Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.2 CVE-2020-3396 A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical … Ios Xe Mitigation only Fix from $1,9502020-09-24 CRITICAL 9.8 CVE-2015-4719 The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request. Pexip Infinity 10+ Fix from $2,3002020-09-24 HIGH 7.8 CVE-2020-25595 An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been ide… Fedora after 4.14.0 Fix from $1,9502020-09-23 HIGH 8.8 CVE-2020-8247 Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.18… Application Delivery Controller Firmware 10.2.7b / 11.0.3f+ Fix from $1,9502020-09-18 MEDIUM 6.7 CVE-2020-0403 In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation… Android Mitigation only Fix from $1,6002020-09-17 HIGH 7.2 CVE-2020-24046 A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a smal… Spamtitan No fix yet Fix from $1,9502020-09-17 MEDIUM 5.5 CVE-2020-0404 In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalati… Android Mitigation only Fix from $1,6002020-09-17 HIGH 7.8 CVE-2020-0074 In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a… Android Patch available Fix from $1,9502020-09-17 HIGH 8.4 CVE-2020-16875EPSS 47% <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who s… Exchange Server Patch available Fix from $1,9502020-09-11 HIGH 7.5 CVE-2020-9733 An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If e… Experience Manager after 6.5.5.0 Fix from $1,9502020-09-10 HIGH 7.0 CVE-2020-7311 Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during… Mcafee Agent 5.6.6+ Fix from $1,9502020-09-10 HIGH 7.8 CVE-2020-10056 A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected application is execu… License Management Utility 2.4+ Fix from $1,9502020-09-09 MEDIUM 6.1 CVE-2020-7324 Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny acces… Mvision Endpoint 20.9+ Fix from $1,6002020-09-09 HIGH 7.8 CVE-2020-7523 Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could ca… Modbus Driver Suite 2.20_ie_30 / 3.20_ie_30+ Fix from $1,9502020-08-31 HIGH 7.2 CVE-2020-4603 IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new wea… Security Guardium Insights Patch available Fix from $1,9502020-08-27 MEDIUM 6.8 CVE-2020-5916 In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file… Big Ip Access Policy Manager 15.0.1.4 / 15.1.0.5+ Fix from $1,6002020-08-26 HIGH 7.8 CVE-2019-11847 An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the co… Aleos 4.4.9 / 4.9.4+ Fix from $1,9502020-08-21 MEDIUM 6.8 CVE-2020-10290 Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that p… Urx Mitigation only Fix from $1,6002020-08-21 MEDIUM 6.9 CVE-2020-7310 Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change fil… Total Protection 4.0.161.1+ Fix from $1,6002020-08-21 MEDIUM 5.4 CVE-2020-14194 Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link. Zulip Server 2.1.5+ Fix from $1,6002020-08-21 HIGH 7.5 CVE-2020-14215 Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations. Zulip Server 2.1.5+ Fix from $1,9502020-08-21 HIGH 7.8 CVE-2020-15862 Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as … Ubuntu Linux 5.8.1+ Fix from $1,9502020-08-20 CRITICAL 9.9 CVE-2020-15149 NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user… Nodebb 1.14.3+ Fix from $2,3002020-08-20 HIGH 8.8 CVE-2020-7018 Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, t… Enterprise Search 7.9.0+ Fix from $1,9502020-08-18 MEDIUM 6.5 CVE-2020-7019 In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs … Elasticsearch 6.8.12 / 7.9.0+ Fix from $1,6002020-08-18 HIGH 7.0 CVE-2020-1488 An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acc… Windows 10 Patch available Fix from $1,9502020-08-17 MEDIUM 5.3 CVE-2015-8032 In Textpattern 4.5.7, an unprivileged author can change an article's markup setting. Textpattern Patch available Fix from $1,6002020-08-14 HIGH 7.8 CVE-2020-24330 An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop t… Fedora after 0.3.14 Fix from $1,9502020-08-13 HIGH 7.8 CVE-2020-24331 An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access … Fedora after 0.3.14 Fix from $1,9502020-08-13 MEDIUM 6.5 CVE-2020-7305 Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to crea… Data Loss Prevention 11.3.28 / 11.4.200+ Fix from $1,6002020-08-13