Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2018-8841 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc… Webaccess 8.3.1+ Fix from $1,9502018-05-15 HIGH 8.8 CVE-2018-8853 Philips Brilliance CT devices operate user functions from within a contained kiosk in a Microsoft Windows operating system. Windows boots by default … Brilliance Firmware 64 after 4.1.6 Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10168 TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-p… Eap Controller No fix yet Fix from $1,9502018-05-03 MEDIUM 5.3 CVE-2018-0245 A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker … Wireless Lan Controller Software Mitigation only Fix from $1,6002018-05-02 HIGH 7.5 CVE-2018-10550 In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to. Octopus Deploy 2018.4.7+ Fix from $1,9502018-04-30 HIGH 7.8 CVE-2018-10079 Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data… Watchdog Console No fix yet Fix from $1,9502018-04-20 HIGH 7.8 CVE-2018-10190 A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run … Private Internet Access Mitigation only Fix from $1,9502018-04-17 HIGH 8.8 CVE-2018-10172 7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivileg… 7 Zip after 18.01 Fix from $1,9502018-04-16 MEDIUM 5.5 CVE-2018-4173 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar"… Iphone Os 10.13.4 / 11.3+ Fix from $1,6002018-04-13 HIGH 7.8 CVE-2017-0358 Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe… Debian Linux after 2016.2.22 Fix from $1,9502018-04-13 MEDIUM 6.0 CVE-2017-5703 Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially l… Core I7 8550u Mitigation only Fix from $1,6002018-04-03 CRITICAL 9.1 CVE-2018-1000141 I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining un… I\, Librarian after 4.9 Fix from $2,3002018-03-23 HIGH 8.8 CVE-2017-0932 Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation on the in… Edgeos after 1.9.1.1 Fix from $1,9502018-03-22 HIGH 8.8 CVE-2017-0934 Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file… Edgeos after 1.9.1 Fix from $1,9502018-03-22 HIGH 8.8 CVE-2017-0935 Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the fi… Edgeos after 1.9.1.1 Fix from $1,9502018-03-22 HIGH 8.8 CVE-2017-5736 An elevation of privilege in Intel Software Guard Extensions Platform Software Component before 1.9.105.42329 allows a local attacker to execute arbi… Software Guard Extensions Platform Software Component 1.9.105.42329+ Fix from $1,9502018-03-20 HIGH 7.2 CVE-2017-8187 Huawei FusionSphere OpenStack V100R006C00SPC102(NFV) has a privilege escalation vulnerability. Due to improper privilege restrictions, an attacker wi… Fusionsphere Openstack Firmware Mitigation only Fix from $1,9502018-03-20 MEDIUM 6.7 CVE-2018-4844 A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.1… Simatic Wincc Oa Ui 3.15.10+ Fix from $1,6002018-03-20 HIGH 7.5 CVE-2018-1000133 Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that can result in A standard unp… Trident Patch available Fix from $1,9502018-03-16 HIGH 7.8 CVE-2018-1182 An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle … Rsa Identity Governance And Lifecycle Mitigation only Fix from $1,9502018-03-08 MEDIUM 6.7 CVE-2017-6152 A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on th… Big Iq Centralized Management after 5.2.0 Fix from $1,6002018-03-08 HIGH 7.0 CVE-2018-0821 AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vul… Windows 10 Patch available Fix from $1,9502018-02-15 HIGH 7.4 CVE-2018-1000028 Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS serve… Linux Kernel after 4.15.7 Fix from $1,9502018-02-09 MEDIUM 5.5 CVE-2017-10689 In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a f… Ubuntu Linux 1.10.10 / 5.3.4+ Fix from $1,6002018-02-09 MEDIUM 6.5 CVE-2017-10690 In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from.… Satellite 5.3.4 / 2017.3.4+ Fix from $1,6002018-02-09 HIGH 8.8 CVE-2017-15536 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authentic… Data Science Workbench 1.2.0+ Fix from $1,9502018-02-05 HIGH 8.8 CVE-2018-5706 An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System … Octopus Deploy 4.1.9+ Fix from $1,9502018-01-16 MEDIUM 6.5 CVE-2018-0010 A vulnerability in the Juniper Networks Junos Space Security Director allows a user who does not have SSH access to a device to reuse the URL that wa… Junos Space Patch available Fix from $1,6002018-01-10 MEDIUM 5.4 CVE-2017-1493 IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access c… Urbancode Deploy Mitigation only Fix from $1,6002018-01-09 HIGH 7.8 CVE-2018-0748 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1… Windows 10 Patch available Fix from $1,9502018-01-04