Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.5 CVE-2019-13014 Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged … Little Snitch Mitigation only Fix from $1,6002019-08-23 MEDIUM 5.3 CVE-2016-10929 The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in. Advanced Ajax Page Loader 2.7.7+ Fix from $1,6002019-08-22 HIGH 7.5 CVE-2017-18584 The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action. Post Pay Counter 2.731+ Fix from $1,9502019-08-22 CRITICAL 9.8 CVE-2016-10922 The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation. Store Toolkit For Woocommerce 1.5.7+ Fix from $2,3002019-08-22 CRITICAL 9.8 CVE-2016-10923 The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation. Store Toolkit For Woocommerce 1.5.8+ Fix from $2,3002019-08-22 HIGH 7.5 CVE-2019-12634 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS D… Integrated Management Controller Supervisor after 6.7.2.0 Fix from $1,9502019-08-21 HIGH 7.8 CVE-2019-14257 pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka Z… Zenoss No fix yet Fix from $1,9502019-08-21 HIGH 7.3 CVE-2019-2122 In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the default case between the Win… Android Mitigation only Fix from $1,9502019-08-20 MEDIUM 6.7 CVE-2019-3637 Privilege Escalation vulnerability in McAfee FRP 5.x prior to 5.1.0.209 allows local users to gain elevated privileges via running McAfee Tray with e… File And Removable Media Protection 5.1.0.209+ Fix from $1,6002019-08-14 CRITICAL 9.8 CVE-2016-10886 The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. Wp Editor 1.2.6+ Fix from $2,3002019-08-14 HIGH 7.8 CVE-2019-12808 ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can over… Altools after 18.1 Fix from $1,9502019-08-13 MEDIUM 6.7 CVE-2019-1972 A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, local attacker with valid admin… Enterprise Network Function Virtualization Infrastructure after 3.10.3 Fix from $1,6002019-08-08 MEDIUM 5.3 CVE-2017-18451 cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257). Cpanel 56.0.49 / 58.0.49+ Fix from $1,6002019-08-02 HIGH 7.8 CVE-2017-18413 In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299). Cpanel 56.0.52 / 60.0.48+ Fix from $1,9502019-08-02 HIGH 7.8 CVE-2017-18383 cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309). Cpanel 62.0.35 / 64.0.42+ Fix from $1,9502019-08-02 HIGH 7.8 CVE-2019-11771 AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users. Openj9 0.15.0+ Fix from $1,9502019-07-17 HIGH 7.2 CVE-2019-1889 A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an a… Application Policy Infrastructure Controller Mitigation only Fix from $1,9502019-07-04 HIGH 7.3 CVE-2019-1855 A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker … Jabber 12.6+ Fix from $1,9502019-07-04 HIGH 8.8 CVE-2017-8228 Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough ve… Ipm 721s Firmware after 2.420.ac00.16.r.20160909 Fix from $1,9502019-07-03 HIGH 8.8 CVE-2017-8230 On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of se… Ipm 721s Firmware after 2.420.ac00.16.r.20160909 Fix from $1,9502019-07-03 HIGH 7.8 CVE-2019-13125 HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation. Habomalhunter after 2.0.0.3 Fix from $1,9502019-07-01 CRITICAL 9.8 CVE-2019-1620EPSS 84% A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to … Data Center Network Manager No fix yet Fix from $2,3002019-06-27 HIGH 7.5 CVE-2019-1621EPSS 30% A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to … Data Center Network Manager No fix yet Fix from $1,9502019-06-27 MEDIUM 6.5 CVE-2019-1906 A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual d… Prime Infrastructure Mitigation only Fix from $1,6002019-06-20 HIGH 7.8 CVE-2019-1625 A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level privileges to the root user o… Sd Wan Firmware 18.3.6+ Fix from $1,9502019-06-20 HIGH 8.8 CVE-2019-1626 A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated priv… Sd Wan Firmware after 18.3.6 Fix from $1,9502019-06-20 HIGH 8.8 CVE-2019-2003 In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirecti… Android Mitigation only Fix from $1,9502019-06-19 MEDIUM 6.7 CVE-2018-10239 A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administr… Nios after 8.4.1 Fix from $1,6002019-06-17 HIGH 7.8 CVE-2019-0128 Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated u… Chipset Device Software 10.1.1.45+ Fix from $1,9502019-06-13 HIGH 7.3 CVE-2019-0164 Improper permissions in the installer for Intel(R) Turbo Boost Max Technology 3.0 driver version 1.0.0.1035 and before may allow an authenticated use… Turbo Boost Max Technology 3.0 after 1.0.0.1035 Fix from $1,9502019-06-13