Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Axiom CRITICAL 9.8
CVE-2015-5463

AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers…

Fix: after 9.5.3
Fix from $2,300 2019-04-03
Moodle HIGH 8.8
CVE-2019-3849

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content…

Fix: 3.4.8 / 3.5.5+
Fix from $1,950 2019-03-26
Plum A\+ Infusion System Firmware CRITICAL 9.8
CVE-2015-3954

Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and…

Fix: after 13.6
Fix from $2,300 2019-03-25
Capi Release HIGH 8.1
CVE-2019-3785

Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with…

Fix: 1.78.0+
Fix from $1,950 2019-03-13
Nx Os HIGH 7.8
CVE-2019-1603

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrat…

Fix: 7.0+
Fix from $1,950 2019-03-08
Nx Os HIGH 7.8
CVE-2019-1604

A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privil…

Fix: 6.2 / 7.0+
Fix from $1,950 2019-03-08
Sonicosv MEDIUM 5.5
CVE-2018-9867

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the Sonic…

Fix: after 5.9.1.10
Fix from $1,600 2019-02-19
Satellite HIGH 7.2
CVE-2018-14666

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered…

Fix: after 6.4
Fix from $1,950 2019-01-22
Ceph MEDIUM 5.7
CVE-2018-14662

It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d…

Fix: 13.2.4+
Fix from $1,600 2019-01-15
Adaptive Security Appliance Software HIGH 8.1
CVE-2018-15465

A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (le…

Fix: 9.4.4.29 / 9.6.4.20+
Fix from $1,950 2018-12-24
Keycloak HIGH 8.1
CVE-2018-14637

The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…

Fix: 4.6.0+
Fix from $1,950 2018-11-30
Vgo Firmware HIGH 8.8
CVE-2018-17933

VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execut…

Mitigation only
Fix from $1,950 2018-10-30
Projectsend CRITICAL 9.8
CVE-2016-10734

ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.

Mitigation only
Fix from $2,300 2018-10-29
Ucs Director MEDIUM 6.5
CVE-2018-15405

A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director coul…

Mitigation only
Fix from $1,600 2018-10-05
Network Functions Virtualization Infrastructure MEDIUM 6.5
CVE-2018-0460

A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any fil…

Mitigation only
Fix from $1,600 2018-10-05
Network Functions Virtualization Infrastructure MEDIUM 6.5
CVE-2018-0459

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote at…

Mitigation only
Fix from $1,600 2018-10-05
Elastic Cloud Enterprise MEDIUM 5.3
CVE-2018-3829

In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles…

Fix: 1.1.4+
Fix from $1,600 2018-09-19
Enterprise Linux Server HIGH 7.8
CVE-2016-7035

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged accou…

Fix: after 1.1.16
Fix from $1,950 2018-09-10
Cloudforms Management Engine HIGH 8.8
CVE-2016-7071

It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authent…

Fix: 5.6.2.2 / 5.7.0.7+
Fix from $1,950 2018-09-10
Aedes MEDIUM 5.3
CVE-2018-3778

Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.

Fix: 0.35.0+
Fix from $1,600 2018-08-08
Prime Collaboration MEDIUM 6.5
CVE-2018-0391

A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the …

Fix: after 12.2
Fix from $1,600 2018-08-01
Open Build Service MEDIUM 6.5
CVE-2018-12466

openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.

Fix: 9.2.4+
Fix from $1,600 2018-08-01
Open Build Service MEDIUM 6.5
CVE-2018-12467

Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDe…

Fix: 2.9.4+
Fix from $1,600 2018-08-01
Jboss Fuse CRITICAL 9.0
CVE-2017-2589

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored …

Mitigation only
Fix from $2,300 2018-07-26
Debian Linux HIGH 7.8
CVE-2018-10906

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use…

Fix: 2.9.8 / 3.2.5+
Fix from $1,950 2018-07-24
Mobility Services Engine 3365 Firmware MEDIUM 6.5
CVE-2018-0393

A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to m…

Mitigation only
Fix from $1,600 2018-07-18
Ceph Storage HIGH 8.1
CVE-2018-10861

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po…

Patch available
Fix from $1,950 2018-07-10
Universal Search HIGH 8.8
CVE-2017-16773

Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass …

Fix: 1.0.5-0135+
Fix from $1,950 2018-07-05
Setup MEDIUM 5.3
CVE-2018-1113

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates sec…

Fix: 2.11.4+
Fix from $1,600 2018-07-03
Twincat CRITICAL 9.1
CVE-2017-16726

Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to…

Mitigation only
Fix from $2,300 2018-06-27