Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 6.7 CVE-2011-2910 The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping … Debian Linux 0.0.8-13+ Fix from $1,6002019-11-15 HIGH 8.8 CVE-2019-15799 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, w… Gs1900 8 Firmware 2.50+ Fix from $1,9502019-11-14 MEDIUM 5.5 CVE-2019-14590 Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially ena… Graphics Driver 26.20.100.7209+ Fix from $1,6002019-11-14 HIGH 8.8 CVE-2019-3651 Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO … Advanced Threat Defense 4.8+ Fix from $1,9502019-11-13 HIGH 8.8 CVE-2010-4664 In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their… Debian Linux 0.4.2+ Fix from $1,9502019-11-13 HIGH 7.8 CVE-2019-2193 In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lea… Android Mitigation only Fix from $1,9502019-11-13 HIGH 7.8 CVE-2019-1405 KEVEPSS 30% An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Wi… Windows 10 1507 Patch available Fix from $1,9502019-11-12 HIGH 7.8 CVE-2019-1388 KEVEPSS 9% An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Cert… Windows 10 1507 Patch available Fix from $1,9502019-11-12 HIGH 7.1 CVE-2019-18845 The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbi… Viper Rgb Firmware Mitigation only Fix from $1,9502019-11-09 CRITICAL 9.8 CVE-2019-18623 Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public da… Energycap after 7.5.6 Fix from $2,3002019-11-08 CRITICAL 9.8 CVE-2006-4243 linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code. Linux Vserver 2.6.17+ Fix from $2,3002019-11-06 HIGH 7.8 CVE-2013-4251 The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories. Fedora 0.12.1+ Fix from $1,9502019-11-04 HIGH 7.3 CVE-2013-2012 autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory. Debian Linux 21.5.8+ Fix from $1,9502019-10-31 CRITICAL 9.8 CVE-2019-18425 An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. Ther… Debian Linux after 4.12.1 Fix from $2,3002019-10-31 HIGH 8.8 CVE-2018-18931 An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permissions on the C:\TRMS\Service… Carousel Digital Signage after 7.0.4.104 Fix from $1,9502019-10-29 HIGH 8.8 CVE-2019-4546 After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allo… Maximo For Oil And Gas Mitigation only Fix from $1,9502019-10-29 CRITICAL 9.8 CVE-2019-16897 In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120… K7 Antivirus Premium after 16.0.0120 Fix from $2,3002019-10-28 HIGH 7.7 CVE-2019-10716 An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /in… Director after 3.5.3.1 Fix from $1,9502019-10-21 HIGH 8.8 CVE-2019-15901 An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, p… Doas 6.2+ Fix from $1,9502019-10-18 CRITICAL 9.1 CVE-2019-17631 From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil… Satellite after 0.16.0 Fix from $2,3002019-10-17 HIGH 7.8 CVE-2019-16519 ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in schedu… Cyber Security after 6.7.900.0 Fix from $1,9502019-10-14 HIGH 7.8 CVE-2019-9745 CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service… Hip Integrator Recognition Configuration Tool No fix yet Fix from $1,9502019-10-14 CRITICAL 9.8 CVE-2018-21025 In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configura… Centreon Vm after 19.04.3 Fix from $2,3002019-10-08 HIGH 8.8 CVE-2019-15747 SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role due to in… Sitos Six Mitigation only Fix from $1,9502019-10-07 HIGH 7.8 CVE-2018-9425 In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of pri… Android Mitigation only Fix from $1,9502019-09-27 MEDIUM 6.5 CVE-2019-14220 An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual mac… Bluestacks after 4.120 Fix from $1,6002019-09-24 HIGH 8.8 CVE-2019-11280 Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x… Pivotal Application Service 2.3.18 / 2.4.14+ Fix from $1,9502019-09-20 HIGH 8.8 CVE-2016-11002 The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation. Extra 1.2.4+ Fix from $1,9502019-09-20 HIGH 8.8 CVE-2016-11003 The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation. Bloom 1.1.1+ Fix from $1,9502019-09-20 HIGH 8.8 CVE-2016-11004 The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation. Monarch 1.2.7+ Fix from $1,9502019-09-20