Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Lefthand HIGH 7.6
CVE-2016-8529

A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 a…

Fix: after 12.5
Fix from $1,950 2018-02-15
Boot2docker HIGH 8.8
CVE-2014-5279

The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for rem…

Fix: after 1.2
Fix from $1,950 2018-02-06
Tririga Application Platform MEDIUM 5.4
CVE-2016-0342

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify a…

Fix: 3.3.2.6 / 3.4.2.3+
Fix from $1,600 2018-02-02
Open Atrium HIGH 7.5
CVE-2014-9504

The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via…

Fix: 7.x-2.26+
Fix from $1,950 2018-02-01
Vzkernel MEDIUM 6.5
CVE-2014-3519

The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow …

Patch available
Fix from $1,600 2018-02-01
Track It\! CRITICAL 9.8
CVE-2016-6598EPSS 19%

BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service cont…

Fix: after 11.4
Fix from $2,300 2018-01-30
Activity Streams MEDIUM 5.4
CVE-2017-9513

Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence…

Fix: 6.3.0+
Fix from $1,600 2018-01-29
Sailfish Os HIGH 7.5
CVE-2015-3888

Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.

Fix: 1.1.2.16+
Fix from $1,950 2018-01-12
Enterprise Linux HIGH 7.8
CVE-2017-15131

It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting…

Fix: 0.15.5+
Fix from $1,950 2018-01-09
Thecartpress Ecommerce Shopping Cart HIGH 7.5
CVE-2015-3302EPSS 22%

The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attacker…

Fix: after 1.3.9
Fix from $1,950 2017-12-29
Fedora HIGH 7.5
CVE-2015-8008

The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intende…

Fix: 1.25.3+
Fix from $1,950 2017-12-29
Diskstation Manager MEDIUM 6.5
CVE-2017-16766

An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows loc…

Fix: 6.0.3-8754-6 / 6.1.4-15217+
Fix from $1,600 2017-12-22
Epmp 1000 Firmware HIGH 8.8
CVE-2017-5254EPSS 54%

In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passw…

Fix: after 3.5
Fix from $1,950 2017-12-20
Calendar MEDIUM 6.5
CVE-2017-15891

Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calend…

Fix: 2.0.1-0242+
Fix from $1,600 2017-12-08
Vtscada HIGH 7.8
CVE-2017-14031

An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and wr…

Fix: after 11.3.03
Fix from $1,950 2017-11-06
Application Policy Infrastructure Controller Enterprise Module HIGH 8.8
CVE-2017-12262

A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow a…

Fix: 1.5+
Fix from $1,950 2017-11-02
Openedge CRITICAL 9.8
CVE-2015-9245

Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh…

Mitigation only
Fix from $2,300 2017-10-31
Subversion HIGH 8.8
CVE-2013-4246

libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a…

Patch available
Fix from $1,950 2017-10-30
Traffic Server CRITICAL 9.8
CVE-2014-3624

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request…

Patch available
Fix from $2,300 2017-10-30
Derby HIGH 7.5
CVE-2010-2232

In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.

Patch available
Fix from $1,950 2017-10-23
Mediawiki MEDIUM 6.5
CVE-2012-4379

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct c…

Fix: after 1.18.4
Fix from $1,600 2017-10-19
Mediawiki HIGH 7.5
CVE-2012-4380

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an accoun…

Fix: after 1.18.4
Fix from $1,950 2017-10-19
Puppet Enterprise HIGH 7.2
CVE-2016-5714

Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protect…

Fix: after 1.7.0
Fix from $1,950 2017-10-18
Perltidy HIGH 7.1
CVE-2014-2277

The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary file…

Fix: after 2012-07-01-1
Fix from $1,950 2017-10-17
Gollum HIGH 8.8
CVE-2014-9489

The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "mast…

Fix: after 4.0.0
Fix from $1,950 2017-10-17
Fiyo Cms CRITICAL 9.8
CVE-2014-9148EPSS 11%

Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administ…

Fix: after 2.0.1.8
Fix from $2,300 2017-10-16
Piwigo MEDIUM 6.5
CVE-2016-10514

url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that co…

Fix: after 2.8.2
Fix from $1,600 2017-10-10
X Pack MEDIUM 6.5
CVE-2017-8447

An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a…

Mitigation only
Fix from $1,600 2017-09-29
X Pack HIGH 8.8
CVE-2017-8448

An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch…

Mitigation only
Fix from $1,950 2017-09-29
Man Db HIGH 7.8
CVE-2015-1336

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain pri…

Fix: after 2.7.6.1
Fix from $1,950 2017-09-28