Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Debian Linux MEDIUM 6.7
CVE-2011-2910

The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping …

Fix: 0.0.8-13+
Fix from $1,600 2019-11-15
Gs1900 8 Firmware HIGH 8.8
CVE-2019-15799

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, w…

Fix: 2.50+
Fix from $1,950 2019-11-14
Graphics Driver MEDIUM 5.5
CVE-2019-14590

Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially ena…

Fix: 26.20.100.7209+
Fix from $1,600 2019-11-14
Advanced Threat Defense HIGH 8.8
CVE-2019-3651

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO …

Fix: 4.8+
Fix from $1,950 2019-11-13
Debian Linux HIGH 8.8
CVE-2010-4664

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their…

Fix: 0.4.2+
Fix from $1,950 2019-11-13
Android HIGH 7.8
CVE-2019-2193

In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lea…

Mitigation only
Fix from $1,950 2019-11-13
Windows 10 1507 HIGH 7.8
CVE-2019-1405 KEVEPSS 30%

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Wi…

Patch available
Fix from $1,950 2019-11-12
Windows 10 1507 HIGH 7.8
CVE-2019-1388 KEVEPSS 9%

An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Cert…

Patch available
Fix from $1,950 2019-11-12
Viper Rgb Firmware HIGH 7.1
CVE-2019-18845

The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbi…

Mitigation only
Fix from $1,950 2019-11-09
Energycap CRITICAL 9.8
CVE-2019-18623

Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public da…

Fix: after 7.5.6
Fix from $2,300 2019-11-08
Linux Vserver CRITICAL 9.8
CVE-2006-4243

linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.

Fix: 2.6.17+
Fix from $2,300 2019-11-06
Fedora HIGH 7.8
CVE-2013-4251

The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.

Fix: 0.12.1+
Fix from $1,950 2019-11-04
Debian Linux HIGH 7.3
CVE-2013-2012

autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.

Fix: 21.5.8+
Fix from $1,950 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2019-18425

An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. Ther…

Fix: after 4.12.1
Fix from $2,300 2019-10-31
Carousel Digital Signage HIGH 8.8
CVE-2018-18931

An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permissions on the C:\TRMS\Service…

Fix: after 7.0.4.104
Fix from $1,950 2019-10-29
Maximo For Oil And Gas HIGH 8.8
CVE-2019-4546

After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allo…

Mitigation only
Fix from $1,950 2019-10-29
K7 Antivirus Premium CRITICAL 9.8
CVE-2019-16897

In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120…

Fix: after 16.0.0120
Fix from $2,300 2019-10-28
Director HIGH 7.7
CVE-2019-10716

An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /in…

Fix: after 3.5.3.1
Fix from $1,950 2019-10-21
Doas HIGH 8.8
CVE-2019-15901

An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, p…

Fix: 6.2+
Fix from $1,950 2019-10-18
Satellite CRITICAL 9.1
CVE-2019-17631

From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…

Fix: after 0.16.0
Fix from $2,300 2019-10-17
Cyber Security HIGH 7.8
CVE-2019-16519

ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in schedu…

Fix: after 6.7.900.0
Fix from $1,950 2019-10-14
Hip Integrator Recognition Configuration Tool HIGH 7.8
CVE-2019-9745

CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service…

No fix yet
Fix from $1,950 2019-10-14
Centreon Vm CRITICAL 9.8
CVE-2018-21025

In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configura…

Fix: after 19.04.3
Fix from $2,300 2019-10-08
Sitos Six HIGH 8.8
CVE-2019-15747

SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role due to in…

Mitigation only
Fix from $1,950 2019-10-07
Android HIGH 7.8
CVE-2018-9425

In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of pri…

Mitigation only
Fix from $1,950 2019-09-27
Bluestacks MEDIUM 6.5
CVE-2019-14220

An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual mac…

Fix: after 4.120
Fix from $1,600 2019-09-24
Pivotal Application Service HIGH 8.8
CVE-2019-11280

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x…

Fix: 2.3.18 / 2.4.14+
Fix from $1,950 2019-09-20
Extra HIGH 8.8
CVE-2016-11002

The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.

Fix: 1.2.4+
Fix from $1,950 2019-09-20
Bloom HIGH 8.8
CVE-2016-11003

The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.

Fix: 1.1.1+
Fix from $1,950 2019-09-20
Monarch HIGH 8.8
CVE-2016-11004

The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.

Fix: 1.2.7+
Fix from $1,950 2019-09-20