Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Wp Invoice MEDIUM 6.5
CVE-2016-11011

The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.

Fix: 4.1.1+
Fix from $1,600 2019-09-20
Websphere Application Server MEDIUM 6.5
CVE-2019-4477

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by impro…

Fix: after 9.0.5.0
Fix from $1,600 2019-09-17
Newspaper CRITICAL 9.8
CVE-2016-10972EPSS 9%

The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

Fix: 6.7.2+
Fix from $2,300 2019-09-16
Peepso HIGH 8.8
CVE-2016-10968

The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.

Fix: 1.6.1+
Fix from $1,950 2019-09-16
Membersonic CRITICAL 9.8
CVE-2016-10971

The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required.

Fix: 1.302+
Fix from $2,300 2019-09-16
Windows 10 1507 HIGH 7.8
CVE-2019-1215 KEVEPSS 19%

An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege V…

Patch available
Fix from $1,950 2019-09-11
Misp MEDIUM 6.5
CVE-2019-16202

MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLogge…

Fix: 2.4.115+
Fix from $1,600 2019-09-10
Elementor Page Builder HIGH 8.8
CVE-2017-18596

The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.

Fix: 1.8.0+
Fix from $1,950 2019-09-10
Swape CRITICAL 9.8
CVE-2018-21013

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving…

Fix: 1.2.1+
Fix from $2,300 2019-09-09
Android MEDIUM 6.7
CVE-2019-9443

In the Android kernel in the vl53L0 driver there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation o…

Mitigation only
Fix from $1,600 2019-09-06
Webex Teams HIGH 8.8
CVE-2019-1939

A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affec…

Fix: 3.0.12427.0+
Fix from $1,950 2019-09-05
I MEDIUM 6.3
CVE-2019-4536

IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles…

Patch available
Fix from $1,600 2019-08-29
Backup HIGH 7.8
CVE-2019-15720

CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level access, a user can modify the bac…

Fix: after 6.1.2.34
Fix from $1,950 2019-08-28
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4448

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are …

Patch available
Fix from $1,950 2019-08-26
Code42 For Enterprise MEDIUM 5.5
CVE-2019-11551

In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through…

Fix: after 6.9.1
Fix from $1,600 2019-08-21
Open Xchange Appsuite HIGH 8.1
CVE-2019-11521

OX App Suite 7.10.1 allows Content Spoofing.

No fix yet
Fix from $1,950 2019-08-20
Desktop Password Reset HIGH 7.0
CVE-2019-12889

An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can…

No fix yet
Fix from $1,950 2019-08-20
Windows 10 HIGH 7.0
CVE-2019-1175

An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who successfully exploited the v…

Patch available
Fix from $1,950 2019-08-14
Windows 10 HIGH 7.0
CVE-2019-1177

An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vu…

Patch available
Fix from $1,950 2019-08-14
Windows 10 HIGH 7.8
CVE-2019-1162

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who success…

Patch available
Fix from $1,950 2019-08-14
Nomad CRITICAL 9.8
CVE-2019-12618

HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.

Fix: after 0.9.1
Fix from $2,300 2019-08-12
Application Service HIGH 7.5
CVE-2019-11270

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can by…

Fix: 2.3.15 / 2.3.22+
Fix from $1,950 2019-08-05
Fred CRITICAL 9.8
CVE-2019-1010178

Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets…

No fix yet
Fix from $2,300 2019-07-24
Code42 HIGH 8.8
CVE-2019-11553

In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organization can i…

Fix: after 6.8.4
Fix from $1,950 2019-07-19
Model Specific Registers Safe HIGH 7.5
CVE-2019-1010066

Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specif…

Patch available
Fix from $1,950 2019-07-18
Mikogo HIGH 7.8
CVE-2019-12731

The Windows versions of Snapview Mikogo, versions before 5.10.2 are affected by insecure implementations which allow local attackers to escalate priv…

Fix: 5.10.2+
Fix from $1,950 2019-07-12
Enterprise MEDIUM 6.5
CVE-2019-7278

Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.

Fix: after 2.3.0a
Fix from $1,600 2019-07-01
Web6000q Firmware HIGH 8.8
CVE-2018-15557

An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to…

No fix yet
Fix from $1,950 2019-06-27
Supportassist For Home Pcs HIGH 7.8
CVE-2019-3735

Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, an…

Mitigation only
Fix from $1,950 2019-06-20
Windows 10 HIGH 7.8
CVE-2019-1007

An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with ele…

Patch available
Fix from $1,950 2019-06-12