Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Struxureware Building Operations Automation Server As Firmware HIGH 7.2
CVE-2016-2278EPSS 13%

Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated adminis…

Fix: after 1.7
Fix from $1,950 2016-03-02
Vesp211 Eu Firmware CRITICAL 9.8
CVE-2016-2275

The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on t…

Mitigation only
Fix from $2,300 2016-02-21
Rails MEDIUM 5.3
CVE-2015-7577

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.…

Fix: after 3.2.22
Fix from $1,600 2016-02-16
Email Security Appliance Firmeware HIGH 7.5
CVE-2016-1315

The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allow…

Mitigation only
Fix from $1,950 2016-02-12
Django MEDIUM 5.5
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and creat…

Mitigation only
Fix from $1,600 2016-02-08
Bamboo CRITICAL 9.1
CVE-2015-8361

Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers …

Patch available
Fix from $2,300 2016-02-08
Prime Security Manager HIGH 8.8
CVE-2016-1301

The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9…

Mitigation only
Fix from $1,950 2016-02-07
Nx Os HIGH 8.8
CVE-2016-1302

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switche…

Fix: 2.50+
Fix from $1,950 2016-02-07
Kubernetes HIGH 7.7
CVE-2016-1905

The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a …

Mitigation only
Fix from $1,950 2016-02-03
Php Openid HIGH 8.8
CVE-2016-2049

examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME elem…

Mitigation only
Fix from $1,950 2016-02-01
Shareit MEDIUM 6.1
CVE-2016-1492

The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier…

No fix yet
Fix from $1,600 2016-01-26
Identity Services Engine Software MEDIUM 6.5
CVE-2015-6317

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct re…

Mitigation only
Fix from $1,600 2016-01-23
Player MEDIUM 6.3
CVE-2015-6933

The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x…

Patch available
Fix from $1,600 2016-01-09
Ucmdb Browser HIGH 8.4
CVE-2015-6862

HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.

Patch available
Fix from $1,950 2016-01-08
Change And Configuration Management Database MEDIUM 5.4
CVE-2015-5017

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 befor…

Mitigation only
Fix from $1,600 2016-01-03
Mq Appliance M2000 MEDIUM 5.6
CVE-2015-1985

The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by le…

Fix: after 8.0.0.3
Fix from $1,600 2016-01-03
Securid Web Agent MEDIUM 6.7
CVE-2015-6851

EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unatten…

Fix: after 7.2.1
Fix from $1,600 2015-12-23
Hbase HIGH 7.3
CVE-2015-1836EPSS 7%

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and o…

Mitigation only
Fix from $1,950 2015-12-21
Tvos HIGH 9.3
CVE-2015-7055

AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to…

Fix: after 9.1
Fix from $1,950 2015-12-11
Isilon Onefs HIGH 8.5
CVE-2015-6848

EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not uni…

Fix: after 7.1.1.0
Fix from $1,950 2015-11-27
Openshift HIGH 7.5
CVE-2015-5325

Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: …

Fix: after 3.1
Fix from $1,950 2015-11-25
Gpu Driver HIGH 7.7
CVE-2015-7865

nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.8…

Fix: 341.92 / 354.35+
Fix from $1,950 2015-11-24
Gpu Driver HIGH 10.0
CVE-2015-5053

The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for…

Mitigation only
Fix from $1,950 2015-11-24
Telemetry Web Server HIGH 7.8
CVE-2015-7910

Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass inte…

Mitigation only
Fix from $1,950 2015-11-19
Visilogic Oplc Ide MEDIUM 6.8
CVE-2015-6478

Unitronics VisiLogic OPLC IDE before 9.8.02 does not properly restrict access to ActiveX controls, which allows remote attackers to have an unspecifi…

Fix: after 9.8.0.0
Fix from $1,600 2015-11-13
iOS MEDIUM 5.0
CVE-2015-6366

Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended net…

Mitigation only
Fix from $1,600 2015-11-13
Mobaxterm HIGH 7.5
CVE-2015-7244EPSS 5%

The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authenticatio…

Fix: after 8.2
Fix from $1,950 2015-11-04
Vertica HIGH 7.5
CVE-2015-6867

The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands v…

Mitigation only
Fix from $1,950 2015-11-04
Joomla\! MEDIUM 5.0
CVE-2015-7899

The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via…

Mitigation only
Fix from $1,600 2015-10-29
Websphere Portal MEDIUM 5.0
CVE-2014-8912

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before…

Patch available
Fix from $1,600 2015-10-28