Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.3 CVE-2019-1622EPSS 79% A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to … Data Center Network Manager No fix yet Fix from $1,6002019-06-27 HIGH 7.2 CVE-2018-16553 In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin. Jspxcms Mitigation only Fix from $1,9502019-06-20 CRITICAL 9.8 CVE-2019-2729EPSS 89% Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected … Communications Diameter Signaling Router after 7.3.6 Fix from $2,3002019-06-19 CRITICAL 9.8 CVE-2018-17148 An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios… Nagios Xi 5.5.4+ Fix from $2,3002019-06-19 MEDIUM 6.5 CVE-2017-10721 Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet funct… Endoscope Camera Firmware No fix yet Fix from $1,6002019-06-17 MEDIUM 6.5 CVE-2018-18958 OPNsense 18.7.x before 18.7.7 has Incorrect Access Control. Opnsense 18.7.7+ Fix from $1,6002019-06-17 MEDIUM 5.3 CVE-2019-10962 BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstatio… Alaris Gateway Workstation Firmware Mitigation only Fix from $1,6002019-06-13 HIGH 7.1 CVE-2019-10925 A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could escalate privileges by sending s… Simatic Mv420 Firmware Mitigation only Fix from $1,9502019-06-12 HIGH 7.5 CVE-2018-10691 An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, th… Awk 3121 Firmware No fix yet Fix from $1,9502019-06-07 MEDIUM 5.9 CVE-2018-5264 Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a … Unifi Firmware No fix yet Fix from $1,6002019-06-07 HIGH 8.0 CVE-2019-3895 An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker c… Openstack 0.9.0+ Fix from $1,9502019-06-03 HIGH 8.8 CVE-2018-5406EPSS 12% The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS)… Kace Systems Management Appliance Firmware 9.0.270+ Fix from $1,9502019-06-03 HIGH 8.1 CVE-2019-3567 In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a mali… Osquery 3.4.0+ Fix from $1,9502019-06-03 MEDIUM 5.7 CVE-2019-11894 A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may res… Smart Home Controller Firmware 9.8.905+ Fix from $1,6002019-05-29 MEDIUM 5.3 CVE-2019-11895 A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may r… Smart Home Controller Firmware 9.8.905+ Fix from $1,6002019-05-29 HIGH 7.1 CVE-2019-11896 A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.… Smart Home Controller Firmware 9.8.907+ Fix from $1,9502019-05-29 HIGH 8.0 CVE-2019-11892 A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may r… Smart Home Controller Firmware 9.8.905+ Fix from $1,9502019-05-29 HIGH 7.8 CVE-2018-13895 Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an unprivileged access to phone … Mdm9150 Firmware Mitigation only Fix from $1,9502019-05-24 CRITICAL 9.8 CVE-2017-11365 Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3… Symfony Patch available Fix from $2,3002019-05-23 CRITICAL 9.8 CVE-2017-5212 Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control. Open Xchange Appsuite No fix yet Fix from $2,3002019-05-23 CRITICAL 9.8 CVE-2017-5863 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. Open Xchange Appsuite after 7.8.3 Fix from $2,3002019-05-22 HIGH 8.8 CVE-2017-6912 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. Open Xchange Appsuite after 7.8.3 Fix from $1,9502019-05-22 HIGH 8.8 CVE-2017-8340 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. Open Xchange Appsuite after 7.8.3 Fix from $1,9502019-05-22 CRITICAL 9.8 CVE-2019-11634 KEVEPSS 8% Citrix Workspace App before 1904 for Windows has Incorrect Access Control. Receiver 1904+ Fix from $2,3002019-05-22 MEDIUM 6.7 CVE-2019-1649 A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could al… Asa 5500 Firmware 1.0.18 / 1.1.15+ Fix from $1,6002019-05-13 MEDIUM 5.9 CVE-2019-3566 A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to r… Whatsapp after 2.19.103 Fix from $1,6002019-05-10 HIGH 7.8 CVE-2019-6566 GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could all… Ge Communicator 4.0.517+ Fix from $1,9502019-05-09 MEDIUM 5.6 CVE-2019-6544 GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain a… Ge Communicator 4.0.517+ Fix from $1,6002019-05-09 MEDIUM 6.5 CVE-2019-5014 An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An att… Fw 1007 Firmware Mitigation only Fix from $1,6002019-05-08 MEDIUM 6.5 CVE-2019-1695 A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could a… Adaptive Security Appliance Software 6.2.3.12 / 6.3.0.3+ Fix from $1,6002019-05-03