Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Storagegrid Webscale MEDIUM 6.5
CVE-2017-12422

NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arb…

Mitigation only
Fix from $1,600 2017-08-29
Replibit CRITICAL 9.8
CVE-2017-13707

Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges via sudo command execution. …

Fix: 2017.08.04+
Fix from $2,300 2017-08-27
X Pack MEDIUM 5.3
CVE-2017-8446

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vuln…

Fix: after 5.5.1
Fix from $1,600 2017-08-18
Application Policy Infrastructure Controller HIGH 7.1
CVE-2017-6767

A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges …

Mitigation only
Fix from $1,950 2017-08-17
Monitouch V Sft MEDIUM 5.3
CVE-2017-9662

An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. Monitouch V-SFT is install…

Fix: after 5.4.42.0
Fix from $1,600 2017-08-14
Hospitality Reporting And Analytics MEDIUM 5.4
CVE-2017-10142

Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Mobile Apps). Supported v…

Patch available
Fix from $1,600 2017-08-08
Flexcube Universal Banking MEDIUM 5.4
CVE-2017-10098

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported …

Patch available
Fix from $1,600 2017-08-08
Flexcube Private Banking MEDIUM 6.5
CVE-2017-10103

Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported ver…

Patch available
Fix from $1,600 2017-08-08
Java Advanced Management Console HIGH 7.4
CVE-2017-10104

Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is J…

Patch available
Fix from $1,950 2017-08-08
Agile Product Lifecycle Management MEDIUM 5.4
CVE-2017-10094

Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected …

Patch available
Fix from $1,600 2017-08-08
Primavera P6 Enterprise Project Portfolio Management MEDIUM 5.4
CVE-2017-10046

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Su…

Patch available
Fix from $1,600 2017-08-08
Hospitality Reporting And Analytics HIGH 7.7
CVE-2017-10000

Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported ver…

Patch available
Fix from $1,950 2017-08-08
Sipass Integrated HIGH 8.1
CVE-2017-9940

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged …

Fix: after 2.65
Fix from $1,950 2017-08-08
Vsn300 Firmware MEDIUM 6.5
CVE-2017-7916

A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger …

Fix: after 1.8.15
Fix from $1,600 2017-08-07
GitLab MEDIUM 6.3
CVE-2017-11438

GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group …

Mitigation only
Fix from $1,600 2017-08-02
Tinyproxy MEDIUM 5.5
CVE-2017-11747

main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow …

Fix: after 1.8.4
Fix from $1,600 2017-07-30
Hashtopussy HIGH 8.8
CVE-2017-11681

Incorrect Access Control vulnerability in Hashtopussy 0.4.0 allows remote authenticated users to execute actions that should only be available for ad…

Fix: after 0.4.0
Fix from $1,950 2017-07-27
Orientdb CRITICAL 9.8
CVE-2017-11467EPSS 73%

OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to exe…

Fix: after 2.2.22
Fix from $2,300 2017-07-20
Inteno Router Firmware HIGH 8.8
CVE-2017-11361

Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands…

No fix yet
Fix from $1,950 2017-07-17
Moodle MEDIUM 6.5
CVE-2017-7532

In Moodle 3.x, course creators are able to change system default settings for courses.

Patch available
Fix from $1,600 2017-07-17
Atutor CRITICAL 9.8
CVE-2017-1000003

ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in …

Fix: after 2.2.1
Fix from $2,300 2017-07-17
Ios Xr HIGH 7.0
CVE-2017-6728

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary code at the root privilege leve…

Mitigation only
Fix from $1,950 2017-07-10
Prime Network MEDIUM 6.7
CVE-2017-6732

A vulnerability in the installation procedure for Cisco Prime Network Software could allow an authenticated, local attacker to elevate their privileg…

Mitigation only
Fix from $1,600 2017-07-10
Cloud Foundry Uaa MEDIUM 6.6
CVE-2017-8032

In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to …

Fix: after 263
Fix from $1,600 2017-07-10
Systemd CRITICAL 9.8
CVE-2017-1000082

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privi…

Fix: 234+
Fix from $2,300 2017-07-07
Epmp 1000 Firmware MEDIUM 6.8
CVE-2017-7918EPSS 7%

An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able …

Mitigation only
Fix from $1,600 2017-06-21
Epmp 1000 Firmware HIGH 7.6
CVE-2017-7922EPSS 10%

An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted…

Mitigation only
Fix from $1,950 2017-06-21
Capi Release MEDIUM 6.5
CVE-2016-8219

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the Space…

Fix: 1.12.0 / 250+
Fix from $1,600 2017-06-13
Cloud Foundry Uaa Bosh HIGH 8.8
CVE-2017-4973

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions pr…

Fix: after 256
Fix from $1,950 2017-06-13
Cf Release HIGH 7.2
CVE-2017-4991

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions pr…

Fix: after 259
Fix from $1,950 2017-06-13