Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2016-10856 cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29). Cpanel 11.48.4.8 / 11.50.3.1+ Fix from $1,6002019-08-01 MEDIUM 6.5 CVE-2016-10857 cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60). Cpanel 11.48.4.8 / 11.50.3.1+ Fix from $1,6002019-08-01 HIGH 8.1 CVE-2016-10860 cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66). Cpanel 11.48.4.8 / 11.50.3.1+ Fix from $1,9502019-08-01 HIGH 7.4 CVE-2014-8183 It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker wi… Satellite 1.15.6+ Fix from $1,9502019-08-01 HIGH 7.8 CVE-2019-10161 It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specif… Libvirt 4.10.1 / 5.4.1+ Fix from $1,9502019-07-30 HIGH 8.8 CVE-2019-10138 A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked suf… Novajoin 1.1.1+ Fix from $1,9502019-07-30 HIGH 7.5 CVE-2017-18380 edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain n… Edx Platform 2017-08-03+ Fix from $1,9502019-07-30 CRITICAL 9.8 CVE-2019-9884 eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management … Eclass Ip 2.5.10.2.1+ Fix from $2,3002019-07-25 HIGH 7.8 CVE-2018-13896 XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBL_SEC stage… Mdm9206 Firmware Mitigation only Fix from $1,9502019-07-22 MEDIUM 5.4 CVE-2019-3794 Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking att… Cloud Foundry Uaa 73.4.0+ Fix from $1,6002019-07-18 HIGH 7.8 CVE-2019-1010316 pyxtrlock 0.3 and earlier is affected by: Incorrect Access Control. The impact is: False locking impression when run in a non-X11 session. The fixed … Pyxtrlock after 0.3 Fix from $1,9502019-07-11 CRITICAL 9.8 CVE-2019-10970 In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a r… Panelview 5510 Firmware 4.003 / 5.002+ Fix from $2,3002019-07-11 HIGH 7.5 CVE-2019-9886 Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass befo… Eclass Ip 2.5.10.2.1+ Fix from $1,9502019-07-11 MEDIUM 5.4 CVE-2018-17151 Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control. Cache No fix yet Fix from $1,6002019-07-11 HIGH 7.2 CVE-2018-19588 Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control. Adc V522ir Firmware No fix yet Fix from $1,9502019-07-11 HIGH 8.1 CVE-2018-11744 Cloudera Manager through 5.15 has Incorrect Access Control. Cloudera Manager after 6.1.0 Fix from $1,9502019-07-11 HIGH 8.1 CVE-2018-19576 GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allo… GitLab 11.3.11 / 11.4.8+ Fix from $1,9502019-07-10 MEDIUM 6.5 CVE-2018-19496 An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. Ther… GitLab 11.3.11 / 11.4.8+ Fix from $1,6002019-07-10 MEDIUM 5.3 CVE-2018-19577 Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulne… GitLab 11.3.11 / 11.4.8+ Fix from $1,6002019-07-10 MEDIUM 5.9 CVE-2018-14833 Intuit Lacerte 2017 has Incorrect Access Control. Lacerte after 2017 Fix from $1,6002019-07-09 MEDIUM 6.5 CVE-2019-1890 A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mo… Application Policy Infrastructure Controller Mitigation only Fix from $1,6002019-07-04 HIGH 8.1 CVE-2018-14859 Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated… Odoo Patch available Fix from $1,9502019-07-03 HIGH 8.1 CVE-2018-14863 Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to c… Odoo Patch available Fix from $1,9502019-07-03 MEDIUM 6.5 CVE-2018-14864 Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remo… Odoo Patch available Fix from $1,6002019-07-03 HIGH 8.8 CVE-2019-13028 An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to… Electronic Identification Cards Client 3.0.3 / 3.1.2+ Fix from $1,9502019-06-28 HIGH 7.1 CVE-2019-10964 Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor tr… Minimed 508 Firmware Mitigation only Fix from $1,9502019-06-28 MEDIUM 6.5 CVE-2019-10175 A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine wheth… Containerized Data Importer Mitigation only Fix from $1,6002019-06-28 MEDIUM 5.3 CVE-2018-14867 Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to po… Odoo Patch available Fix from $1,6002019-06-28 CRITICAL 9.8 CVE-2018-14885 Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker… Odoo Patch available Fix from $2,3002019-06-28 CRITICAL 9.8 CVE-2019-1619EPSS 83% A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to … Data Center Network Manager No fix yet Fix from $2,3002019-06-27