Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Openshift Container Platform HIGH 7.8
CVE-2019-19354

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attac…

Fix: 4.4.3+
Fix from $1,950 2021-03-24
Openshift HIGH 7.8
CVE-2019-19349

An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat …

No fix yet
Fix from $1,950 2021-03-24
Openshift HIGH 7.8
CVE-2019-19350

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 an…

No fix yet
Fix from $1,950 2021-03-24
Identity Services Engine MEDIUM 6.5
CVE-2021-1412

Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitiv…

Fix: 2.3.0+
Fix from $1,600 2021-02-17
Catalyst Center HIGH 8.8
CVE-2021-1303

A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an…

Fix: 2.1.2.0+
Fix from $1,950 2021-01-20
Identity Services Engine MEDIUM 6.7
CVE-2020-27122

A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to…

Fix: 3.0.0+
Fix from $1,600 2020-11-06
Emc Networker MEDIUM 6.5
CVE-2020-26182

Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may…

Fix: 19.3.0.2+
Fix from $1,600 2020-10-16
Application And Change Control HIGH 8.2
CVE-2020-7334

Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators …

Fix: 8.3.2+
Fix from $1,950 2020-10-15
Enterprise Search HIGH 8.8
CVE-2020-7018

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, t…

Fix: 7.9.0+
Fix from $1,950 2020-08-18
Elasticsearch HIGH 8.8
CVE-2020-7014

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation fl…

Fix: after 7.6.1
Fix from $1,950 2020-06-03
Intelligent Power Manager HIGH 7.8
CVE-2020-6652

Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system conf…

Fix: after 1.67
Fix from $1,950 2020-05-07
Globalprotect HIGH 7.8
CVE-2020-1989

An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on A…

Fix: 5.0.8 / 5.1.1+
Fix from $1,950 2020-04-08
Openshift HIGH 7.0
CVE-2019-19346

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the follow…

Fix: 3.11.188-4 / 4.1.37+
Fix from $1,950 2020-04-02
Openshift HIGH 7.0
CVE-2019-19348

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following…

Fix: 3.11.188-4 / 4.1.37+
Fix from $1,950 2020-04-02
Elasticsearch HIGH 8.8
CVE-2020-7009

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. …

Fix: 6.8.8 / 7.6.2+
Fix from $1,950 2020-03-31
Openshift HIGH 7.8
CVE-2019-19345

A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pass…

Fix: 4.3+
Fix from $1,950 2020-03-20
Template Service Broker Operator HIGH 7.0
CVE-2020-1705

A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerab…

Fix: 4.3.0+
Fix from $1,950 2020-03-19
Openshift HIGH 7.0
CVE-2019-19351

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container…

Mitigation only
Fix from $1,950 2020-03-18
Openshift HIGH 7.0
CVE-2019-19355

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the co…

Mitigation only
Fix from $1,950 2020-03-18
Openshift Service Mesh HIGH 7.8
CVE-2020-1704

An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens…

Fix: 1.0.8+
Fix from $1,950 2020-02-17
Openshift Container Platform HIGH 7.0
CVE-2020-1708

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod…

Mitigation only
Fix from $1,950 2020-02-07
Sinema Server CRITICAL 9.9
CVE-2019-10940

A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a…

Fix: 14.0+
Fix from $2,300 2020-01-16
Openshift Container Platform HIGH 8.8
CVE-2019-14819

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to…

No fix yet
Fix from $1,950 2020-01-07
Smart Home Controller Firmware HIGH 8.0
CVE-2019-11891

A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 …

Fix: 9.8.905+
Fix from $1,950 2019-05-29
Smart Home Controller Firmware HIGH 8.0
CVE-2019-11893

A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.…

Fix: 9.8.905+
Fix from $1,950 2019-05-29
Fedora HIGH 7.0
CVE-2019-10143

It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has con…

Fix: after 3.0.19
Fix from $1,950 2019-05-24
Fedora HIGH 7.8
CVE-2019-3843

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient s…

Fix: 242+
Fix from $1,950 2019-04-26
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-7066

It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local u…

Fix: 7.1.0+
Fix from $1,950 2018-09-11
Ansible Tower HIGH 8.0
CVE-2016-7070

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus…

Fix: 3.0.3+
Fix from $1,950 2018-09-11
Ansible Tower HIGH 7.2
CVE-2018-1101

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. Syste…

Fix: 3.2.4+
Fix from $1,950 2018-05-02