Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.6 CVE-2016-8529 A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 a… Lefthand after 12.5 Fix from $1,9502018-02-15 HIGH 8.8 CVE-2014-5279 The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for rem… Boot2docker after 1.2 Fix from $1,9502018-02-06 MEDIUM 5.4 CVE-2016-0342 IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify a… Tririga Application Platform 3.3.2.6 / 3.4.2.3+ Fix from $1,6002018-02-02 HIGH 7.5 CVE-2014-9504 The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via… Open Atrium 7.x-2.26+ Fix from $1,9502018-02-01 MEDIUM 6.5 CVE-2014-3519 The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow … Vzkernel Patch available Fix from $1,6002018-02-01 CRITICAL 9.8 CVE-2016-6598EPSS 19% BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service cont… Track It\! after 11.4 Fix from $2,3002018-01-30 MEDIUM 5.4 CVE-2017-9513 Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence… Activity Streams 6.3.0+ Fix from $1,6002018-01-29 HIGH 7.5 CVE-2015-3888 Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL. Sailfish Os 1.1.2.16+ Fix from $1,9502018-01-12 HIGH 7.8 CVE-2017-15131 It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting… Enterprise Linux 0.15.5+ Fix from $1,9502018-01-09 HIGH 7.5 CVE-2015-3302EPSS 22% The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attacker… Thecartpress Ecommerce Shopping Cart after 1.3.9 Fix from $1,9502017-12-29 HIGH 7.5 CVE-2015-8008 The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intende… Fedora 1.25.3+ Fix from $1,9502017-12-29 MEDIUM 6.5 CVE-2017-16766 An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows loc… Diskstation Manager 6.0.3-8754-6 / 6.1.4-15217+ Fix from $1,6002017-12-22 HIGH 8.8 CVE-2017-5254EPSS 54% In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passw… Epmp 1000 Firmware after 3.5 Fix from $1,9502017-12-20 MEDIUM 6.5 CVE-2017-15891 Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calend… Calendar 2.0.1-0242+ Fix from $1,6002017-12-08 HIGH 7.8 CVE-2017-14031 An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and wr… Vtscada after 11.3.03 Fix from $1,9502017-11-06 HIGH 8.8 CVE-2017-12262 A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow a… Application Policy Infrastructure Controller Enterprise Module 1.5+ Fix from $1,9502017-11-02 CRITICAL 9.8 CVE-2015-9245 Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh… Openedge Mitigation only Fix from $2,3002017-10-31 HIGH 8.8 CVE-2013-4246 libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a… Subversion Patch available Fix from $1,9502017-10-30 CRITICAL 9.8 CVE-2014-3624 Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request… Traffic Server Patch available Fix from $2,3002017-10-30 HIGH 7.5 CVE-2010-2232 In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file. Derby Patch available Fix from $1,9502017-10-23 MEDIUM 6.5 CVE-2012-4379 MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct c… Mediawiki after 1.18.4 Fix from $1,6002017-10-19 HIGH 7.5 CVE-2012-4380 MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an accoun… Mediawiki after 1.18.4 Fix from $1,9502017-10-19 HIGH 7.2 CVE-2016-5714 Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protect… Puppet Enterprise after 1.7.0 Fix from $1,9502017-10-18 HIGH 7.1 CVE-2014-2277 The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary file… Perltidy after 2012-07-01-1 Fix from $1,9502017-10-17 HIGH 8.8 CVE-2014-9489 The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "mast… Gollum after 4.0.0 Fix from $1,9502017-10-17 CRITICAL 9.8 CVE-2014-9148EPSS 11% Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administ… Fiyo Cms after 2.0.1.8 Fix from $2,3002017-10-16 MEDIUM 6.5 CVE-2016-10514 url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that co… Piwigo after 2.8.2 Fix from $1,6002017-10-10 MEDIUM 6.5 CVE-2017-8447 An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a… X Pack Mitigation only Fix from $1,6002017-09-29 HIGH 8.8 CVE-2017-8448 An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch… X Pack Mitigation only Fix from $1,9502017-09-29 HIGH 7.8 CVE-2015-1336 The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain pri… Man Db after 2.7.6.1 Fix from $1,9502017-09-28