Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Vedge 100 Firmware HIGH 7.8
CVE-2019-1646

A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device c…

Fix: 18.4.0+
Fix from $1,950 2019-01-24
Vedge 100 Firmware HIGH 7.8
CVE-2019-1648

A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges…

Fix: 18.4.0+
Fix from $1,950 2019-01-24
Sinumerik 808d V4.7 Firmware MEDIUM 6.6
CVE-2018-11461

A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4…

Fix: after 4.8
Fix from $1,600 2018-12-12
Sinumerik 808d V4.7 Firmware CRITICAL 9.8
CVE-2018-11462

A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4…

Fix: after 4.8
Fix from $2,300 2018-12-12
Meraki Mr 24 Firmware MEDIUM 6.5
CVE-2018-0284

A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote …

Fix: 9.37 / 10.20+
Fix from $1,600 2018-11-08
Openstack MEDIUM 5.5
CVE-2016-2121

A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat…

Mitigation only
Fix from $1,600 2018-10-31
Open Real Time Bidding HIGH 7.5
CVE-2015-7266

The Interactive Advertising Bureau (IAB) OpenRTB 2.3 protocol implementation might allow remote attackers to conceal the status of ad transactions an…

No fix yet
Fix from $1,950 2018-10-30
Enterprise Linux HIGH 7.8
CVE-2016-10730

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Applicatio…

No fix yet
Fix from $1,950 2018-10-24
Wireless Lan Controller Software HIGH 7.8
CVE-2018-0417

A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform ce…

Fix: 8.2.170.0 / 8.5.131.0+
Fix from $1,950 2018-10-17
Rox Ii Firmware HIGH 7.2
CVE-2018-13802

A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged user account access via SSH …

Fix: 2.12.1+
Fix from $1,950 2018-10-10
Rox Ii Firmware HIGH 8.8
CVE-2018-13801

A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp and valid low-privileged user …

Fix: 2.12.1+
Fix from $1,950 2018-10-10
Ios Rom Monitor MEDIUM 6.8
CVE-2018-15370

A vulnerability in Cisco IOS ROM Monitor (ROMMON) Software for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, local attacker to …

Mitigation only
Fix from $1,600 2018-10-05
Network Services Orchestrator HIGH 7.5
CVE-2018-0463

A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remo…

Mitigation only
Fix from $1,950 2018-10-05
Secure Firewall Threat Defense HIGH 8.2
CVE-2018-0453

A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) …

Mitigation only
Fix from $1,950 2018-10-05
Umbrella Enterprise Roaming Client HIGH 7.8
CVE-2018-0437

A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administr…

Fix: 2.1.118 / 4.6.1098+
Fix from $1,950 2018-10-05
Data Center Network Manager HIGH 7.2
CVE-2018-0440

A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application administrator to execute commands …

Fix: 11.0+
Fix from $1,950 2018-10-05
Vedge 100 Firmware HIGH 8.8
CVE-2018-0432

A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges…

Fix: 18.3.0+
Fix from $1,950 2018-10-05
Gitolite CRITICAL 9.8
CVE-2013-4451

gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating…

Fix: after 3.5.3
Fix from $2,300 2018-09-21
Ansible Tower HIGH 8.0
CVE-2016-7070

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus…

Fix: 3.0.3+
Fix from $1,950 2018-09-11
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8657

It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuratio…

Mitigation only
Fix from $1,950 2018-07-31
Finesse CRITICAL 9.8
CVE-2018-0398

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-s…

Mitigation only
Fix from $2,300 2018-07-18
Finesse CRITICAL 9.8
CVE-2018-0399

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a clearte…

Mitigation only
Fix from $2,300 2018-07-18
Debian Linux MEDIUM 5.5
CVE-2014-2079

X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to …

Patch available
Fix from $1,600 2018-07-16
Hot X507 Firmware HIGH 8.1
CVE-2016-6564

Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple …

No fix yet
Fix from $1,950 2018-07-13
Secureconnector HIGH 7.8
CVE-2016-9485

On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full func…

Mitigation only
Fix from $1,950 2018-07-13
Secureconnector HIGH 7.8
CVE-2016-9486

On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full func…

Mitigation only
Fix from $1,950 2018-07-13
Manageengine Applications Manager HIGH 8.8
CVE-2016-9489

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own …

Mitigation only
Fix from $1,950 2018-07-13
Nx Os HIGH 8.8
CVE-2018-0293

A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands th…

Fix: 7.0 / 7.3+
Fix from $1,950 2018-06-20
Nx Os MEDIUM 6.7
CVE-2018-0294

A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure …

Fix: 2.0.1.159 / 2.1.1.86+
Fix from $1,600 2018-06-20
Nx Os HIGH 8.8
CVE-2018-0330

A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an…

Fix: 7.0 / 7.3+
Fix from $1,950 2018-06-20