Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Tizen HIGH 8.8
CVE-2018-16263

The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy config…

Mitigation only
Fix from $1,950 2020-01-22
Tizen MEDIUM 6.5
CVE-2018-16265

The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, du…

Mitigation only
Fix from $1,600 2020-01-22
Tizen HIGH 8.1
CVE-2018-16266

The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy c…

Mitigation only
Fix from $1,950 2020-01-22
Tizen HIGH 8.1
CVE-2018-16267

The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security polic…

Mitigation only
Fix from $1,950 2020-01-22
Wp Database Reset HIGH 8.8
CVE-2020-7047

The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a …

Fix: after 3.1
Fix from $1,950 2020-01-16
Sinema Server CRITICAL 9.9
CVE-2019-10940

A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a…

Fix: 14.0+
Fix from $2,300 2020-01-16
Bitbucket HIGH 8.8
CVE-2019-15012

Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from…

Fix: 5.6.11 / 6.0.11+
Fix from $1,950 2020-01-15
Junos HIGH 7.8
CVE-2014-6448

Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restrictions and execute arbitrary…

Mitigation only
Fix from $1,950 2020-01-15
Remedy Ar System Server MEDIUM 6.5
CVE-2015-5071

AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate"…

No fix yet
Fix from $1,600 2020-01-15
Remedy Ar System Server MEDIUM 6.5
CVE-2015-5072

The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navi…

No fix yet
Fix from $1,600 2020-01-15
Xgi Vga Display Manager HIGH 7.8
CVE-2015-5466

Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain…

No fix yet
Fix from $1,950 2020-01-15
Delegate HIGH 7.8
CVE-2015-7556

DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.

No fix yet
Fix from $1,950 2020-01-15
Joomla\! HIGH 7.5
CVE-2012-1563EPSS 9%

Joomla! before 2.5.3 allows Admin Account Creation.

Fix: 2.5.3+
Fix from $1,950 2020-01-15
Windows 10 HIGH 7.8
CVE-2020-0635

An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevat…

Patch available
Fix from $1,950 2020-01-14
Data Protector Agent HIGH 7.8
CVE-2012-4760

A Privilege Escalation vulnerability exists in the SDBagent service in Safend Data Protector Agent 3.4.5586.9772, which could let a local malicious u…

No fix yet
Fix from $1,950 2020-01-13
Data Protector Agent HIGH 7.8
CVE-2012-4761

A Privilege Escalation vulnerability exists in the unquoted Service Binary in SDPAgent or SDBAgent in Safend Data Protector Agent 3.4.5586.9772, whic…

No fix yet
Fix from $1,950 2020-01-13
Debian Linux HIGH 7.5
CVE-2019-19728

SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.

Fix: 18.08.9 / 19.05.5+
Fix from $1,950 2020-01-13
Hashbrown Cms HIGH 8.8
CVE-2020-6949

A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of a…

Fix: after 1.3.3
Fix from $1,950 2020-01-13
Data Protector Agent MEDIUM 6.1
CVE-2012-4767

An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, which could let a malicious us…

No fix yet
Fix from $1,600 2020-01-13
Spagobi HIGH 8.8
CVE-2013-6231EPSS 10%

SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script

Fix: 4.1+
Fix from $1,950 2020-01-10
Ca Automic Dollar Universe HIGH 7.8
CVE-2019-19544

CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate p…

No fix yet
Fix from $1,950 2020-01-08
Encryption Desktop HIGH 7.8
CVE-2016-6590

A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suit…

Fix: 7.6 / 10.4.1+
Fix from $1,950 2020-01-08
Openshift Container Platform HIGH 8.8
CVE-2019-14819

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to…

No fix yet
Fix from $1,950 2020-01-07
Rconfig HIGH 7.8
CVE-2019-19585EPSS 6%

An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apa…

No fix yet
Fix from $1,950 2020-01-06
Fedora HIGH 7.8
CVE-2013-4161

gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security iss…

Mitigation only
Fix from $1,950 2019-12-31
Sonicos HIGH 7.2
CVE-2019-7479

A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen…

Fix: after 5.9.1.12-4o
Fix from $1,950 2019-12-31
Textproc\/isearch HIGH 7.5
CVE-2012-5663

The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area…

Fix: 1.47.01nb1+
Fix from $1,950 2019-12-30
Debian Linux HIGH 7.8
CVE-2013-2016

A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the vi…

Fix: after 1.4.2
Fix from $1,950 2019-12-30
Dl4343 Firmware HIGH 8.8
CVE-2019-20074

On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.

Mitigation only
Fix from $1,950 2019-12-30
Collabtive CRITICAL 9.8
CVE-2013-5027

Collabtive 1.0 has incorrect access control

No fix yet
Fix from $2,300 2019-12-27