Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.8 CVE-2018-0095 A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) … Asyncos Mitigation only Fix from $1,9502018-01-18 MEDIUM 5.9 CVE-2018-0096 A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to … Prime Infrastructure Mitigation only Fix from $1,6002018-01-18 HIGH 7.8 CVE-2016-0327 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator p… Security Identity Manager Virtual Appliance Patch available Fix from $1,9502018-01-12 HIGH 8.8 CVE-2014-0087 The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), al… Cloudforms Management Engine 5.3+ Fix from $1,9502018-01-11 HIGH 8.8 CVE-2014-5070 Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenticated users to the login page. S350i Firmware No fix yet Fix from $1,9502018-01-11 HIGH 7.1 CVE-2014-2071 Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunnele… Clearpass 6.2.5.61640 / 6.3.0.61712+ Fix from $1,9502018-01-08 MEDIUM 6.5 CVE-2014-8540 The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging impro… GitLab 7.4.3+ Fix from $1,6002018-01-05 CRITICAL 9.8 CVE-2014-7862EPSS 81% The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrat… Desktop Central 90109+ Fix from $2,3002018-01-04 MEDIUM 5.3 CVE-2017-12363 A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affect… Webex Meetings Server Mitigation only Fix from $1,6002017-11-30 MEDIUM 6.8 CVE-2017-12342 A vulnerability in the Open Agent Container (OAC) feature of Cisco Nexus Series Switches could allow an unauthenticated, local attacker to read and s… Nx Os Mitigation only Fix from $1,6002017-11-30 MEDIUM 5.7 CVE-2017-12351 A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outsi… Nx Os Mitigation only Fix from $1,6002017-11-30 HIGH 8.8 CVE-2016-10700 auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging i… Cacti 1.0.0+ Fix from $1,9502017-11-24 HIGH 7.8 CVE-2016-6804 The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that a… Openoffice 4.1.3+ Fix from $1,9502017-11-20 HIGH 7.8 CVE-2017-12261 A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local at… Identity Services Engine Mitigation only Fix from $1,9502017-11-02 CRITICAL 9.8 CVE-2014-0073EPSS 8% The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap… Cordova In App Browser after 2.9.0 Fix from $2,3002017-10-30 HIGH 7.8 CVE-2015-5699 The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute arbitrary commands via shell m… Cumulus Linux after 2.5.3 Fix from $1,9502017-10-22 CRITICAL 9.9 CVE-2017-12251 A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciou… Cloud Services Platform 2100 Mitigation only Fix from $2,3002017-10-19 MEDIUM 5.9 CVE-2015-3229 fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora A… Spin Kickstarts Patch available Fix from $1,6002017-10-16 CRITICAL 9.8 CVE-2015-4650EPSS 6% Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code w… Clearpass Policy Manager after 6.4.6 Fix from $2,3002017-10-16 HIGH 7.5 CVE-2014-7851 oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowle… Ovirt Engine Mitigation only Fix from $1,9502017-10-16 HIGH 7.8 CVE-2015-5675 The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial of service (kernel panic). FreeBSD No fix yet Fix from $1,9502017-10-10 HIGH 8.8 CVE-2015-2673EPSS 19% The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0… Wp Easycart No fix yet Fix from $1,9502017-10-06 MEDIUM 6.5 CVE-2017-12268 A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable… Anyconnect Secure Mobility Client Mitigation only Fix from $1,6002017-10-05 MEDIUM 6.7 CVE-2015-3321 Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain pri… Fingerprint Manager after 8.01.41 Fix from $1,6002017-10-03 HIGH 7.8 CVE-2015-7358 The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not pro… Ciphershed after 1.14 Fix from $1,9502017-10-03 HIGH 7.8 CVE-2015-7359 The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when runni… Ciphershed after 1.14 Fix from $1,9502017-10-03 MEDIUM 6.8 CVE-2017-12239 A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband… Ios Xe Mitigation only Fix from $1,6002017-09-29 HIGH 8.8 CVE-2017-12226 A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Super… Ios Xe Mitigation only Fix from $1,9502017-09-29 HIGH 8.8 CVE-2017-12230 A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileg… Ios Xe Mitigation only Fix from $1,9502017-09-29 HIGH 7.8 CVE-2015-3643 usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and b… Usb Creator after 0.2.67 Fix from $1,9502017-09-28