Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Centreon HIGH 7.2
CVE-2019-19699EPSS 28%

There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to sy…

Fix: after 19.10
Fix from $1,950 2020-04-06
Openstack Cloud HIGH 7.8
CVE-2018-17954

An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8…

Mitigation only
Fix from $1,950 2020-04-03
Openshift HIGH 7.0
CVE-2019-19346

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the follow…

Fix: 3.11.188-4 / 4.1.37+
Fix from $1,950 2020-04-02
Openshift HIGH 7.0
CVE-2019-19348

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following…

Fix: 3.11.188-4 / 4.1.37+
Fix from $1,950 2020-04-02
Elasticsearch HIGH 8.8
CVE-2020-7009

Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. …

Fix: 6.8.8 / 7.6.2+
Fix from $1,950 2020-03-31
Debian Linux HIGH 7.8
CVE-2020-5291

Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2`…

Fix: 0.4.1+
Fix from $1,950 2020-03-31
Portico Server 1 Client HIGH 7.8
CVE-2020-10940

Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.

Fix: after 3.0.7
Fix from $1,950 2020-03-27
System Update HIGH 7.8
CVE-2015-7333

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed an…

Fix: after 5.07.0008
Fix from $1,950 2020-03-27
System Update HIGH 7.8
CVE-2015-7334

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed an…

Fix: after 5.07.0008
Fix from $1,950 2020-03-27
Solution Center HIGH 7.8
CVE-2015-8534

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed …

Fix: 3.3.002+
Fix from $1,950 2020-03-27
Parallels Desktop MEDIUM 6.7
CVE-2020-8873

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first …

Fix: 15.1.3+
Fix from $1,600 2020-03-23
Codeigniter HIGH 8.8
CVE-2020-10793

CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contribut…

Fix: after 4.0.0
Fix from $1,950 2020-03-23
Openshift HIGH 7.8
CVE-2019-19345

A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pass…

Fix: 4.3+
Fix from $1,950 2020-03-20
Enigma Nms HIGH 8.8
CVE-2019-16071

Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settings in the …

Fix: after 65.0.0
Fix from $1,950 2020-03-20
Sd Wan Firmware HIGH 7.8
CVE-2020-3265

A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to root on the underlying operat…

Fix: 18.4.5 / 19.2.2+
Fix from $1,950 2020-03-19
Openshift HIGH 7.0
CVE-2019-19351

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container…

Mitigation only
Fix from $1,950 2020-03-18
Openshift HIGH 7.0
CVE-2019-19355

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the co…

Mitigation only
Fix from $1,950 2020-03-18
Fusion HIGH 7.8
CVE-2020-3950 KEVEPSS 7%

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4…

Fix: 5.4.0 / 11.0.1+
Fix from $1,950 2020-03-17
Learnpress MEDIUM 6.5
CVE-2020-7916

be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teac…

Fix: after 3.2.6.5
Fix from $1,600 2020-03-16
Nagios MEDIUM 6.5
CVE-2020-6584

Nagios Log Server 2.1.3 has Incorrect Access Control.

No fix yet
Fix from $1,600 2020-03-16
V2rayl HIGH 7.8
CVE-2020-10588

v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but ex…

No fix yet
Fix from $1,950 2020-03-15
V2rayl HIGH 7.8
CVE-2020-10589

v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user but contains commands that a…

No fix yet
Fix from $1,950 2020-03-15
GitLab HIGH 8.1
CVE-2020-10088

GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incor…

Fix: after 12.8.1
Fix from $1,950 2020-03-13
Windows 10 HIGH 7.1
CVE-2020-0785

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile…

Patch available
Fix from $1,950 2020-03-12
Windows 10 HIGH 7.8
CVE-2020-0799

An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic link…

Patch available
Fix from $1,950 2020-03-12
Advanced Threat Defense HIGH 7.8
CVE-2020-7254

Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to exe…

Fix: 4.8.2+
Fix from $1,950 2020-03-12
Nethack CRITICAL 9.8
CVE-2020-5253

NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited.…

Fix: 3.6.0+
Fix from $2,300 2020-03-10
GitLab CRITICAL 9.8
CVE-2020-8113

GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

Fix: 12.6.8+
Fix from $2,300 2020-03-06
Valvelink HIGH 7.8
CVE-2020-6971

In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate p…

Fix: after 13.4.118
Fix from $1,950 2020-03-05
Timemoto Tm 616 Firmware HIGH 7.5
CVE-2019-12183

Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.

No fix yet
Fix from $1,950 2020-03-02