Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 8.0 CVE-2019-18945 Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability. Solutions Business Manager 11.7.1+ Fix from $1,9502021-02-26 MEDIUM 5.5 CVE-2021-1258 A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges … Anyconnect Secure Mobility Client 4.9.03047 / 4.9.03049+ Fix from $1,6002021-01-13 MEDIUM 6.5 CVE-2020-13922 Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter… Dolphinscheduler Mitigation only Fix from $1,6002021-01-11 CRITICAL 9.1 CVE-2020-3426 A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated S… iOS Mitigation only Fix from $2,3002020-09-24 MEDIUM 6.8 CVE-2019-16017 A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP… Unified Customer Voice Portal 11.6 / 12.0+ Fix from $1,6002020-09-23 HIGH 7.8 CVE-2020-3473 A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to el… Ios Xr 6.5.29 / 6.6.3+ Fix from $1,9502020-09-04 HIGH 8.4 CVE-2020-3530 A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute … Ios Xr 7.1.2+ Fix from $1,9502020-09-04 HIGH 8.8 CVE-2020-3443 A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute… Smart Software Manager On Prem Mitigation only Fix from $1,9502020-08-26 MEDIUM 6.3 CVE-2020-3485 A vulnerability in the role-based access control (RBAC) functionality of the web management software of Cisco Vision Dynamic Signage Director could a… Vision Dynamic Signage Director Mitigation only Fix from $1,6002020-08-26 HIGH 8.8 CVE-2020-7352 The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embe… Galaxy after 2.0.12 Fix from $1,9502020-08-06 MEDIUM 6.8 CVE-2020-11933 cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker cou… Snapd 2.45.2+ Fix from $1,6002020-07-29 HIGH 8.1 CVE-2020-12028EPSS 53% In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the re… Factorytalk View No fix yet Fix from $1,9502020-07-20 HIGH 7.8 CVE-2020-3379 A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlyi… Sd Wan Firmware 18.3.0+ Fix from $1,9502020-07-16 HIGH 7.8 CVE-2020-3180 A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account tha… Sd Wan 18.3.6 / 18.4.5+ Fix from $1,9502020-07-16 CRITICAL 9.8 CVE-2020-3227 A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenti… Ios Xe Mitigation only Fix from $2,3002020-06-03 HIGH 8.8 CVE-2020-3229EPSS 5% A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remo… Ios Xe Patch available Fix from $1,9502020-06-03 MEDIUM 6.7 CVE-2020-3213 A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to those of the root user o… Ios Xe Patch available Fix from $1,6002020-06-03 MEDIUM 6.7 CVE-2020-3214 A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileg… Ios Xe Mitigation only Fix from $1,6002020-06-03 MEDIUM 6.7 CVE-2020-3215 A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges… Ios Xe No fix yet Fix from $1,6002020-06-03 MEDIUM 6.7 CVE-2020-3208 A vulnerability in the image verification feature of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs… iOS Patch available Fix from $1,6002020-06-03 HIGH 7.1 CVE-2019-19100 A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.4SP, … Automation Studio 4.3.11 / 4.4.9+ Fix from $1,9502020-04-29 HIGH 7.8 CVE-2020-8484 Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authent… 800xa Mitigation only Fix from $1,9502020-04-29 HIGH 7.8 CVE-2020-8485 Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker aut… 800xa Mitigation only Fix from $1,9502020-04-29 HIGH 7.8 CVE-2020-8486 Insufficient protection of the inter-process communication functions in ABB System 800xA RNRP (all published versions) enables an attacker authentica… 800xa Rnrp Mitigation only Fix from $1,9502020-04-29 HIGH 7.8 CVE-2020-8487 Insufficient protection of the inter-process communication functions in ABB System 800xA Base (all published versions) enables an attacker authentica… 800xa Base System Mitigation only Fix from $1,9502020-04-29 HIGH 7.8 CVE-2020-8488 Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacke… 800xa Batch Management No fix yet Fix from $1,9502020-04-29 HIGH 7.8 CVE-2020-8489 Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an a… 800xa Information Management Mitigation only Fix from $1,9502020-04-29 CRITICAL 9.1 CVE-2019-19106 Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to a… Tg\/s3.2 Firmware Mitigation only Fix from $2,3002020-04-22 MEDIUM 5.5 CVE-2019-19107 The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the passwo… Tg\/s3.2 Firmware Mitigation only Fix from $1,6002020-04-22 HIGH 7.8 CVE-2020-7259 Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to by… Endpoint Security Mitigation only Fix from $1,9502020-04-15