Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Android HIGH 8.8
CVE-2019-2102

In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK…

Mitigation only
Fix from $1,950 2019-06-07
Thehive HIGH 8.8
CVE-2017-18376

An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to esc…

Fix: 2.13.4 / 3.3.1+
Fix from $1,950 2019-06-02
Libvirt HIGH 8.8
CVE-2019-10132

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati…

Fix: after 4.1.0
Fix from $1,950 2019-05-22
Nx Os MEDIUM 6.7
CVE-2019-1727

A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser an…

Fix: 7.0 / 7.3+
Fix from $1,600 2019-05-15
Nx Os MEDIUM 6.7
CVE-2019-1730

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command …

Fix: 7.0 / 8.3+
Fix from $1,600 2019-05-15
Nexus 9000 Series Application Centric Infrastructure MEDIUM 6.7
CVE-2019-1803

A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allo…

Mitigation only
Fix from $1,600 2019-05-03
Nx Os HIGH 7.8
CVE-2019-1592

A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software c…

Mitigation only
Fix from $1,950 2019-05-03
Application Policy Infrastructure Controller HIGH 7.8
CVE-2019-1682

A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authentica…

Fix: 4.1+
Fix from $1,950 2019-05-03
Ubuntu Download Manager CRITICAL 9.8
CVE-2016-1579

UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functiona…

Mitigation only
Fix from $2,300 2019-04-22
Ubuntu Linux HIGH 7.8
CVE-2015-1341

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Ap…

Fix: 2.19.2+
Fix from $1,950 2019-04-22
Windows 10 HIGH 7.8
CVE-2019-0730

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…

Patch available
Fix from $1,950 2019-04-09
Windows 10 HIGH 7.8
CVE-2019-0731

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…

Patch available
Fix from $1,950 2019-04-09
Windows 10 MEDIUM 5.5
CVE-2019-0796

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privi…

Patch available
Fix from $1,600 2019-04-09
Workspace Control HIGH 7.8
CVE-2019-10885

An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed se…

Fix: 10.3.90.0+
Fix from $1,950 2019-04-05
Symbiq Infusion System Firmware HIGH 8.8
CVE-2015-3965

Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privi…

Fix: after 3.13
Fix from $1,950 2019-03-23
Netiq Edirectory HIGH 7.5
CVE-2016-9166

NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.

Fix: 9.0+
Fix from $1,950 2019-03-21
Matrix Storage Manager HIGH 7.8
CVE-2019-0121

Improper permissions in Intel(R) Matrix Storage Manager 8.9.0.1023 and before may allow an authenticated user to potentially enable escalation of pri…

Fix: after 8.9.0.1023
Fix from $1,950 2019-03-14
Usb 3.0 Creator Utility HIGH 7.8
CVE-2019-0129

Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege …

Mitigation only
Fix from $1,950 2019-03-14
Rapid Storage Technology Enterprise HIGH 7.8
CVE-2019-0135

Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an authenticated …

Fix: 5.5.0.2015+
Fix from $1,950 2019-03-14
Canarytokens HIGH 7.5
CVE-2019-9768EPSS 12%

Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for…

Fix: after 2019-03-01
Fix from $1,950 2019-03-14
Common Services Platform Collector CRITICAL 9.8
CVE-2019-1723EPSS 6%

A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device b…

Fix: 2.7.4.6 / 2.8.1.2+
Fix from $2,300 2019-03-13
PHP HIGH 7.5
CVE-2019-9637EPSS 7%

An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented,…

Fix: 7.1.27 / 7.2.16+
Fix from $1,950 2019-03-09
Nx Os HIGH 7.8
CVE-2019-1602

A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that coul…

Fix: 7.0+
Fix from $1,950 2019-03-08
Container Runtime HIGH 8.8
CVE-2019-3779

Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust …

Fix: 0.29.0+
Fix from $1,950 2019-03-08
Nx Os HIGH 7.8
CVE-2019-1596

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege le…

Fix: 7.0+
Fix from $1,950 2019-03-07
Nx Os HIGH 7.8
CVE-2019-1591

A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local atta…

Fix: 14.0+
Fix from $1,950 2019-03-06
Nx Os HIGH 7.8
CVE-2019-1593

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege le…

Fix: 7.0 / 8.2+
Fix from $1,950 2019-03-06
Nx Os HIGH 7.4
CVE-2019-1594

A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service …

Fix: 5.2 / 6.2+
Fix from $1,950 2019-03-06
Filr HIGH 7.8
CVE-2019-3475

A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege us…

No fix yet
Fix from $1,950 2019-02-20
Telepresence Management Suite MEDIUM 5.3
CVE-2019-1660

A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, rem…

Mitigation only
Fix from $1,600 2019-02-07