Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Rapid Storage Technology HIGH 7.8
CVE-2018-3635

Insufficient input validation in installer in Intel Rapid Store Technology (RST) before version 16.7 may allow an unprivileged user to potentially el…

Fix: 16.7+
Fix from $1,950 2018-11-14
Advanced Business Application Programming HIGH 7.2
CVE-2018-2481

In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a transaction code reserved for cust…

Fix: after 7.11
Fix from $1,950 2018-11-13
Operations Manager HIGH 8.8
CVE-2018-15762

Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior t…

Fix: 2.0.24 / 2.1.15+
Fix from $1,950 2018-11-02
Webaccess HIGH 7.8
CVE-2018-14828

Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perfo…

Fix: after 8.3.1
Fix from $1,950 2018-10-23
Workspace Control HIGH 7.8
CVE-2018-15592

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with ele…

Fix: 10.3.10.0+
Fix from $1,950 2018-10-15
Ektron Cms CRITICAL 9.8
CVE-2018-12596EPSS 22%

Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages vi…

Patch available
Fix from $2,300 2018-10-10
Rox Ii Firmware HIGH 7.2
CVE-2018-13802

A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged user account access via SSH …

Fix: 2.12.1+
Fix from $1,950 2018-10-10
Rox Ii Firmware HIGH 8.8
CVE-2018-13801

A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp and valid low-privileged user …

Fix: 2.12.1+
Fix from $1,950 2018-10-10
Joomla\! HIGH 8.8
CVE-2018-17855

An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in th…

Fix: 3.8.13+
Fix from $1,950 2018-10-09
Umbrella Enterprise Roaming Client HIGH 7.8
CVE-2018-0437

A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administr…

Fix: 2.1.118 / 4.6.1098+
Fix from $1,950 2018-10-05
Umbrella Enterprise Roaming Client HIGH 7.8
CVE-2018-0438

A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administr…

Fix: 2.1.127+
Fix from $1,950 2018-10-05
Rv110w Firmware CRITICAL 9.8
CVE-2018-0425

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, …

Fix: 1.0.3.44+
Fix from $2,300 2018-10-05
Webex Teams HIGH 8.7
CVE-2018-0436

A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization…

Fix: 10.6.0+
Fix from $1,950 2018-10-05
Ams Device Manager MEDIUM 6.5
CVE-2018-14808

Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on the affected products.

Fix: after 13.5
Fix from $1,600 2018-10-01
Debian Linux MEDIUM 5.5
CVE-2015-9267

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This al…

Fix: 2.49+
Fix from $1,600 2018-10-01
Tivoli Storage Manager MEDIUM 5.5
CVE-2018-1550

IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to o…

Fix: after 8.1.4.1
Fix from $1,600 2018-09-26
Galaxy Apps HIGH 7.8
CVE-2018-10502

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 4.2.18.2. An att…

Fix: 4.2.18.2+
Fix from $1,950 2018-09-24
Samsung Members HIGH 8.8
CVE-2018-11614

This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker…

Fix: 2.4.25+
Fix from $1,950 2018-09-24
Cn80 MEDIUM 5.8
CVE-2018-14825

On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN…

Mitigation only
Fix from $1,600 2018-09-24
Karaf HIGH 8.8
CVE-2018-11786

In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri…

Fix: 4.2.0+
Fix from $1,950 2018-09-18
Simatic Wincc Open Architecture CRITICAL 9.1
CVE-2018-13799

A vulnerability has been identified in SIMATIC WinCC OA V3.14 and prior (All versions < V3.14-P021). Improper access control to a data point of the a…

Fix: after 3.14
Fix from $2,300 2018-09-12
Ubuntu Linux HIGH 7.8
CVE-2018-10853

A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current …

Fix: 4.18+
Fix from $1,950 2018-09-11
Antivirus \+ Security HIGH 7.8
CVE-2018-10514

A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate …

Fix: after 12.0
Fix from $1,950 2018-08-30
Manjaro Linux HIGH 7.8
CVE-2018-15912

An issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can install or remove arbitrary p…

Fix: after 20180716-1
Fix from $1,950 2018-08-29
Deltav HIGH 7.8
CVE-2018-14791

Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable and library files on the affec…

Mitigation only
Fix from $1,950 2018-08-23
Intellispace Cardiovascular HIGH 7.8
CVE-2018-14787

In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated priv…

Fix: after 4.1
Fix from $1,950 2018-08-22
Librehealth Ehr HIGH 8.8
CVE-2018-1000648

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can resul…

No fix yet
Fix from $1,950 2018-08-20
Omero HIGH 7.2
CVE-2018-1000634

The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can res…

Fix: after 5.4.6
Fix from $1,950 2018-08-20
Web Security Appliance MEDIUM 6.7
CVE-2018-0428

A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate pri…

Mitigation only
Fix from $1,600 2018-08-15
Subrion Cms MEDIUM 6.5
CVE-2018-14836

Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perfor…

Mitigation only
Fix from $1,600 2018-08-02