Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Data Center Network Manager MEDIUM 5.3
CVE-2019-1622EPSS 79%

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $1,600 2019-06-27
Jspxcms HIGH 7.2
CVE-2018-16553

In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.

Mitigation only
Fix from $1,950 2019-06-20
Communications Diameter Signaling Router CRITICAL 9.8
CVE-2019-2729EPSS 89%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected …

Fix: after 7.3.6
Fix from $2,300 2019-06-19
Nagios Xi CRITICAL 9.8
CVE-2018-17148

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios…

Fix: 5.5.4+
Fix from $2,300 2019-06-19
Endoscope Camera Firmware MEDIUM 6.5
CVE-2017-10721

Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet funct…

No fix yet
Fix from $1,600 2019-06-17
Opnsense MEDIUM 6.5
CVE-2018-18958

OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.

Fix: 18.7.7+
Fix from $1,600 2019-06-17
Alaris Gateway Workstation Firmware MEDIUM 5.3
CVE-2019-10962

BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstatio…

Mitigation only
Fix from $1,600 2019-06-13
Simatic Mv420 Firmware HIGH 7.1
CVE-2019-10925

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could escalate privileges by sending s…

Mitigation only
Fix from $1,950 2019-06-12
Awk 3121 Firmware HIGH 7.5
CVE-2018-10691

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, th…

No fix yet
Fix from $1,950 2019-06-07
Unifi Firmware MEDIUM 5.9
CVE-2018-5264

Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a …

No fix yet
Fix from $1,600 2019-06-07
Openstack HIGH 8.0
CVE-2019-3895

An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker c…

Fix: 0.9.0+
Fix from $1,950 2019-06-03
Kace Systems Management Appliance Firmware HIGH 8.8
CVE-2018-5406EPSS 12%

The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS)…

Fix: 9.0.270+
Fix from $1,950 2019-06-03
Osquery HIGH 8.1
CVE-2019-3567

In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a mali…

Fix: 3.4.0+
Fix from $1,950 2019-06-03
Smart Home Controller Firmware MEDIUM 5.7
CVE-2019-11894

A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may res…

Fix: 9.8.905+
Fix from $1,600 2019-05-29
Smart Home Controller Firmware MEDIUM 5.3
CVE-2019-11895

A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may r…

Fix: 9.8.905+
Fix from $1,600 2019-05-29
Smart Home Controller Firmware HIGH 7.1
CVE-2019-11896

A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.…

Fix: 9.8.907+
Fix from $1,950 2019-05-29
Smart Home Controller Firmware HIGH 8.0
CVE-2019-11892

A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may r…

Fix: 9.8.905+
Fix from $1,950 2019-05-29
Mdm9150 Firmware HIGH 7.8
CVE-2018-13895

Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an unprivileged access to phone …

Mitigation only
Fix from $1,950 2019-05-24
Symfony CRITICAL 9.8
CVE-2017-11365

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3…

Patch available
Fix from $2,300 2019-05-23
Open Xchange Appsuite CRITICAL 9.8
CVE-2017-5212

Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.

No fix yet
Fix from $2,300 2019-05-23
Open Xchange Appsuite CRITICAL 9.8
CVE-2017-5863

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

Fix: after 7.8.3
Fix from $2,300 2019-05-22
Open Xchange Appsuite HIGH 8.8
CVE-2017-6912

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

Fix: after 7.8.3
Fix from $1,950 2019-05-22
Open Xchange Appsuite HIGH 8.8
CVE-2017-8340

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

Fix: after 7.8.3
Fix from $1,950 2019-05-22
Receiver CRITICAL 9.8
CVE-2019-11634 KEVEPSS 8%

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Fix: 1904+
Fix from $2,300 2019-05-22
Asa 5500 Firmware MEDIUM 6.7
CVE-2019-1649

A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could al…

Fix: 1.0.18 / 1.1.15+
Fix from $1,600 2019-05-13
Whatsapp MEDIUM 5.9
CVE-2019-3566

A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to r…

Fix: after 2.19.103
Fix from $1,600 2019-05-10
Ge Communicator HIGH 7.8
CVE-2019-6566

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could all…

Fix: 4.0.517+
Fix from $1,950 2019-05-09
Ge Communicator MEDIUM 5.6
CVE-2019-6544

GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain a…

Fix: 4.0.517+
Fix from $1,600 2019-05-09
Fw 1007 Firmware MEDIUM 6.5
CVE-2019-5014

An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An att…

Mitigation only
Fix from $1,600 2019-05-08
Adaptive Security Appliance Software MEDIUM 6.5
CVE-2019-1695

A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could a…

Fix: 6.2.3.12 / 6.3.0.3+
Fix from $1,600 2019-05-03