Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
HIGH 7.8 CVE-2019-19354 An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attac… Openshift Container Platform 4.4.3+ Fix from $1,9502021-03-24 HIGH 7.8 CVE-2019-19349 An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat … Openshift No fix yet Fix from $1,9502021-03-24 HIGH 7.8 CVE-2019-19350 An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 an… Openshift No fix yet Fix from $1,9502021-03-24 MEDIUM 6.5 CVE-2021-1412 Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitiv… Identity Services Engine 2.3.0+ Fix from $1,6002021-02-17 HIGH 8.8 CVE-2021-1303 A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an… Catalyst Center 2.1.2.0+ Fix from $1,9502021-01-20 MEDIUM 6.7 CVE-2020-27122 A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to… Identity Services Engine 3.0.0+ Fix from $1,6002020-11-06 MEDIUM 6.5 CVE-2020-26182 Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may… Emc Networker 19.3.0.2+ Fix from $1,6002020-10-16 HIGH 8.2 CVE-2020-7334 Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators … Application And Change Control 8.3.2+ Fix from $1,9502020-10-15 HIGH 8.8 CVE-2020-7018 Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, t… Enterprise Search 7.9.0+ Fix from $1,9502020-08-18 HIGH 8.8 CVE-2020-7014 The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation fl… Elasticsearch after 7.6.1 Fix from $1,9502020-06-03 HIGH 7.8 CVE-2020-6652 Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin users to upload the system conf… Intelligent Power Manager after 1.67 Fix from $1,9502020-05-07 HIGH 7.8 CVE-2020-1989 An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on A… Globalprotect 5.0.8 / 5.1.1+ Fix from $1,9502020-04-08 HIGH 7.0 CVE-2019-19346 An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the follow… Openshift 3.11.188-4 / 4.1.37+ Fix from $1,9502020-04-02 HIGH 7.0 CVE-2019-19348 An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following… Openshift 3.11.188-4 / 4.1.37+ Fix from $1,9502020-04-02 HIGH 8.8 CVE-2020-7009 Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. … Elasticsearch 6.8.8 / 7.6.2+ Fix from $1,9502020-03-31 HIGH 7.8 CVE-2019-19345 A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pass… Openshift 4.3+ Fix from $1,9502020-03-20 HIGH 7.0 CVE-2020-1705 A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerab… Template Service Broker Operator 4.3.0+ Fix from $1,9502020-03-19 HIGH 7.0 CVE-2019-19351 An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container… Openshift Mitigation only Fix from $1,9502020-03-18 HIGH 7.0 CVE-2019-19355 An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the co… Openshift Mitigation only Fix from $1,9502020-03-18 HIGH 7.8 CVE-2020-1704 An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens… Openshift Service Mesh 1.0.8+ Fix from $1,9502020-02-17 HIGH 7.0 CVE-2020-1708 It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod… Openshift Container Platform Mitigation only Fix from $1,9502020-02-07 CRITICAL 9.9 CVE-2019-10940 A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a… Sinema Server 14.0+ Fix from $2,3002020-01-16 HIGH 8.8 CVE-2019-14819 A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to… Openshift Container Platform No fix yet Fix from $1,9502020-01-07 HIGH 8.0 CVE-2019-11891 A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 … Smart Home Controller Firmware 9.8.905+ Fix from $1,9502019-05-29 HIGH 8.0 CVE-2019-11893 A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.… Smart Home Controller Firmware 9.8.905+ Fix from $1,9502019-05-29 HIGH 7.0 CVE-2019-10143 It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has con… Fedora after 3.0.19 Fix from $1,9502019-05-24 HIGH 7.8 CVE-2019-3843 It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient s… Fedora 242+ Fix from $1,9502019-04-26 HIGH 7.8 CVE-2016-7066 It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local u… Jboss Enterprise Application Platform 7.1.0+ Fix from $1,9502018-09-11 HIGH 8.0 CVE-2016-7070 A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus… Ansible Tower 3.0.3+ Fix from $1,9502018-09-11 HIGH 7.2 CVE-2018-1101 Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. Syste… Ansible Tower 3.2.4+ Fix from $1,9502018-05-02