Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 6.5 CVE-2018-1999032 A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier in GlobalConfig.java that al… Pangolin Connector For Testrail after 2.1 Fix from $1,6002018-08-01 HIGH 8.8 CVE-2018-0613 NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX… Calsos Csdx Firmware after 4.37210411 Fix from $1,9502018-07-26 HIGH 7.8 CVE-2018-10906 In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use… Debian Linux 2.9.8 / 3.2.5+ Fix from $1,9502018-07-24 HIGH 8.8 CVE-2018-0343 A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arb… Vbond Orchestrator 18.3.0+ Fix from $1,9502018-07-18 HIGH 8.8 CVE-2016-9489 In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own … Manageengine Applications Manager Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2018-0024 An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain … Junos Mitigation only Fix from $1,9502018-07-11 HIGH 8.2 CVE-2018-3682 BMC Firmware in Intel server boards, compute modules, and systems potentially allow an attacker with administrative privileges to make unauthorized r… Bmc Firmware Mitigation only Fix from $1,9502018-07-10 CRITICAL 9.8 CVE-2018-9853 Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process by leveraging the ability to … Freesshd Mitigation only Fix from $2,3002018-07-10 HIGH 8.4 CVE-2018-5884 Improper Access Control in Multimedia in Snapdragon Mobile and Snapdragon Wear, Non-standard applications without permission may acquire permission o… Mdm9607 Firmware Mitigation only Fix from $1,9502018-07-06 HIGH 7.8 CVE-2018-13405 The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, i… Linux Kernel after 3.16 Fix from $1,9502018-07-06 MEDIUM 5.5 CVE-2018-9334 The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allo… Pan Os after 8.0.8 Fix from $1,6002018-07-03 HIGH 8.8 CVE-2018-4845 A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens … Rapidpoint 400 Firmware 3.3+ Fix from $1,9502018-06-26 HIGH 7.2 CVE-2018-0610 Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code… Zenphoto after 1.4.14 Fix from $1,9502018-06-26 MEDIUM 5.3 CVE-2018-0573 baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a con… Basercms after 4.1.0.1 Fix from $1,6002018-06-26 MEDIUM 6.5 CVE-2018-12884 In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastruc… Octopus Deploy Mitigation only Fix from $1,6002018-06-26 HIGH 8.8 CVE-2017-2672 A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file woul… Satellite 1.15+ Fix from $1,9502018-06-21 CRITICAL 9.8 CVE-2018-9021EPSS 10% An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with s… Privileged Access Manager after 2.8.2 Fix from $2,3002018-06-18 CRITICAL 9.8 CVE-2018-9022EPSS 13% An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or command… Privileged Access Manager after 2.8.2 Fix from $2,3002018-06-18 HIGH 7.8 CVE-2018-1460 IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writable file, which could be used… Puredata System For Analytics No fix yet Fix from $1,9502018-06-15 HIGH 7.5 CVE-2018-5166 WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access … Ubuntu Linux 60.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7803 When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforc… Enterprise Linux Desktop 52.3.0 / 55.0+ Fix from $1,9502018-06-11 MEDIUM 5.5 CVE-2017-7767 The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater,… Firefox 52.2.0 / 54.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7782 An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. No… Firefox 52.3.0 / 55.0+ Fix from $1,6002018-06-11 MEDIUM 5.5 CVE-2017-5409 The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parame… Firefox 45.8.0 / 52.0+ Fix from $1,6002018-06-11 HIGH 8.8 CVE-2018-11190 Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 2 of 6). Disk Backup 4.0.3.1+ Fix from $1,9502018-06-02 MEDIUM 6.5 CVE-2018-1495 IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a… Flashsystem 900 Firmware No fix yet Fix from $1,6002018-05-29 MEDIUM 6.5 CVE-2018-1134 An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by chan… Moodle after 3.4.2 Fix from $1,6002018-05-25 MEDIUM 6.2 CVE-2017-14187 A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions al… Fortios after 5.6.2 Fix from $1,6002018-05-24 HIGH 8.8 CVE-2018-11323 An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissi… Joomla\! 3.8.8+ Fix from $1,9502018-05-22 HIGH 8.8 CVE-2018-1000400 Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities th… Cri O 1.9.0+ Fix from $1,9502018-05-18