Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.1 CVE-2018-0751 The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Win… Windows 10 No fix yet Fix from $1,9502018-01-04 HIGH 8.8 CVE-2018-4862 In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an Azure account in suc… Octopus Deploy after 4.1.5 Fix from $1,9502018-01-03 CRITICAL 9.8 CVE-2017-9944 A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of… 7kt Pac1200 Data Manager Firmware 2.03+ Fix from $2,3002017-12-27 HIGH 8.8 CVE-2017-5254EPSS 54% In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passw… Epmp 1000 Firmware after 3.5 Fix from $1,9502017-12-20 MEDIUM 6.7 CVE-2017-14380 In EMC Isilon OneFS 8.1.0.0, 8.0.1.0 - 8.0.1.1, 8.0.0.0 - 8.0.0.4, 7.2.1.0 - 7.2.1.5, 7.2.0.x, and 7.1.1.x, a malicious compliance admin (compadmin) … Isilon Onefs Mitigation only Fix from $1,6002017-12-13 HIGH 8.8 CVE-2017-11319EPSS 6% Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges b… Perspective No fix yet Fix from $1,9502017-12-11 HIGH 8.8 CVE-2017-17384 ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job. Ispconfig Patch available Fix from $1,9502017-12-07 MEDIUM 5.3 CVE-2017-13165 An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937. Android Patch available Fix from $1,6002017-12-06 HIGH 8.1 CVE-2017-15055 TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary i… Teampass 2.1.27.9+ Fix from $1,9502017-11-27 HIGH 8.1 CVE-2017-1000241 The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow a… Openemr after 5.0.1 Fix from $1,9502017-11-17 CRITICAL 9.8 CVE-2017-12635EPSS 100% Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1… Couchdb 1.7.0+ Fix from $2,3002017-11-14 HIGH 7.5 CVE-2017-16520 Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners. Buildmaster 5.8.2+ Fix from $1,9502017-11-11 HIGH 7.8 CVE-2017-14031 An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and wr… Vtscada after 11.3.03 Fix from $1,9502017-11-06 MEDIUM 6.5 CVE-2017-1000156 Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any gr… Mahara Patch available Fix from $1,6002017-11-03 HIGH 7.8 CVE-2017-9450 The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary… Amazon Web Services Cloudformation Bootstrap 1.4-19.10+ Fix from $1,9502017-10-30 MEDIUM 6.5 CVE-2017-15917 In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server. Prtg Network Monitor Mitigation only Fix from $1,6002017-10-26 MEDIUM 6.7 CVE-2017-14329 Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell. Extremexos Mitigation only Fix from $1,6002017-10-23 MEDIUM 6.7 CVE-2017-14330 Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process. Extremexos No fix yet Fix from $1,6002017-10-23 HIGH 8.8 CVE-2017-15013EPSS 7% OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authentica… Documentum Content Server after 7.3 Fix from $1,9502017-10-13 HIGH 7.5 CVE-2017-5722 Incorrect policy enforcement in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows atta… Nuc7i7bnh Firmware Patch available Fix from $1,9502017-10-11 HIGH 7.8 CVE-2017-12728 An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-administrativ… Scada Webserver after 2.02.0007 Fix from $1,9502017-10-05 MEDIUM 6.5 CVE-2017-1000104 The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overal… Config File Provider after 2.16.1 Fix from $1,6002017-10-05 CRITICAL 9.8 CVE-2017-14349 An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and mon… Sitescope Mitigation only Fix from $2,3002017-09-30 MEDIUM 6.5 CVE-2017-8447 An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a… X Pack Mitigation only Fix from $1,6002017-09-29 HIGH 8.8 CVE-2017-8448 An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch… X Pack Mitigation only Fix from $1,9502017-09-29 HIGH 7.8 CVE-2017-9724 In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to gain access to kernel memory, s… Android after 8.0 Fix from $1,9502017-09-21 HIGH 7.3 CVE-2017-14484 The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by cr… Sci Mathematics Gimps Patch available Fix from $1,9502017-09-15 MEDIUM 6.3 CVE-2017-14124 In eLux RP 5.x before 5.5.1000 LTSR and 5.6.x before 5.6.2 CR when classic desktop mode is used, it is possible to start applications other than defi… Rp after 5.6.0 Fix from $1,6002017-09-13 HIGH 7.8 CVE-2017-14312 Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root ac… Nagios Core after 4.3.4 Fix from $1,9502017-09-11 HIGH 8.8 CVE-2016-0732 The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with… Cf Release after 229 Fix from $1,9502017-09-07