Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Webaccess HIGH 7.8
CVE-2018-8841

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $1,950 2018-05-15
Brilliance Firmware 64 HIGH 8.8
CVE-2018-8853

Philips Brilliance CT devices operate user functions from within a contained kiosk in a Microsoft Windows operating system. Windows boots by default …

Fix: after 4.1.6
Fix from $1,950 2018-05-04
Eap Controller HIGH 8.8
CVE-2018-10168

TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-p…

No fix yet
Fix from $1,950 2018-05-03
Wireless Lan Controller Software MEDIUM 5.3
CVE-2018-0245

A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker …

Mitigation only
Fix from $1,600 2018-05-02
Octopus Deploy HIGH 7.5
CVE-2018-10550

In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.

Fix: 2018.4.7+
Fix from $1,950 2018-04-30
Watchdog Console HIGH 7.8
CVE-2018-10079

Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data…

No fix yet
Fix from $1,950 2018-04-20
Private Internet Access HIGH 7.8
CVE-2018-10190

A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run …

Mitigation only
Fix from $1,950 2018-04-17
7 Zip HIGH 8.8
CVE-2018-10172

7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivileg…

Fix: after 18.01
Fix from $1,950 2018-04-16
Iphone Os MEDIUM 5.5
CVE-2018-4173

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar"…

Fix: 10.13.4 / 11.3+
Fix from $1,600 2018-04-13
Debian Linux HIGH 7.8
CVE-2017-0358

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe…

Fix: after 2016.2.22
Fix from $1,950 2018-04-13
Core I7 8550u MEDIUM 6.0
CVE-2017-5703

Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially l…

Mitigation only
Fix from $1,600 2018-04-03
I\, Librarian CRITICAL 9.1
CVE-2018-1000141

I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining un…

Fix: after 4.9
Fix from $2,300 2018-03-23
Edgeos HIGH 8.8
CVE-2017-0932

Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation on the in…

Fix: after 1.9.1.1
Fix from $1,950 2018-03-22
Edgeos HIGH 8.8
CVE-2017-0934

Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file…

Fix: after 1.9.1
Fix from $1,950 2018-03-22
Edgeos HIGH 8.8
CVE-2017-0935

Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the fi…

Fix: after 1.9.1.1
Fix from $1,950 2018-03-22
Software Guard Extensions Platform Software Component HIGH 8.8
CVE-2017-5736

An elevation of privilege in Intel Software Guard Extensions Platform Software Component before 1.9.105.42329 allows a local attacker to execute arbi…

Fix: 1.9.105.42329+
Fix from $1,950 2018-03-20
Fusionsphere Openstack Firmware HIGH 7.2
CVE-2017-8187

Huawei FusionSphere OpenStack V100R006C00SPC102(NFV) has a privilege escalation vulnerability. Due to improper privilege restrictions, an attacker wi…

Mitigation only
Fix from $1,950 2018-03-20
Simatic Wincc Oa Ui MEDIUM 6.7
CVE-2018-4844

A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.1…

Fix: 3.15.10+
Fix from $1,600 2018-03-20
Trident HIGH 7.5
CVE-2018-1000133

Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that can result in A standard unp…

Patch available
Fix from $1,950 2018-03-16
Rsa Identity Governance And Lifecycle HIGH 7.8
CVE-2018-1182

An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle …

Mitigation only
Fix from $1,950 2018-03-08
Big Iq Centralized Management MEDIUM 6.7
CVE-2017-6152

A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on th…

Fix: after 5.2.0
Fix from $1,600 2018-03-08
Windows 10 HIGH 7.0
CVE-2018-0821

AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vul…

Patch available
Fix from $1,950 2018-02-15
Linux Kernel HIGH 7.4
CVE-2018-1000028

Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS serve…

Fix: after 4.15.7
Fix from $1,950 2018-02-09
Ubuntu Linux MEDIUM 5.5
CVE-2017-10689

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a f…

Fix: 1.10.10 / 5.3.4+
Fix from $1,600 2018-02-09
Satellite MEDIUM 6.5
CVE-2017-10690

In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from.…

Fix: 5.3.4 / 2017.3.4+
Fix from $1,600 2018-02-09
Data Science Workbench HIGH 8.8
CVE-2017-15536

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authentic…

Fix: 1.2.0+
Fix from $1,950 2018-02-05
Octopus Deploy HIGH 8.8
CVE-2018-5706

An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System …

Fix: 4.1.9+
Fix from $1,950 2018-01-16
Junos Space MEDIUM 6.5
CVE-2018-0010

A vulnerability in the Juniper Networks Junos Space Security Director allows a user who does not have SSH access to a device to reuse the URL that wa…

Patch available
Fix from $1,600 2018-01-10
Urbancode Deploy MEDIUM 5.4
CVE-2017-1493

IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access c…

Mitigation only
Fix from $1,600 2018-01-09
Windows 10 HIGH 7.8
CVE-2018-0748

The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1…

Patch available
Fix from $1,950 2018-01-04