Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.0 CVE-2018-10500 This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An att… Galaxy Apps 6.4.0.15+ Fix from $1,9502018-09-24 HIGH 8.8 CVE-2018-15610 A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. A… Ip Office No fix yet Fix from $1,9502018-09-12 CRITICAL 9.8 CVE-2018-7791 A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior t… Modicon M221 Firmware 1.6.2.0+ Fix from $2,3002018-08-29 HIGH 8.1 CVE-2016-7048 The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary … PostgreSQL 9.1.24 / 9.2.19+ Fix from $1,9502018-08-20 MEDIUM 6.7 CVE-2018-0428 A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate pri… Web Security Appliance Mitigation only Fix from $1,6002018-08-15 CRITICAL 9.8 CVE-2018-10630EPSS 11% For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, a… Tsw X60 Firmware 1.502.0047.001 / 2.001.0037.001+ Fix from $2,3002018-08-10 MEDIUM 5.8 CVE-2018-11456 A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could sen… Automation License Manager 5.3.4.4+ Fix from $1,6002018-08-07 MEDIUM 6.5 CVE-2017-12171EPSS 8% A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines… Enterprise Linux Mitigation only Fix from $1,6002018-07-26 MEDIUM 6.5 CVE-2017-2664 CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of Cl… Cloudforms 5.7.3 / 5.8.1+ Fix from $1,6002018-07-26 HIGH 7.8 CVE-2018-10905 CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an… Cloudforms Mitigation only Fix from $1,9502018-07-24 HIGH 8.8 CVE-2018-0343 A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arb… Vbond Orchestrator 18.3.0+ Fix from $1,9502018-07-18 MEDIUM 5.9 CVE-2016-6543 A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthe… Itrack Easy Mitigation only Fix from $1,6002018-07-13 HIGH 7.5 CVE-2013-2972 IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM X-Force ID: 83868. Websphere Cast Iron Cloud Integration Patch available Fix from $1,9502018-07-11 MEDIUM 6.5 CVE-2018-1129 A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who… Ceph Storage Patch available Fix from $1,6002018-07-10 HIGH 7.8 CVE-2018-4858 A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is in… Ec 61850 System Configurator Firmware 3.11 / 5.80+ Fix from $1,9502018-07-09 HIGH 8.1 CVE-2018-1080 Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and… Dogtagpki after 10.6.1 Fix from $1,9502018-07-03 HIGH 8.8 CVE-2018-4845 A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens … Rapidpoint 400 Firmware 3.3+ Fix from $1,9502018-06-26 HIGH 8.8 CVE-2016-9905 A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and … Enterprise Linux Desktop 45.6.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2011-4181 A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases… Open Build Service 2.1.16+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2018-8922 Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders vi… Drive Server Mitigation only Fix from $1,6002018-06-01 MEDIUM 5.3 CVE-2015-9236 Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allo… Hapi 11.0.0+ Fix from $1,6002018-05-31 MEDIUM 5.9 CVE-2015-9243 When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config … Hapi 11.1.4+ Fix from $1,6002018-05-29 HIGH 7.8 CVE-2016-8656 Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502018-05-22 MEDIUM 6.7 CVE-2009-5150 Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communi… Computrace Agent No fix yet Fix from $1,6002018-05-11 MEDIUM 6.7 CVE-2009-5151 The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for t… Computrace Agent No fix yet Fix from $1,6002018-05-11 HIGH 7.8 CVE-2013-6272 The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended ac… Android after 4.4.2 Fix from $1,9502018-05-02 MEDIUM 5.4 CVE-2013-6739 IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855. Spss Modeler 16.0.0.0+ Fix from $1,6002018-04-27 HIGH 7.4 CVE-2014-0881 The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain s… Integrated Management Module Firmware after 3.56 Fix from $1,9502018-04-25 HIGH 7.5 CVE-2016-9599 puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of T… Openstack Mitigation only Fix from $1,9502018-04-24 MEDIUM 5.3 CVE-2014-6109 IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7… Security Identity Manager Patch available Fix from $1,6002018-04-20