Fix: after 4.3.2
Fix from $1,600 2019-08-23