Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
CRITICAL 9.8 CVE-2018-5472 Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unau… Intellispace Portal Mitigation only Fix from $2,3002018-03-26 HIGH 7.8 CVE-2014-5443 Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling u… Seafile Server 3.1.0 / 3.1.2+ Fix from $1,9502018-03-19 HIGH 7.8 CVE-2015-7440 IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15,… Rational Collaborative Lifecycle Management after 6.0.1 Fix from $1,9502018-03-15 CRITICAL 9.8 CVE-2018-7500 A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, gi… Pi Web Api after 2017 Fix from $2,3002018-03-14 MEDIUM 6.5 CVE-2016-8629 Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest serve… Keycloak 2.4.0+ Fix from $1,6002018-03-12 HIGH 7.8 CVE-2014-7272 Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations… Fedora 0.10.0+ Fix from $1,9502018-03-08 HIGH 8.8 CVE-2018-0213 A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain … Identity Services Engine Mitigation only Fix from $1,9502018-03-08 HIGH 7.8 CVE-2015-7596 SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation directories and executable modules, w… Safenet Authentication Service End User Software Tools For Windows Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7597 SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to… Safenet Authentication Service Iis Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7598 SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allo… Safenet Authentication Service Tokenvalidator Proxy Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7961 SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allo… Safenet Authentication Service Remote Web Workplace Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7962 SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allow… Safenet Authentication Service For Outlook Web App Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7963 SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local us… Safenet Authentication Service For Ad Fs Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7964 SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local user… Safenet Authentication Service For Nps Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7965 SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows loca… Safenet Authentication Service Windows Logon Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7966 SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows loca… Safenet Authentication Service Windows Logon Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2015-7967 SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which … Safenet Authentication Service For Citrix Web Interface Agent Patch available Fix from $1,9502018-03-02 HIGH 7.8 CVE-2014-10070 zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numb… Zsh after 5.0.6 Fix from $1,9502018-02-27 CRITICAL 9.8 CVE-2018-0130 A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenti… Virtual Managed Services Mitigation only Fix from $2,3002018-02-22 HIGH 8.8 CVE-2013-0267 The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user… Vcl 2.3.2+ Fix from $1,9502018-02-21 HIGH 8.8 CVE-2016-8528 A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found. Eucalyptus after 4.3.1 Fix from $1,9502018-02-15 HIGH 8.8 CVE-2016-8533 A remote priviledge escalation vulnerability in HPE Matrix Operating Environment version 7.6 was found. Matrix Operating Environment No fix yet Fix from $1,9502018-02-15 HIGH 8.8 CVE-2016-8534 A remote privilege elevation vulnerability in HPE Matrix Operating Environment version 7.6 was found. Matrix Operating Environment No fix yet Fix from $1,9502018-02-15 HIGH 7.8 CVE-2016-8742 The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p… Couchdb No fix yet Fix from $1,9502018-02-12 HIGH 7.8 CVE-2015-1416 Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch befo… FreeBSD Mitigation only Fix from $1,9502018-02-05 MEDIUM 6.7 CVE-2014-3752 The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights to execute arbitrary code wi… Totalprotection after 24.0.2.1 Fix from $1,6002018-02-01 MEDIUM 6.5 CVE-2014-9503 The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permi… Open Atrium 7.x-2.26+ Fix from $1,6002018-02-01 MEDIUM 5.4 CVE-2014-4919 OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition … Eshop 4.7.13 / 4.8.7+ Fix from $1,6002018-01-19 HIGH 7.5 CVE-2018-0089 A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to a… Policy Suite Mitigation only Fix from $1,9502018-01-18 HIGH 7.1 CVE-2018-0092 A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software could allow an authenticated, local attacker to impr… Nx Os Mitigation only Fix from $1,9502018-01-18