Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Enterprise Linux MEDIUM 5.4
CVE-2018-16838

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser…

Mitigation only
Fix from $1,600 2019-03-25
Serve HIGH 7.5
CVE-2019-5415

A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has…

No fix yet
Fix from $1,950 2019-03-21
Hadoop HIGH 7.4
CVE-2018-11767

In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-d…

Fix: after 2.9.1
Fix from $1,950 2019-03-21
Access Manager HIGH 7.8
CVE-2018-18252

An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to unprivileged users via the -…

No fix yet
Fix from $1,950 2019-03-15
Big Ip Application Acceleration Manager MEDIUM 5.5
CVE-2019-6601

In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of i…

Fix: after 12.1.3
Fix from $1,600 2019-03-13
Capi Release HIGH 8.1
CVE-2019-3785

Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with…

Fix: 1.78.0+
Fix from $1,950 2019-03-13
Webmin HIGH 7.8
CVE-2019-9624EPSS 24%

Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a…

No fix yet
Fix from $1,950 2019-03-07
Acrobat Dc CRITICAL 9.8
CVE-2018-19725

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypa…

Fix: after 19.010.20069
Fix from $2,300 2019-03-05
Snapdragon Auto Firmware HIGH 7.1
CVE-2018-5839

Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon C…

Mitigation only
Fix from $1,950 2019-02-25
Filr HIGH 7.8
CVE-2019-3475

A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege us…

No fix yet
Fix from $1,950 2019-02-20
Chrome MEDIUM 6.5
CVE-2019-5768

DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user…

Fix: 72.0.3626.81+
Fix from $1,600 2019-02-19
Kappa Firmware HIGH 7.8
CVE-2018-19012

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a spec…

Mitigation only
Fix from $1,950 2019-01-28
Service Desk Manager CRITICAL 9.8
CVE-2018-19635

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.

Patch available
Fix from $2,300 2019-01-22
Drupal HIGH 7.4
CVE-2017-6924

In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the us…

Fix: 8.3.7+
Fix from $1,950 2019-01-15
Inplc Rt MEDIUM 6.7
CVE-2018-0671

Privilege escalation vulnerability in INplc-RT 3.08 and earlier allows an attacker with administrator rights to execute arbitrary code on the Windows…

Fix: after 3.08
Fix from $1,600 2019-01-09
V2i Hub HIGH 7.5
CVE-2018-1000624

Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive functionality. By visiting http:…

Mitigation only
Fix from $1,950 2018-12-28
Secure Access Series Ssl Vpn Sa 4000 HIGH 8.8
CVE-2018-20193

Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow pri…

No fix yet
Fix from $1,950 2018-12-21
Big Ip Application Acceleration Manager HIGH 7.8
CVE-2018-15331

On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, w…

Fix: after 12.1.3
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11965

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Anyone can execute proptrigger.sh which wi…

Patch available
Fix from $1,950 2018-12-20
Api Connect HIGH 7.2
CVE-2018-1973

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level acce…

Fix: after 5.0.8.4
Fix from $1,950 2018-12-20
Expedition CRITICAL 9.8
CVE-2018-10143EPSS 25%

The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level com…

No fix yet
Fix from $2,300 2018-12-12
Chrome MEDIUM 6.5
CVE-2018-18344

Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote at…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Script Security HIGH 8.8
CVE-2018-1000865

A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTr…

Fix: after 1.47
Fix from $1,950 2018-12-10
Pipeline\ HIGH 8.8
CVE-2018-1000866

A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxT…

Fix: after 2.59
Fix from $1,950 2018-12-10
Campaign HIGH 7.8
CVE-2018-1941

IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating access permissions. IBM X-For…

Fix: 9.1.0.13 / 9.1.2.7+
Fix from $1,950 2018-12-05
Hitshop HIGH 8.8
CVE-2018-19853

An issue was discovered in hitshop through 2014-07-15. There is an elevation-of-privilege vulnerability (that allows control over the whole web site)…

Fix: after 2014-07-15
Fix from $1,950 2018-12-04
Android HIGH 7.8
CVE-2018-11911

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of script may lead …

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11912

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of daemons may lead…

Patch available
Fix from $1,950 2018-11-27
Prtg Network Monitor HIGH 8.8
CVE-2018-19411

PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (incl…

Fix: 18.2.40.1683+
Fix from $1,950 2018-11-21
Chrome MEDIUM 6.5
CVE-2018-6080

Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer p…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14