Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Container Runtime HIGH 8.8
CVE-2019-3779

Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust …

Fix: 0.29.0+
Fix from $1,950 2019-03-08
Iks G6824a Firmware HIGH 7.5
CVE-2019-6520

Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration ch…

Fix: after 4.5
Fix from $1,950 2019-03-05
Hyperflex Hx Data Platform HIGH 7.8
CVE-2019-1664

A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in …

Mitigation only
Fix from $1,950 2019-02-21
Hyperflex Hx Data Platform MEDIUM 5.3
CVE-2019-1666

A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphit…

Mitigation only
Fix from $1,600 2019-02-21
Yingzhipython CRITICAL 9.1
CVE-2013-5654

Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage

No fix yet
Fix from $2,300 2019-02-15
Telepresence Management Suite MEDIUM 5.3
CVE-2019-1660

A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, rem…

Mitigation only
Fix from $1,600 2019-02-07
Facslyric MEDIUM 6.8
CVE-2019-6517

BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November 2017 and November 2018 and BD…

Mitigation only
Fix from $1,600 2019-02-06
Control For Beaglebone Sl CRITICAL 9.8
CVE-2018-10612

In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not…

Fix: 3.5.14.0+
Fix from $2,300 2019-01-29
Rv320 Firmware HIGH 7.5
CVE-2019-1653 KEVEPSS 100%

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentic…

Mitigation only
Fix from $1,950 2019-01-24
Sd Wan HIGH 8.0
CVE-2019-1647

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized ac…

Fix: 18.4.0+
Fix from $1,950 2019-01-24
Identity Services Engine HIGH 7.2
CVE-2018-15459

A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain add…

Mitigation only
Fix from $1,950 2019-01-23
Service Desk Manager HIGH 7.5
CVE-2018-19634

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

Patch available
Fix from $1,950 2019-01-22
iOS MEDIUM 6.5
CVE-2018-0484

A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a vi…

Mitigation only
Fix from $1,600 2019-01-10
Tim 1531 Irc Firmware CRITICAL 10.0
CVE-2018-13816

A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although con…

Fix: 2.0+
Fix from $2,300 2018-12-12
Zxin10 CRITICAL 9.8
CVE-2018-7364EPSS 10%

All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to imprope…

No fix yet
Fix from $2,300 2018-12-07
Rails HIGH 7.5
CVE-2018-16476

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserializ…

Fix: 4.2.11 / 5.0.7.1+
Fix from $1,950 2018-11-30
Linux Pam HIGH 8.1
CVE-2018-17953

A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead…

Mitigation only
Fix from $1,950 2018-11-27
Zxhn F670 Firmware HIGH 8.8
CVE-2018-7362

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which may allows an unauthorized user…

Fix: 1.1.10p3t18+
Fix from $1,950 2018-11-16
Stealthwatch Enterprise CRITICAL 9.8
CVE-2018-15394

A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypa…

Fix: after 6.10.2
Fix from $2,300 2018-11-08
Vgo Firmware MEDIUM 6.8
CVE-2018-17931

If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to a…

Fix: after 3.0.3.52164
Fix from $1,600 2018-10-30
Nextcloud Server HIGH 8.1
CVE-2018-16466

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess token…

Fix: 12.0.11 / 13.0.6+
Fix from $1,950 2018-10-30
Webaccess HIGH 7.8
CVE-2018-17908

WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the i…

Fix: after 8.3.2
Fix from $1,950 2018-10-29
Saga1 L8b Firmware HIGH 8.8
CVE-2018-17921

SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair the device without human int…

Mitigation only
Fix from $1,950 2018-10-24
Wireless Lan Controller Software MEDIUM 5.4
CVE-2018-15395

A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authentica…

Mitigation only
Fix from $1,600 2018-10-17
Ios Xe MEDIUM 6.7
CVE-2018-15371

A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication …

Mitigation only
Fix from $1,600 2018-10-05
Ios Xe HIGH 8.1
CVE-2018-15372

A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco …

Mitigation only
Fix from $1,950 2018-10-05
Email Security Appliance MEDIUM 5.3
CVE-2018-0447

A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthen…

Mitigation only
Fix from $1,600 2018-10-05
Webex Teams HIGH 8.7
CVE-2018-0436

A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization…

Fix: 10.6.0+
Fix from $1,950 2018-10-05
Ams Device Manager CRITICAL 9.8
CVE-2018-14804

Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.

Fix: after 13.5
Fix from $2,300 2018-10-01
Aura Communication Manager MEDIUM 6.7
CVE-2018-15611

A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the l…

Fix: 7.1.3.1+
Fix from $1,600 2018-09-27