Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.2 CVE-2016-2278EPSS 13% Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated adminis… Struxureware Building Operations Automation Server As Firmware after 1.7 Fix from $1,9502016-03-02 CRITICAL 9.8 CVE-2016-2275 The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on t… Vesp211 Eu Firmware Mitigation only Fix from $2,3002016-02-21 MEDIUM 5.3 CVE-2015-7577 activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.… Rails after 3.2.22 Fix from $1,6002016-02-16 HIGH 7.5 CVE-2016-1315 The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allow… Email Security Appliance Firmeware Mitigation only Fix from $1,9502016-02-12 MEDIUM 5.5 CVE-2016-2048 Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and creat… Django Mitigation only Fix from $1,6002016-02-08 CRITICAL 9.1 CVE-2015-8361 Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers … Bamboo Patch available Fix from $2,3002016-02-08 HIGH 8.8 CVE-2016-1301 The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9… Prime Security Manager Mitigation only Fix from $1,9502016-02-07 HIGH 8.8 CVE-2016-1302 Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switche… Nx Os 2.50+ Fix from $1,9502016-02-07 HIGH 7.7 CVE-2016-1905 The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a … Kubernetes Mitigation only Fix from $1,9502016-02-03 HIGH 8.8 CVE-2016-2049 examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME elem… Php Openid Mitigation only Fix from $1,9502016-02-01 MEDIUM 6.1 CVE-2016-1492 The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier… Shareit No fix yet Fix from $1,6002016-01-26 MEDIUM 6.5 CVE-2015-6317 Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct re… Identity Services Engine Software Mitigation only Fix from $1,6002016-01-23 MEDIUM 6.3 CVE-2015-6933 The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x… Player Patch available Fix from $1,6002016-01-09 HIGH 8.4 CVE-2015-6862 HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors. Ucmdb Browser Patch available Fix from $1,9502016-01-08 MEDIUM 5.4 CVE-2015-5017 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 befor… Change And Configuration Management Database Mitigation only Fix from $1,6002016-01-03 MEDIUM 5.6 CVE-2015-1985 The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by le… Mq Appliance M2000 after 8.0.0.3 Fix from $1,6002016-01-03 MEDIUM 6.7 CVE-2015-6851 EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unatten… Securid Web Agent after 7.2.1 Fix from $1,6002015-12-23 HIGH 7.3 CVE-2015-1836EPSS 7% Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and o… Hbase Mitigation only Fix from $1,9502015-12-21 HIGH 9.3 CVE-2015-7055 AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to… Tvos after 9.1 Fix from $1,9502015-12-11 HIGH 8.5 CVE-2015-6848 EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not uni… Isilon Onefs after 7.1.1.0 Fix from $1,9502015-11-27 HIGH 7.5 CVE-2015-5325 Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: … Openshift after 3.1 Fix from $1,9502015-11-25 HIGH 7.7 CVE-2015-7865 nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.8… Gpu Driver 341.92 / 354.35+ Fix from $1,9502015-11-24 HIGH 10.0 CVE-2015-5053 The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for… Gpu Driver Mitigation only Fix from $1,9502015-11-24 HIGH 7.8 CVE-2015-7910 Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass inte… Telemetry Web Server Mitigation only Fix from $1,9502015-11-19 MEDIUM 6.8 CVE-2015-6478 Unitronics VisiLogic OPLC IDE before 9.8.02 does not properly restrict access to ActiveX controls, which allows remote attackers to have an unspecifi… Visilogic Oplc Ide after 9.8.0.0 Fix from $1,6002015-11-13 MEDIUM 5.0 CVE-2015-6366 Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended net… iOS Mitigation only Fix from $1,6002015-11-13 HIGH 7.5 CVE-2015-7244EPSS 5% The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authenticatio… Mobaxterm after 8.2 Fix from $1,9502015-11-04 HIGH 7.5 CVE-2015-6867 The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands v… Vertica Mitigation only Fix from $1,9502015-11-04 MEDIUM 5.0 CVE-2015-7899 The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via… Joomla\! Mitigation only Fix from $1,6002015-10-29 MEDIUM 5.0 CVE-2014-8912 IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before… Websphere Portal Patch available Fix from $1,6002015-10-28