Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2018-3635 Insufficient input validation in installer in Intel Rapid Store Technology (RST) before version 16.7 may allow an unprivileged user to potentially el… Rapid Storage Technology 16.7+ Fix from $1,9502018-11-14 HIGH 7.2 CVE-2018-2481 In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a transaction code reserved for cust… Advanced Business Application Programming after 7.11 Fix from $1,9502018-11-13 HIGH 8.8 CVE-2018-15762 Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior t… Operations Manager 2.0.24 / 2.1.15+ Fix from $1,9502018-11-02 HIGH 7.8 CVE-2018-14828 Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perfo… Webaccess after 8.3.1 Fix from $1,9502018-10-23 HIGH 7.8 CVE-2018-15592 An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with ele… Workspace Control 10.3.10.0+ Fix from $1,9502018-10-15 CRITICAL 9.8 CVE-2018-12596EPSS 22% Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages vi… Ektron Cms Patch available Fix from $2,3002018-10-10 HIGH 7.2 CVE-2018-13802 A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged user account access via SSH … Rox Ii Firmware 2.12.1+ Fix from $1,9502018-10-10 HIGH 8.8 CVE-2018-13801 A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp and valid low-privileged user … Rox Ii Firmware 2.12.1+ Fix from $1,9502018-10-10 HIGH 8.8 CVE-2018-17855 An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in th… Joomla\! 3.8.13+ Fix from $1,9502018-10-09 HIGH 7.8 CVE-2018-0437 A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administr… Umbrella Enterprise Roaming Client 2.1.118 / 4.6.1098+ Fix from $1,9502018-10-05 HIGH 7.8 CVE-2018-0438 A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administr… Umbrella Enterprise Roaming Client 2.1.127+ Fix from $1,9502018-10-05 CRITICAL 9.8 CVE-2018-0425 A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, … Rv110w Firmware 1.0.3.44+ Fix from $2,3002018-10-05 HIGH 8.7 CVE-2018-0436 A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization… Webex Teams 10.6.0+ Fix from $1,9502018-10-05 MEDIUM 6.5 CVE-2018-14808 Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on the affected products. Ams Device Manager after 13.5 Fix from $1,6002018-10-01 MEDIUM 5.5 CVE-2015-9267 Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This al… Debian Linux 2.49+ Fix from $1,6002018-10-01 MEDIUM 5.5 CVE-2018-1550 IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to o… Tivoli Storage Manager after 8.1.4.1 Fix from $1,6002018-09-26 HIGH 7.8 CVE-2018-10502 This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 4.2.18.2. An att… Galaxy Apps 4.2.18.2+ Fix from $1,9502018-09-24 HIGH 8.8 CVE-2018-11614 This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker… Samsung Members 2.4.25+ Fix from $1,9502018-09-24 MEDIUM 5.8 CVE-2018-14825 On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN… Cn80 Mitigation only Fix from $1,6002018-09-24 HIGH 8.8 CVE-2018-11786 In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri… Karaf 4.2.0+ Fix from $1,9502018-09-18 CRITICAL 9.1 CVE-2018-13799 A vulnerability has been identified in SIMATIC WinCC OA V3.14 and prior (All versions < V3.14-P021). Improper access control to a data point of the a… Simatic Wincc Open Architecture after 3.14 Fix from $2,3002018-09-12 HIGH 7.8 CVE-2018-10853 A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current … Ubuntu Linux 4.18+ Fix from $1,9502018-09-11 HIGH 7.8 CVE-2018-10514 A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate … Antivirus \+ Security after 12.0 Fix from $1,9502018-08-30 HIGH 7.8 CVE-2018-15912 An issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can install or remove arbitrary p… Manjaro Linux after 20180716-1 Fix from $1,9502018-08-29 HIGH 7.8 CVE-2018-14791 Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable and library files on the affec… Deltav Mitigation only Fix from $1,9502018-08-23 HIGH 7.8 CVE-2018-14787 In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated priv… Intellispace Cardiovascular after 4.1 Fix from $1,9502018-08-22 HIGH 8.8 CVE-2018-1000648 LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can resul… Librehealth Ehr No fix yet Fix from $1,9502018-08-20 HIGH 7.2 CVE-2018-1000634 The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can res… Omero after 5.4.6 Fix from $1,9502018-08-20 MEDIUM 6.7 CVE-2018-0428 A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate pri… Web Security Appliance Mitigation only Fix from $1,6002018-08-15 MEDIUM 6.5 CVE-2018-14836 Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perfor… Subrion Cms Mitigation only Fix from $1,6002018-08-02