Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Libvirt Slaves MEDIUM 6.5
CVE-2019-10472

A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH ser…

Fix: after 1.8.5
Fix from $1,600 2019-10-23
Dynatrace Application Monitoring MEDIUM 6.5
CVE-2019-10463

A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker…

Fix: after 2.1.4
Fix from $1,600 2019-10-23
Cloud Foundation HIGH 7.5
CVE-2019-16919

Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account…

Fix: 1.8.4+
Fix from $1,950 2019-10-18
Uplay HIGH 7.8
CVE-2019-14737

Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.

No fix yet
Fix from $1,950 2019-10-14
Patrol Agent HIGH 7.8
CVE-2019-17043

An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevat…

Mitigation only
Fix from $1,950 2019-10-14
Patrol Agent HIGH 7.8
CVE-2019-17044

An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" …

Patch available
Fix from $1,950 2019-10-14
Android HIGH 7.8
CVE-2019-2114

In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permissi…

Patch available
Fix from $1,950 2019-10-11
Android HIGH 7.8
CVE-2019-2173

In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead …

Patch available
Fix from $1,950 2019-10-11
Vsa MEDIUM 6.7
CVE-2019-14510

An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdm…

Fix: after 9.5.0.22
Fix from $1,600 2019-10-11
Simpolio HIGH 8.8
CVE-2015-9474

The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.

No fix yet
Fix from $1,950 2019-10-10
Pont HIGH 8.8
CVE-2015-9475

The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.

No fix yet
Fix from $1,950 2019-10-10
Teardrop HIGH 8.8
CVE-2015-9476

The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.

Mitigation only
Fix from $1,950 2019-10-10
Vernissage HIGH 8.8
CVE-2015-9477

The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.

Mitigation only
Fix from $1,950 2019-10-10
Nix HIGH 7.8
CVE-2019-17365

Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is worl…

Fix: after 2.3
Fix from $1,950 2019-10-09
Viaware CRITICAL 9.8
CVE-2019-17124EPSS 23%

Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

No fix yet
Fix from $2,300 2019-10-09
Netaddr CRITICAL 9.8
CVE-2019-17383

The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesy…

Fix: 1.5.3 / 2.0.4+
Fix from $2,300 2019-10-09
Antivirus HIGH 7.8
CVE-2019-16913

PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permissi…

No fix yet
Fix from $1,950 2019-10-07
Suse Linux Enterprise Server HIGH 7.1
CVE-2019-3688

The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterpris…

Mitigation only
Fix from $1,950 2019-10-07
Link HIGH 7.8
CVE-2018-19592

The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take cont…

Mitigation only
Fix from $1,950 2019-09-27
iOS MEDIUM 6.7
CVE-2019-12670

A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the name…

Mitigation only
Fix from $1,600 2019-09-25
Nfs Utils CRITICAL 9.8
CVE-2019-3689

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and…

Fix: after 2.1.1-6.10.2
Fix from $2,300 2019-09-19
Ipc Hdw1x2x Firmware HIGH 8.8
CVE-2019-9679

Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected product…

Fix: 2019-08-18+
Fix from $1,950 2019-09-18
Beego MEDIUM 5.5
CVE-2019-16355

The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.

No fix yet
Fix from $1,600 2019-09-16
Humatrix HIGH 7.5
CVE-2019-16106

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the r…

Mitigation only
Fix from $1,950 2019-09-10
Limesurvey HIGH 7.2
CVE-2019-16186

In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Limesurvey HIGH 7.2
CVE-2019-16185

In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Wtf MEDIUM 5.5
CVE-2019-15716

WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the per…

Fix: 0.19.0+
Fix from $1,600 2019-08-28
Gpu Driver HIGH 7.1
CVE-2019-5687

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which …

Mitigation only
Fix from $1,950 2019-08-06
Nexus Repository Manager HIGH 7.5
CVE-2019-9630

Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and im…

Fix: 3.17.0+
Fix from $1,950 2019-07-08
Enterprise System Manager HIGH 7.0
CVE-2019-7588

A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be a…

Fix: after 5.12.2
Fix from $1,950 2019-06-18