Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Search Guard MEDIUM 6.5
CVE-2019-13416

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cl…

Fix: 24.3+
Fix from $1,600 2019-08-13
Adaptive Security Appliance Software HIGH 8.8
CVE-2019-1934

A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attack…

Fix: after 8.2
Fix from $1,950 2019-08-07
Sf 220 24 Firmware CRITICAL 9.1
CVE-2019-1912EPSS 17%

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to …

Fix: 1.1.4.4+
Fix from $2,300 2019-08-07
MongoDB HIGH 7.1
CVE-2019-2386

After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and becom…

Fix: 3.4.22 / 3.6.13+
Fix from $1,950 2019-08-06
Cpanel MEDIUM 5.7
CVE-2018-20945

bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).

Fix: 62.0.39 / 66.0.35+
Fix from $1,600 2019-08-01
Cpanel HIGH 7.2
CVE-2016-10848

cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,950 2019-08-01
Cpanel HIGH 8.1
CVE-2016-10859

cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).

Fix: 11.48.4.8 / 11.50.3.1+
Fix from $1,950 2019-08-01
Central Print Services HIGH 8.8
CVE-2018-17210

An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perfor…

Fix: after 4.1.4
Fix from $1,950 2019-07-20
GitLab MEDIUM 6.5
CVE-2018-19578

GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the J…

Fix: 11.5.1+
Fix from $1,600 2019-07-10
GitLab HIGH 7.5
CVE-2018-19581

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerab…

Fix: 11.3.11 / 11.4.8+
Fix from $1,950 2019-07-10
GitLab HIGH 8.8
CVE-2018-19569

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability th…

Fix: 11.3.11 / 11.4.8+
Fix from $1,950 2019-07-10
Cdh HIGH 7.5
CVE-2017-9325

The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.

Fix: after 5.11.1
Fix from $1,950 2019-07-03
Dcs 1130 Firmware HIGH 7.5
CVE-2017-8409

An issue was discovered on D-Link DCS-1130 devices. The device requires that a user logging to the device to provide a username and password. However…

No fix yet
Fix from $1,950 2019-07-02
Chrome MEDIUM 6.5
CVE-2018-16073

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a cra…

Fix: 69.0.3497.81+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-16074

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a cra…

Fix: 69.0.3497.81+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-16077

Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML…

Fix: 69.0.3497.81+
Fix from $1,600 2019-06-27
Chrome MEDIUM 5.4
CVE-2018-16086

Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malici…

Fix: 69.0.3497.81+
Fix from $1,600 2019-06-27
Moodle HIGH 7.5
CVE-2019-10154

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

Fix: 3.6.4+
Fix from $1,950 2019-06-26
Rv110w Firmware MEDIUM 5.3
CVE-2019-1897

A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $1,600 2019-06-20
Rv110w Firmware MEDIUM 5.3
CVE-2019-1898EPSS 41%

A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $1,600 2019-06-20
Rv110w Firmware MEDIUM 5.3
CVE-2019-1899

A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list …

No fix yet
Fix from $1,600 2019-06-20
Ipq4019 Firmware MEDIUM 5.5
CVE-2017-8252

Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdragon Auto, Snapdragon Compute, …

Mitigation only
Fix from $1,600 2019-06-14
Ipq8074 Firmware HIGH 7.8
CVE-2018-13908

Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon Auto, Snapdragon Compute, Sna…

Mitigation only
Fix from $1,950 2019-06-14
Siveillance Video Management Software 2017 R2 HIGH 8.8
CVE-2019-6581

A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance …

Fix: 11.2a / 12.1a+
Fix from $1,950 2019-06-12
Siveillance Video Management Software 2017 R2 HIGH 7.1
CVE-2019-6582

A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance …

Fix: 11.2a / 12.1a+
Fix from $1,950 2019-06-12
Ios Xr Firmware MEDIUM 5.4
CVE-2019-1842

A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfu…

Mitigation only
Fix from $1,600 2019-06-05
Ox Cloud HIGH 7.2
CVE-2017-8777

Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization.

Fix: after 1.4.0
Fix from $1,950 2019-05-22
Identity Services Engine MEDIUM 6.8
CVE-2019-1851

A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker …

Mitigation only
Fix from $1,600 2019-05-16
Sg200 50 Firmware HIGH 7.2
CVE-2019-1859

A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-s…

Fix: 1.4.10.6+
Fix from $1,950 2019-05-03
Enterprise Linux HIGH 7.0
CVE-2019-3842

In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p…

Fix: after 241
Fix from $1,950 2019-04-09