Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Cpanel MEDIUM 6.5
CVE-2016-10856

cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).

Fix: 11.48.4.8 / 11.50.3.1+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 6.5
CVE-2016-10857

cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).

Fix: 11.48.4.8 / 11.50.3.1+
Fix from $1,600 2019-08-01
Cpanel HIGH 8.1
CVE-2016-10860

cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).

Fix: 11.48.4.8 / 11.50.3.1+
Fix from $1,950 2019-08-01
Satellite HIGH 7.4
CVE-2014-8183

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker wi…

Fix: 1.15.6+
Fix from $1,950 2019-08-01
Libvirt HIGH 7.8
CVE-2019-10161

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specif…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-07-30
Novajoin HIGH 8.8
CVE-2019-10138

A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked suf…

Fix: 1.1.1+
Fix from $1,950 2019-07-30
Edx Platform HIGH 7.5
CVE-2017-18380

edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain n…

Fix: 2017-08-03+
Fix from $1,950 2019-07-30
Eclass Ip CRITICAL 9.8
CVE-2019-9884

eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management …

Fix: 2.5.10.2.1+
Fix from $2,300 2019-07-25
Mdm9206 Firmware HIGH 7.8
CVE-2018-13896

XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBL_SEC stage…

Mitigation only
Fix from $1,950 2019-07-22
Cloud Foundry Uaa MEDIUM 5.4
CVE-2019-3794

Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking att…

Fix: 73.4.0+
Fix from $1,600 2019-07-18
Pyxtrlock HIGH 7.8
CVE-2019-1010316

pyxtrlock 0.3 and earlier is affected by: Incorrect Access Control. The impact is: False locking impression when run in a non-X11 session. The fixed …

Fix: after 0.3
Fix from $1,950 2019-07-11
Panelview 5510 Firmware CRITICAL 9.8
CVE-2019-10970

In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a r…

Fix: 4.003 / 5.002+
Fix from $2,300 2019-07-11
Eclass Ip HIGH 7.5
CVE-2019-9886

Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass befo…

Fix: 2.5.10.2.1+
Fix from $1,950 2019-07-11
Cache MEDIUM 5.4
CVE-2018-17151

Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.

No fix yet
Fix from $1,600 2019-07-11
Adc V522ir Firmware HIGH 7.2
CVE-2018-19588

Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.

No fix yet
Fix from $1,950 2019-07-11
Cloudera Manager HIGH 8.1
CVE-2018-11744

Cloudera Manager through 5.15 has Incorrect Access Control.

Fix: after 6.1.0
Fix from $1,950 2019-07-11
GitLab HIGH 8.1
CVE-2018-19576

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allo…

Fix: 11.3.11 / 11.4.8+
Fix from $1,950 2019-07-10
GitLab MEDIUM 6.5
CVE-2018-19496

An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. Ther…

Fix: 11.3.11 / 11.4.8+
Fix from $1,600 2019-07-10
GitLab MEDIUM 5.3
CVE-2018-19577

Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulne…

Fix: 11.3.11 / 11.4.8+
Fix from $1,600 2019-07-10
Lacerte MEDIUM 5.9
CVE-2018-14833

Intuit Lacerte 2017 has Incorrect Access Control.

Fix: after 2017
Fix from $1,600 2019-07-09
Application Policy Infrastructure Controller MEDIUM 6.5
CVE-2019-1890

A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mo…

Mitigation only
Fix from $1,600 2019-07-04
Odoo HIGH 8.1
CVE-2018-14859

Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated…

Patch available
Fix from $1,950 2019-07-03
Odoo HIGH 8.1
CVE-2018-14863

Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to c…

Patch available
Fix from $1,950 2019-07-03
Odoo MEDIUM 6.5
CVE-2018-14864

Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remo…

Patch available
Fix from $1,600 2019-07-03
Electronic Identification Cards Client HIGH 8.8
CVE-2019-13028

An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to…

Fix: 3.0.3 / 3.1.2+
Fix from $1,950 2019-06-28
Minimed 508 Firmware HIGH 7.1
CVE-2019-10964

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor tr…

Mitigation only
Fix from $1,950 2019-06-28
Containerized Data Importer MEDIUM 6.5
CVE-2019-10175

A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine wheth…

Mitigation only
Fix from $1,600 2019-06-28
Odoo MEDIUM 5.3
CVE-2018-14867

Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to po…

Patch available
Fix from $1,600 2019-06-28
Odoo CRITICAL 9.8
CVE-2018-14885

Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker…

Patch available
Fix from $2,300 2019-06-28
Data Center Network Manager CRITICAL 9.8
CVE-2019-1619EPSS 83%

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $2,300 2019-06-27