Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Galaxy Apps HIGH 7.0
CVE-2018-10500

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An att…

Fix: 6.4.0.15+
Fix from $1,950 2018-09-24
Ip Office HIGH 8.8
CVE-2018-15610

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. A…

No fix yet
Fix from $1,950 2018-09-12
Modicon M221 Firmware CRITICAL 9.8
CVE-2018-7791

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior t…

Fix: 1.6.2.0+
Fix from $2,300 2018-08-29
PostgreSQL HIGH 8.1
CVE-2016-7048

The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary …

Fix: 9.1.24 / 9.2.19+
Fix from $1,950 2018-08-20
Web Security Appliance MEDIUM 6.7
CVE-2018-0428

A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate pri…

Mitigation only
Fix from $1,600 2018-08-15
Tsw X60 Firmware CRITICAL 9.8
CVE-2018-10630EPSS 11%

For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, a…

Fix: 1.502.0047.001 / 2.001.0037.001+
Fix from $2,300 2018-08-10
Automation License Manager MEDIUM 5.8
CVE-2018-11456

A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could sen…

Fix: 5.3.4.4+
Fix from $1,600 2018-08-07
Enterprise Linux MEDIUM 6.5
CVE-2017-12171EPSS 8%

A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…

Mitigation only
Fix from $1,600 2018-07-26
Cloudforms MEDIUM 6.5
CVE-2017-2664

CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of Cl…

Fix: 5.7.3 / 5.8.1+
Fix from $1,600 2018-07-26
Cloudforms HIGH 7.8
CVE-2018-10905

CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an…

Mitigation only
Fix from $1,950 2018-07-24
Vbond Orchestrator HIGH 8.8
CVE-2018-0343

A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arb…

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Itrack Easy MEDIUM 5.9
CVE-2016-6543

A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthe…

Mitigation only
Fix from $1,600 2018-07-13
Websphere Cast Iron Cloud Integration HIGH 7.5
CVE-2013-2972

IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM X-Force ID: 83868.

Patch available
Fix from $1,950 2018-07-11
Ceph Storage MEDIUM 6.5
CVE-2018-1129

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who…

Patch available
Fix from $1,600 2018-07-10
Ec 61850 System Configurator Firmware HIGH 7.8
CVE-2018-4858

A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is in…

Fix: 3.11 / 5.80+
Fix from $1,950 2018-07-09
Dogtagpki HIGH 8.1
CVE-2018-1080

Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and…

Fix: after 10.6.1
Fix from $1,950 2018-07-03
Rapidpoint 400 Firmware HIGH 8.8
CVE-2018-4845

A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens …

Fix: 3.3+
Fix from $1,950 2018-06-26
Enterprise Linux Desktop HIGH 8.8
CVE-2016-9905

A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and …

Fix: 45.6.0+
Fix from $1,950 2018-06-11
Open Build Service HIGH 7.5
CVE-2011-4181

A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases…

Fix: 2.1.16+
Fix from $1,950 2018-06-11
Drive Server MEDIUM 6.5
CVE-2018-8922

Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders vi…

Mitigation only
Fix from $1,600 2018-06-01
Hapi MEDIUM 5.3
CVE-2015-9236

Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allo…

Fix: 11.0.0+
Fix from $1,600 2018-05-31
Hapi MEDIUM 5.9
CVE-2015-9243

When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config …

Fix: 11.1.4+
Fix from $1,600 2018-05-29
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8656

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p…

Mitigation only
Fix from $1,950 2018-05-22
Computrace Agent MEDIUM 6.7
CVE-2009-5150

Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communi…

No fix yet
Fix from $1,600 2018-05-11
Computrace Agent MEDIUM 6.7
CVE-2009-5151

The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for t…

No fix yet
Fix from $1,600 2018-05-11
Android HIGH 7.8
CVE-2013-6272

The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended ac…

Fix: after 4.4.2
Fix from $1,950 2018-05-02
Spss Modeler MEDIUM 5.4
CVE-2013-6739

IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.

Fix: 16.0.0.0+
Fix from $1,600 2018-04-27
Integrated Management Module Firmware HIGH 7.4
CVE-2014-0881

The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain s…

Fix: after 3.56
Fix from $1,950 2018-04-25
Openstack HIGH 7.5
CVE-2016-9599

puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of T…

Mitigation only
Fix from $1,950 2018-04-24
Security Identity Manager MEDIUM 5.3
CVE-2014-6109

IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7…

Patch available
Fix from $1,600 2018-04-20