Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.5 CVE-2019-3653 Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user t… Endpoint Security 10.6.1+ Fix from $1,6002019-10-09 MEDIUM 6.7 CVE-2019-12670 A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the name… iOS Mitigation only Fix from $1,6002019-09-25 HIGH 8.8 CVE-2019-12648 A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access t… iOS Mitigation only Fix from $1,9502019-09-25 CRITICAL 9.8 CVE-2019-15068 A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/… Smart Battery A4 Firmware Mitigation only Fix from $2,3002019-09-25 HIGH 8.8 CVE-2019-6810 CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the exec… Bmxnor0200h Firmware Mitigation only Fix from $1,9502019-09-17 HIGH 7.5 CVE-2019-11899 An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. With Bosch… Access after 3.7 Fix from $1,9502019-09-12 CRITICAL 9.8 CVE-2019-13656EPSS 6% An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote a… Ca Client Automation No fix yet Fix from $2,3002019-09-06 MEDIUM 5.3 CVE-2018-15513 Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role. Totemomail Mitigation only Fix from $1,6002019-08-30 CRITICAL 9.8 CVE-2018-21007 The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads. User Email Verification For Woocommerce 3.2.0+ Fix from $2,3002019-08-29 HIGH 7.5 CVE-2015-9337 The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX. Profile Builder 2.1.4+ Fix from $1,9502019-08-22 HIGH 7.5 CVE-2019-12627 A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a… Secure Firewall Threat Defense 6.4.0.4+ Fix from $1,9502019-08-21 HIGH 7.5 CVE-2019-5036 An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specia… Nest Cam Iq Indoor Firmware No fix yet Fix from $1,9502019-08-20 CRITICAL 9.8 CVE-2017-18543 The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations. Invite Anyone 1.3.16+ Fix from $2,3002019-08-16 HIGH 8.8 CVE-2018-20957 The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks. One\+ Firmware 2018-06-12+ Fix from $1,9502019-08-08 MEDIUM 5.5 CVE-2016-10799 cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137). Cpanel 11.52.6.2 / 11.54.0.26+ Fix from $1,6002019-08-07 HIGH 8.8 CVE-2016-10802 cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142). Cpanel 11.52.6.2 / 11.54.0.26+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10792 cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141). Cpanel 11.52.6.6 / 11.54.0.29+ Fix from $1,9502019-08-06 CRITICAL 9.8 CVE-2019-10938 A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 … Siprotec 5 Digsi Device Driver Patch available Fix from $2,3002019-08-02 MEDIUM 6.3 CVE-2017-18403 cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337). Cpanel 62.0.35 / 64.0.42+ Fix from $1,6002019-08-02 MEDIUM 5.5 CVE-2017-18416 cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303). Cpanel 56.0.52 / 60.0.48+ Fix from $1,6002019-08-02 HIGH 7.8 CVE-2019-10166 It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDe… Libvirt 4.10.1 / 5.4.1+ Fix from $1,9502019-08-02 HIGH 7.8 CVE-2019-10167 The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify … Libvirt 4.10.1 / 5.4.1+ Fix from $1,9502019-08-02 HIGH 7.8 CVE-2019-10168 The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emula… Libvirt 4.10.1 / 5.4.1+ Fix from $1,9502019-08-02 MEDIUM 5.5 CVE-2017-18385 cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311). Cpanel 62.0.35 / 64.0.42+ Fix from $1,6002019-08-02 HIGH 8.8 CVE-2016-10820 cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31). Cpanel 11.50.5.2 / 11.52.4.1+ Fix from $1,9502019-08-01 HIGH 8.1 CVE-2016-10830 cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100). Cpanel 11.50.5.2 / 11.52.4.1+ Fix from $1,9502019-08-01 MEDIUM 6.5 CVE-2018-20930 cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401). Cpanel 62.0.42 / 68.0.33+ Fix from $1,6002019-08-01 MEDIUM 6.5 CVE-2016-10838 cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). Cpanel 11.48.5.2 / 11.50.4.3+ Fix from $1,6002019-08-01 HIGH 7.5 CVE-2015-9291 cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221). Cpanel 11.52.0.13+ Fix from $1,9502019-08-01 MEDIUM 6.5 CVE-2016-10852 cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85). Cpanel 11.48.5.2 / 11.50.4.3+ Fix from $1,6002019-08-01