Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2018-16263 The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy config… Tizen Mitigation only Fix from $1,9502020-01-22 MEDIUM 6.5 CVE-2018-16265 The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, du… Tizen Mitigation only Fix from $1,6002020-01-22 HIGH 8.1 CVE-2018-16266 The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy c… Tizen Mitigation only Fix from $1,9502020-01-22 HIGH 8.1 CVE-2018-16267 The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security polic… Tizen Mitigation only Fix from $1,9502020-01-22 HIGH 8.8 CVE-2020-7047 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a … Wp Database Reset after 3.1 Fix from $1,9502020-01-16 CRITICAL 9.9 CVE-2019-10940 A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a… Sinema Server 14.0+ Fix from $2,3002020-01-16 HIGH 8.8 CVE-2019-15012 Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from… Bitbucket 5.6.11 / 6.0.11+ Fix from $1,9502020-01-15 HIGH 7.8 CVE-2014-6448 Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restrictions and execute arbitrary… Junos Mitigation only Fix from $1,9502020-01-15 MEDIUM 6.5 CVE-2015-5071 AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate"… Remedy Ar System Server No fix yet Fix from $1,6002020-01-15 MEDIUM 6.5 CVE-2015-5072 The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navi… Remedy Ar System Server No fix yet Fix from $1,6002020-01-15 HIGH 7.8 CVE-2015-5466 Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain… Xgi Vga Display Manager No fix yet Fix from $1,9502020-01-15 HIGH 7.8 CVE-2015-7556 DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program. Delegate No fix yet Fix from $1,9502020-01-15 HIGH 7.5 CVE-2012-1563EPSS 9% Joomla! before 2.5.3 allows Admin Account Creation. Joomla\! 2.5.3+ Fix from $1,9502020-01-15 HIGH 7.8 CVE-2020-0635 An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevat… Windows 10 Patch available Fix from $1,9502020-01-14 HIGH 7.8 CVE-2012-4760 A Privilege Escalation vulnerability exists in the SDBagent service in Safend Data Protector Agent 3.4.5586.9772, which could let a local malicious u… Data Protector Agent No fix yet Fix from $1,9502020-01-13 HIGH 7.8 CVE-2012-4761 A Privilege Escalation vulnerability exists in the unquoted Service Binary in SDPAgent or SDBAgent in Safend Data Protector Agent 3.4.5586.9772, whic… Data Protector Agent No fix yet Fix from $1,9502020-01-13 HIGH 7.5 CVE-2019-19728 SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges. Debian Linux 18.08.9 / 19.05.5+ Fix from $1,9502020-01-13 HIGH 8.8 CVE-2020-6949 A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of a… Hashbrown Cms after 1.3.3 Fix from $1,9502020-01-13 MEDIUM 6.1 CVE-2012-4767 An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, which could let a malicious us… Data Protector Agent No fix yet Fix from $1,6002020-01-13 HIGH 8.8 CVE-2013-6231EPSS 10% SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script Spagobi 4.1+ Fix from $1,9502020-01-10 HIGH 7.8 CVE-2019-19544 CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate p… Ca Automic Dollar Universe No fix yet Fix from $1,9502020-01-08 HIGH 7.8 CVE-2016-6590 A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suit… Encryption Desktop 7.6 / 10.4.1+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-14819 A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to… Openshift Container Platform No fix yet Fix from $1,9502020-01-07 HIGH 7.8 CVE-2019-19585EPSS 6% An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apa… Rconfig No fix yet Fix from $1,9502020-01-06 HIGH 7.8 CVE-2013-4161 gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security iss… Fedora Mitigation only Fix from $1,9502019-12-31 HIGH 7.2 CVE-2019-7479 A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen… Sonicos after 5.9.1.12-4o Fix from $1,9502019-12-31 HIGH 7.5 CVE-2012-5663 The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area… Textproc\/isearch 1.47.01nb1+ Fix from $1,9502019-12-30 HIGH 7.8 CVE-2013-2016 A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the vi… Debian Linux after 1.4.2 Fix from $1,9502019-12-30 HIGH 8.8 CVE-2019-20074 On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page. Dl4343 Firmware Mitigation only Fix from $1,9502019-12-30 CRITICAL 9.8 CVE-2013-5027 Collabtive 1.0 has incorrect access control Collabtive No fix yet Fix from $2,3002019-12-27