Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Misp MEDIUM 6.6
CVE-2019-12794

An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability t…

Patch available
Fix from $1,600 2019-06-11
Datagate Mk2 Firmware HIGH 8.8
CVE-2019-12775

An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-…

No fix yet
Fix from $1,950 2019-06-07
Viveport HIGH 7.8
CVE-2019-12176

Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate pri…

Fix: 1.0.0.36+
Fix from $1,950 2019-06-03
Rkt HIGH 7.7
CVE-2019-10144

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capab…

Fix: after 1.30.0
Fix from $1,950 2019-06-03
Smart Home Controller Firmware HIGH 7.1
CVE-2019-11896

A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.…

Fix: 9.8.907+
Fix from $1,950 2019-05-29
Smart Home Controller Firmware HIGH 8.0
CVE-2019-11891

A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 …

Fix: 9.8.905+
Fix from $1,950 2019-05-29
Smart Home Controller Firmware HIGH 8.0
CVE-2019-11893

A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.…

Fix: 9.8.905+
Fix from $1,950 2019-05-29
Risk Authentication HIGH 8.8
CVE-2019-7394

A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1…

Fix: after 8.2.1
Fix from $1,950 2019-05-28
Azure Active Directory Connect MEDIUM 5.3
CVE-2019-1000

An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two Po…

Patch available
Fix from $1,600 2019-05-16
Identity Management HIGH 8.8
CVE-2019-0301

Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface …

Mitigation only
Fix from $1,950 2019-05-14
Go CRITICAL 9.8
CVE-2019-11888

Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain…

Fix: after 1.12.5
Fix from $2,300 2019-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2019-6617

On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to…

Fix: 11.5.9 / 11.6.4+
Fix from $1,600 2019-05-03
Octopus Deploy HIGH 8.1
CVE-2019-11632

In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscope…

Fix: after 2019.4.5
Fix from $1,950 2019-05-01
Smartvista HIGH 7.2
CVE-2018-15207

BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the…

No fix yet
Fix from $1,950 2019-04-30
Fedora HIGH 7.8
CVE-2019-3843

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient s…

Fix: 242+
Fix from $1,950 2019-04-26
Routing Release MEDIUM 6.5
CVE-2019-3789

Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside t…

Fix: 0.188.0+
Fix from $1,600 2019-04-24
Bosh Backup And Restore HIGH 7.1
CVE-2019-3786

Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authentic…

Fix: 1.5.0+
Fix from $1,950 2019-04-24
Runasspc HIGH 7.8
CVE-2019-10239

Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to…

No fix yet
Fix from $1,950 2019-04-24
GitLab MEDIUM 6.5
CVE-2019-7155

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1.…

Fix: 11.5.8 / 11.6.6+
Fix from $1,600 2019-04-16
Shimo Vpn HIGH 7.8
CVE-2018-4008

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript command. The command takes a us…

No fix yet
Fix from $1,950 2019-04-15
Wonderware System Platform HIGH 8.8
CVE-2019-6525

AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node…

Fix: 2017+
Fix from $1,950 2019-04-11
Rancher HIGH 8.1
CVE-2019-6287

In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have bee…

Fix: after 2.1.5
Fix from $1,950 2019-04-10
Windows 10 HIGH 7.8
CVE-2019-0735

An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, …

Patch available
Fix from $1,950 2019-04-09
Endpoint Privilege Manager HIGH 7.8
CVE-2018-14894

CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access r…

Fix: after 10.2.1.603
Fix from $1,950 2019-04-09
Fortios HIGH 7.2
CVE-2017-17544

A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile t…

Fix: after 6.0.6
Fix from $1,950 2019-04-09
Password Manager MEDIUM 6.5
CVE-2019-10676

An issue was discovered in Uniqkey Password Manager 1.14. Upon entering new credentials to a site that is not registered within this product, a pop-u…

No fix yet
Fix from $1,600 2019-04-08
Iphone Os CRITICAL 10.0
CVE-2018-4310

An access issue was addressed with additional sandbox restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.

Fix: 10.14 / 12.0+
Fix from $2,300 2019-04-03
Ios Xe HIGH 8.8
CVE-2019-1754

A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to r…

Patch available
Fix from $1,950 2019-03-28
Pmaa HIGH 8.8
CVE-2018-19648

An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged use…

Mitigation only
Fix from $1,950 2019-03-27
Moodle HIGH 8.8
CVE-2019-3849

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content…

Fix: 3.4.8 / 3.5.5+
Fix from $1,950 2019-03-26