Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Windows 10 HIGH 7.1
CVE-2018-0751

The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Win…

No fix yet
Fix from $1,950 2018-01-04
Octopus Deploy HIGH 8.8
CVE-2018-4862

In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an Azure account in suc…

Fix: after 4.1.5
Fix from $1,950 2018-01-03
7kt Pac1200 Data Manager Firmware CRITICAL 9.8
CVE-2017-9944

A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of…

Fix: 2.03+
Fix from $2,300 2017-12-27
Epmp 1000 Firmware HIGH 8.8
CVE-2017-5254EPSS 54%

In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passw…

Fix: after 3.5
Fix from $1,950 2017-12-20
Isilon Onefs MEDIUM 6.7
CVE-2017-14380

In EMC Isilon OneFS 8.1.0.0, 8.0.1.0 - 8.0.1.1, 8.0.0.0 - 8.0.0.4, 7.2.1.0 - 7.2.1.5, 7.2.0.x, and 7.1.1.x, a malicious compliance admin (compadmin) …

Mitigation only
Fix from $1,600 2017-12-13
Perspective HIGH 8.8
CVE-2017-11319EPSS 6%

Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges b…

No fix yet
Fix from $1,950 2017-12-11
Ispconfig HIGH 8.8
CVE-2017-17384

ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

Patch available
Fix from $1,950 2017-12-07
Android MEDIUM 5.3
CVE-2017-13165

An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937.

Patch available
Fix from $1,600 2017-12-06
Teampass HIGH 8.1
CVE-2017-15055

TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary i…

Fix: 2.1.27.9+
Fix from $1,950 2017-11-27
Openemr HIGH 8.1
CVE-2017-1000241

The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow a…

Fix: after 5.0.1
Fix from $1,950 2017-11-17
Couchdb CRITICAL 9.8
CVE-2017-12635EPSS 100%

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1…

Fix: 1.7.0+
Fix from $2,300 2017-11-14
Buildmaster HIGH 7.5
CVE-2017-16520

Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.

Fix: 5.8.2+
Fix from $1,950 2017-11-11
Vtscada HIGH 7.8
CVE-2017-14031

An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and wr…

Fix: after 11.3.03
Fix from $1,950 2017-11-06
Mahara MEDIUM 6.5
CVE-2017-1000156

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any gr…

Patch available
Fix from $1,600 2017-11-03
Amazon Web Services Cloudformation Bootstrap HIGH 7.8
CVE-2017-9450

The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary…

Fix: 1.4-19.10+
Fix from $1,950 2017-10-30
Prtg Network Monitor MEDIUM 6.5
CVE-2017-15917

In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.

Mitigation only
Fix from $1,600 2017-10-26
Extremexos MEDIUM 6.7
CVE-2017-14329

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.

Mitigation only
Fix from $1,600 2017-10-23
Extremexos MEDIUM 6.7
CVE-2017-14330

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.

No fix yet
Fix from $1,600 2017-10-23
Documentum Content Server HIGH 8.8
CVE-2017-15013EPSS 7%

OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authentica…

Fix: after 7.3
Fix from $1,950 2017-10-13
Nuc7i7bnh Firmware HIGH 7.5
CVE-2017-5722

Incorrect policy enforcement in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows atta…

Patch available
Fix from $1,950 2017-10-11
Scada Webserver HIGH 7.8
CVE-2017-12728

An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-administrativ…

Fix: after 2.02.0007
Fix from $1,950 2017-10-05
Config File Provider MEDIUM 6.5
CVE-2017-1000104

The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overal…

Fix: after 2.16.1
Fix from $1,600 2017-10-05
Sitescope CRITICAL 9.8
CVE-2017-14349

An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and mon…

Mitigation only
Fix from $2,300 2017-09-30
X Pack MEDIUM 6.5
CVE-2017-8447

An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a…

Mitigation only
Fix from $1,600 2017-09-29
X Pack HIGH 8.8
CVE-2017-8448

An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch…

Mitigation only
Fix from $1,950 2017-09-29
Android HIGH 7.8
CVE-2017-9724

In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to gain access to kernel memory, s…

Fix: after 8.0
Fix from $1,950 2017-09-21
Sci Mathematics Gimps HIGH 7.3
CVE-2017-14484

The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by cr…

Patch available
Fix from $1,950 2017-09-15
Rp MEDIUM 6.3
CVE-2017-14124

In eLux RP 5.x before 5.5.1000 LTSR and 5.6.x before 5.6.2 CR when classic desktop mode is used, it is possible to start applications other than defi…

Fix: after 5.6.0
Fix from $1,600 2017-09-13
Nagios Core HIGH 7.8
CVE-2017-14312

Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root ac…

Fix: after 4.3.4
Fix from $1,950 2017-09-11
Cf Release HIGH 8.8
CVE-2016-0732

The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with…

Fix: after 229
Fix from $1,950 2017-09-07