Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Pangolin Connector For Testrail MEDIUM 6.5
CVE-2018-1999032

A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier in GlobalConfig.java that al…

Fix: after 2.1
Fix from $1,600 2018-08-01
Calsos Csdx Firmware HIGH 8.8
CVE-2018-0613

NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX…

Fix: after 4.37210411
Fix from $1,950 2018-07-26
Debian Linux HIGH 7.8
CVE-2018-10906

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use…

Fix: 2.9.8 / 3.2.5+
Fix from $1,950 2018-07-24
Vbond Orchestrator HIGH 8.8
CVE-2018-0343

A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arb…

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Manageengine Applications Manager HIGH 8.8
CVE-2016-9489

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own …

Mitigation only
Fix from $1,950 2018-07-13
Junos HIGH 7.8
CVE-2018-0024

An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain …

Mitigation only
Fix from $1,950 2018-07-11
Bmc Firmware HIGH 8.2
CVE-2018-3682

BMC Firmware in Intel server boards, compute modules, and systems potentially allow an attacker with administrative privileges to make unauthorized r…

Mitigation only
Fix from $1,950 2018-07-10
Freesshd CRITICAL 9.8
CVE-2018-9853

Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process by leveraging the ability to …

Mitigation only
Fix from $2,300 2018-07-10
Mdm9607 Firmware HIGH 8.4
CVE-2018-5884

Improper Access Control in Multimedia in Snapdragon Mobile and Snapdragon Wear, Non-standard applications without permission may acquire permission o…

Mitigation only
Fix from $1,950 2018-07-06
Linux Kernel HIGH 7.8
CVE-2018-13405

The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, i…

Fix: after 3.16
Fix from $1,950 2018-07-06
Pan Os MEDIUM 5.5
CVE-2018-9334

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allo…

Fix: after 8.0.8
Fix from $1,600 2018-07-03
Rapidpoint 400 Firmware HIGH 8.8
CVE-2018-4845

A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens …

Fix: 3.3+
Fix from $1,950 2018-06-26
Zenphoto HIGH 7.2
CVE-2018-0610

Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code…

Fix: after 1.4.14
Fix from $1,950 2018-06-26
Basercms MEDIUM 5.3
CVE-2018-0573

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a con…

Fix: after 4.1.0.1
Fix from $1,600 2018-06-26
Octopus Deploy MEDIUM 6.5
CVE-2018-12884

In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastruc…

Mitigation only
Fix from $1,600 2018-06-26
Satellite HIGH 8.8
CVE-2017-2672

A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file woul…

Fix: 1.15+
Fix from $1,950 2018-06-21
Privileged Access Manager CRITICAL 9.8
CVE-2018-9021EPSS 10%

An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with s…

Fix: after 2.8.2
Fix from $2,300 2018-06-18
Privileged Access Manager CRITICAL 9.8
CVE-2018-9022EPSS 13%

An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or command…

Fix: after 2.8.2
Fix from $2,300 2018-06-18
Puredata System For Analytics HIGH 7.8
CVE-2018-1460

IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writable file, which could be used…

No fix yet
Fix from $1,950 2018-06-15
Ubuntu Linux HIGH 7.5
CVE-2018-5166

WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access …

Fix: 60.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7803

When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforc…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-7767

The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater,…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7782

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. No…

Fix: 52.3.0 / 55.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-5409

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parame…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Disk Backup HIGH 8.8
CVE-2018-11190

Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 2 of 6).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Flashsystem 900 Firmware MEDIUM 6.5
CVE-2018-1495

IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a…

No fix yet
Fix from $1,600 2018-05-29
Moodle MEDIUM 6.5
CVE-2018-1134

An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by chan…

Fix: after 3.4.2
Fix from $1,600 2018-05-25
Fortios MEDIUM 6.2
CVE-2017-14187

A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions al…

Fix: after 5.6.2
Fix from $1,600 2018-05-24
Joomla\! HIGH 8.8
CVE-2018-11323

An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissi…

Fix: 3.8.8+
Fix from $1,950 2018-05-22
Cri O HIGH 8.8
CVE-2018-1000400

Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities th…

Fix: 1.9.0+
Fix from $1,950 2018-05-18