Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Little Snitch MEDIUM 5.5
CVE-2019-13014

Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged …

Mitigation only
Fix from $1,600 2019-08-23
Advanced Ajax Page Loader MEDIUM 5.3
CVE-2016-10929

The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.

Fix: 2.7.7+
Fix from $1,600 2019-08-22
Post Pay Counter HIGH 7.5
CVE-2017-18584

The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action.

Fix: 2.731+
Fix from $1,950 2019-08-22
Store Toolkit For Woocommerce CRITICAL 9.8
CVE-2016-10922

The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.

Fix: 1.5.7+
Fix from $2,300 2019-08-22
Store Toolkit For Woocommerce CRITICAL 9.8
CVE-2016-10923

The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.

Fix: 1.5.8+
Fix from $2,300 2019-08-22
Integrated Management Controller Supervisor HIGH 7.5
CVE-2019-12634

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D…

Fix: after 6.7.2.0
Fix from $1,950 2019-08-21
Zenoss HIGH 7.8
CVE-2019-14257

pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka Z…

No fix yet
Fix from $1,950 2019-08-21
Android HIGH 7.3
CVE-2019-2122

In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the default case between the Win…

Mitigation only
Fix from $1,950 2019-08-20
File And Removable Media Protection MEDIUM 6.7
CVE-2019-3637

Privilege Escalation vulnerability in McAfee FRP 5.x prior to 5.1.0.209 allows local users to gain elevated privileges via running McAfee Tray with e…

Fix: 5.1.0.209+
Fix from $1,600 2019-08-14
Wp Editor CRITICAL 9.8
CVE-2016-10886

The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.

Fix: 1.2.6+
Fix from $2,300 2019-08-14
Altools HIGH 7.8
CVE-2019-12808

ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can over…

Fix: after 18.1
Fix from $1,950 2019-08-13
Enterprise Network Function Virtualization Infrastructure MEDIUM 6.7
CVE-2019-1972

A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, local attacker with valid admin…

Fix: after 3.10.3
Fix from $1,600 2019-08-08
Cpanel MEDIUM 5.3
CVE-2017-18451

cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18413

In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).

Fix: 56.0.52 / 60.0.48+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18383

cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).

Fix: 62.0.35 / 64.0.42+
Fix from $1,950 2019-08-02
Openj9 HIGH 7.8
CVE-2019-11771

AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

Fix: 0.15.0+
Fix from $1,950 2019-07-17
Application Policy Infrastructure Controller HIGH 7.2
CVE-2019-1889

A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an a…

Mitigation only
Fix from $1,950 2019-07-04
Jabber HIGH 7.3
CVE-2019-1855

A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker …

Fix: 12.6+
Fix from $1,950 2019-07-04
Ipm 721s Firmware HIGH 8.8
CVE-2017-8228

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough ve…

Fix: after 2.420.ac00.16.r.20160909
Fix from $1,950 2019-07-03
Ipm 721s Firmware HIGH 8.8
CVE-2017-8230

On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of se…

Fix: after 2.420.ac00.16.r.20160909
Fix from $1,950 2019-07-03
Habomalhunter HIGH 7.8
CVE-2019-13125

HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.

Fix: after 2.0.0.3
Fix from $1,950 2019-07-01
Data Center Network Manager CRITICAL 9.8
CVE-2019-1620EPSS 84%

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $2,300 2019-06-27
Data Center Network Manager HIGH 7.5
CVE-2019-1621EPSS 30%

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $1,950 2019-06-27
Prime Infrastructure MEDIUM 6.5
CVE-2019-1906

A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual d…

Mitigation only
Fix from $1,600 2019-06-20
Sd Wan Firmware HIGH 7.8
CVE-2019-1625

A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level privileges to the root user o…

Fix: 18.3.6+
Fix from $1,950 2019-06-20
Sd Wan Firmware HIGH 8.8
CVE-2019-1626

A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated priv…

Fix: after 18.3.6
Fix from $1,950 2019-06-20
Android HIGH 8.8
CVE-2019-2003

In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirecti…

Mitigation only
Fix from $1,950 2019-06-19
Nios MEDIUM 6.7
CVE-2018-10239

A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administr…

Fix: after 8.4.1
Fix from $1,600 2019-06-17
Chipset Device Software HIGH 7.8
CVE-2019-0128

Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated u…

Fix: 10.1.1.45+
Fix from $1,950 2019-06-13
Turbo Boost Max Technology 3.0 HIGH 7.3
CVE-2019-0164

Improper permissions in the installer for Intel(R) Turbo Boost Max Technology 3.0 driver version 1.0.0.1035 and before may allow an authenticated use…

Fix: after 1.0.0.1035
Fix from $1,950 2019-06-13