Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Endpoint Security MEDIUM 5.5
CVE-2019-3653

Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user t…

Fix: 10.6.1+
Fix from $1,600 2019-10-09
iOS MEDIUM 6.7
CVE-2019-12670

A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the name…

Mitigation only
Fix from $1,600 2019-09-25
iOS HIGH 8.8
CVE-2019-12648

A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access t…

Mitigation only
Fix from $1,950 2019-09-25
Smart Battery A4 Firmware CRITICAL 9.8
CVE-2019-15068

A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/…

Mitigation only
Fix from $2,300 2019-09-25
Bmxnor0200h Firmware HIGH 8.8
CVE-2019-6810

CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the exec…

Mitigation only
Fix from $1,950 2019-09-17
Access HIGH 7.5
CVE-2019-11899

An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. With Bosch…

Fix: after 3.7
Fix from $1,950 2019-09-12
Ca Client Automation CRITICAL 9.8
CVE-2019-13656EPSS 6%

An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote a…

No fix yet
Fix from $2,300 2019-09-06
Totemomail MEDIUM 5.3
CVE-2018-15513

Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.

Mitigation only
Fix from $1,600 2019-08-30
User Email Verification For Woocommerce CRITICAL 9.8
CVE-2018-21007

The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.

Fix: 3.2.0+
Fix from $2,300 2019-08-29
Profile Builder HIGH 7.5
CVE-2015-9337

The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.

Fix: 2.1.4+
Fix from $1,950 2019-08-22
Secure Firewall Threat Defense HIGH 7.5
CVE-2019-12627

A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a…

Fix: 6.4.0.4+
Fix from $1,950 2019-08-21
Nest Cam Iq Indoor Firmware HIGH 7.5
CVE-2019-5036

An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specia…

No fix yet
Fix from $1,950 2019-08-20
Invite Anyone CRITICAL 9.8
CVE-2017-18543

The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.

Fix: 1.3.16+
Fix from $2,300 2019-08-16
One\+ Firmware HIGH 8.8
CVE-2018-20957

The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.

Fix: 2018-06-12+
Fix from $1,950 2019-08-08
Cpanel MEDIUM 5.5
CVE-2016-10799

cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).

Fix: 11.52.6.2 / 11.54.0.26+
Fix from $1,600 2019-08-07
Cpanel HIGH 8.8
CVE-2016-10802

cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).

Fix: 11.52.6.2 / 11.54.0.26+
Fix from $1,950 2019-08-07
Cpanel HIGH 8.8
CVE-2016-10792

cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).

Fix: 11.52.6.6 / 11.54.0.29+
Fix from $1,950 2019-08-06
Siprotec 5 Digsi Device Driver CRITICAL 9.8
CVE-2019-10938

A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 …

Patch available
Fix from $2,300 2019-08-02
Cpanel MEDIUM 6.3
CVE-2017-18403

cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).

Fix: 62.0.35 / 64.0.42+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.5
CVE-2017-18416

cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).

Fix: 56.0.52 / 60.0.48+
Fix from $1,600 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDe…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify …

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emula…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 5.5
CVE-2017-18385

cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).

Fix: 62.0.35 / 64.0.42+
Fix from $1,600 2019-08-02
Cpanel HIGH 8.8
CVE-2016-10820

cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).

Fix: 11.50.5.2 / 11.52.4.1+
Fix from $1,950 2019-08-01
Cpanel HIGH 8.1
CVE-2016-10830

cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).

Fix: 11.50.5.2 / 11.52.4.1+
Fix from $1,950 2019-08-01
Cpanel MEDIUM 6.5
CVE-2018-20930

cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).

Fix: 62.0.42 / 68.0.33+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 6.5
CVE-2016-10838

cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,600 2019-08-01
Cpanel HIGH 7.5
CVE-2015-9291

cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).

Fix: 11.52.0.13+
Fix from $1,950 2019-08-01
Cpanel MEDIUM 6.5
CVE-2016-10852

cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,600 2019-08-01