Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.8 CVE-2019-1646 A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device c… Vedge 100 Firmware 18.4.0+ Fix from $1,9502019-01-24 HIGH 7.8 CVE-2019-1648 A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges… Vedge 100 Firmware 18.4.0+ Fix from $1,9502019-01-24 MEDIUM 6.6 CVE-2018-11461 A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4… Sinumerik 808d V4.7 Firmware after 4.8 Fix from $1,6002018-12-12 CRITICAL 9.8 CVE-2018-11462 A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4… Sinumerik 808d V4.7 Firmware after 4.8 Fix from $2,3002018-12-12 MEDIUM 6.5 CVE-2018-0284 A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote … Meraki Mr 24 Firmware 9.37 / 10.20+ Fix from $1,6002018-11-08 MEDIUM 5.5 CVE-2016-2121 A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat… Openstack Mitigation only Fix from $1,6002018-10-31 HIGH 7.5 CVE-2015-7266 The Interactive Advertising Bureau (IAB) OpenRTB 2.3 protocol implementation might allow remote attackers to conceal the status of ad transactions an… Open Real Time Bidding No fix yet Fix from $1,9502018-10-30 HIGH 7.8 CVE-2016-10730 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Applicatio… Enterprise Linux No fix yet Fix from $1,9502018-10-24 HIGH 7.8 CVE-2018-0417 A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform ce… Wireless Lan Controller Software 8.2.170.0 / 8.5.131.0+ Fix from $1,9502018-10-17 HIGH 7.2 CVE-2018-13802 A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged user account access via SSH … Rox Ii Firmware 2.12.1+ Fix from $1,9502018-10-10 HIGH 8.8 CVE-2018-13801 A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp and valid low-privileged user … Rox Ii Firmware 2.12.1+ Fix from $1,9502018-10-10 MEDIUM 6.8 CVE-2018-15370 A vulnerability in Cisco IOS ROM Monitor (ROMMON) Software for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, local attacker to … Ios Rom Monitor Mitigation only Fix from $1,6002018-10-05 HIGH 7.5 CVE-2018-0463 A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remo… Network Services Orchestrator Mitigation only Fix from $1,9502018-10-05 HIGH 8.2 CVE-2018-0453 A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) … Secure Firewall Threat Defense Mitigation only Fix from $1,9502018-10-05 HIGH 7.8 CVE-2018-0437 A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administr… Umbrella Enterprise Roaming Client 2.1.118 / 4.6.1098+ Fix from $1,9502018-10-05 HIGH 7.2 CVE-2018-0440 A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application administrator to execute commands … Data Center Network Manager 11.0+ Fix from $1,9502018-10-05 HIGH 8.8 CVE-2018-0432 A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges… Vedge 100 Firmware 18.3.0+ Fix from $1,9502018-10-05 CRITICAL 9.8 CVE-2013-4451 gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating… Gitolite after 3.5.3 Fix from $2,3002018-09-21 HIGH 8.0 CVE-2016-7070 A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus… Ansible Tower 3.0.3+ Fix from $1,9502018-09-11 HIGH 7.8 CVE-2016-8657 It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuratio… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502018-07-31 CRITICAL 9.8 CVE-2018-0398 Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-s… Finesse Mitigation only Fix from $2,3002018-07-18 CRITICAL 9.8 CVE-2018-0399 Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to retrieve a clearte… Finesse Mitigation only Fix from $2,3002018-07-18 MEDIUM 5.5 CVE-2014-2079 X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to … Debian Linux Patch available Fix from $1,6002018-07-16 HIGH 8.1 CVE-2016-6564 Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple … Hot X507 Firmware No fix yet Fix from $1,9502018-07-13 HIGH 7.8 CVE-2016-9485 On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full func… Secureconnector Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2016-9486 On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full func… Secureconnector Mitigation only Fix from $1,9502018-07-13 HIGH 8.8 CVE-2016-9489 In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own … Manageengine Applications Manager Mitigation only Fix from $1,9502018-07-13 HIGH 8.8 CVE-2018-0293 A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands th… Nx Os 7.0 / 7.3+ Fix from $1,9502018-06-20 MEDIUM 6.7 CVE-2018-0294 A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure … Nx Os 2.0.1.159 / 2.1.1.86+ Fix from $1,6002018-06-20 HIGH 8.8 CVE-2018-0330 A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an… Nx Os 7.0 / 7.3+ Fix from $1,9502018-06-20