Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Adaptive Server Enterprise HIGH 7.5
CVE-2013-7245

The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by le…

Mitigation only
Fix from $1,950 2018-04-24
Moodle HIGH 8.1
CVE-2018-1082

A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspende…

Fix: after 3.4.1
Fix from $1,950 2018-04-04
GitLab HIGH 8.8
CVE-2017-0926

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user …

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab MEDIUM 6.5
CVE-2017-0927

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use…

Fix: after 10.3.3
Fix from $1,600 2018-03-21
Freeipa MEDIUM 6.3
CVE-2016-9575

Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in I…

Mitigation only
Fix from $1,600 2018-03-13
Open Build Service MEDIUM 6.5
CVE-2017-9268

In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated user…

Fix: after 2.8.2
Fix from $1,600 2018-03-01
Smart Protection Server HIGH 8.8
CVE-2017-11398EPSS 8%

A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauth…

Fix: after 3.2
Fix from $1,950 2018-01-19
Fl Switch 3005 Firmware CRITICAL 9.8
CVE-2017-16743

An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.3…

Fix: after 1.32
Fix from $2,300 2018-01-12
Keycloak HIGH 7.2
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit…

Mitigation only
Fix from $1,950 2017-10-26
Pagure HIGH 7.5
CVE-2017-1002151

Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization

Fix: after 3.3
Fix from $1,950 2017-09-14
Clearpass HIGH 7.2
CVE-2015-3656

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Airlink Raven Xe Firmware CRITICAL 9.8
CVE-2017-6044

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions …

Mitigation only
Fix from $2,300 2017-06-30
Kibana HIGH 7.5
CVE-2016-1000219

Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files…

Fix: 4.1.11 / 4.5.4+
Fix from $1,950 2017-06-16
Android HIGH 7.8
CVE-2014-9945

In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Android HIGH 7.8
CVE-2014-9950

In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Zulip Server MEDIUM 6.5
CVE-2017-0896

Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application serv…

Patch available
Fix from $1,600 2017-06-02
PostgreSQL HIGH 7.5
CVE-2017-7484

It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, an…

Fix: after 9.2.20
Fix from $1,950 2017-05-12
Server Automation MEDIUM 5.3
CVE-2016-5063EPSS 8%

The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization…

Fix: after 8.7
Fix from $1,600 2017-05-02
Ruggedcom Rox I MEDIUM 6.5
CVE-2017-2686

Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interfa…

Fix: after 2.9.0
Fix from $1,600 2017-03-29
Ruggedcom Rox I HIGH 8.8
CVE-2017-2689

Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain pri…

Fix: after 2.9.0
Fix from $1,950 2017-03-29
Iphone Os MEDIUM 5.3
CVE-2016-7651

An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" c…

Fix: after 10.1.1
Fix from $1,600 2017-02-20
Linux Kernel HIGH 7.8
CVE-2016-8443

Possible unauthorized memory access in the hypervisor. Incorrect configuration provides access to subsystem page tables. Product: Android. Versions: …

Mitigation only
Fix from $1,950 2017-01-12
Intercloud Fabric HIGH 8.8
CVE-2016-9217

A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to …

Mitigation only
Fix from $1,950 2016-12-26
Asterisk MEDIUM 5.3
CVE-2016-9938

An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 1…

Mitigation only
Fix from $1,600 2016-12-12
Bently Nevada 3500\/22m Usb Firmware CRITICAL 10.0
CVE-2016-5788

General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier fo…

Mitigation only
Fix from $2,300 2016-11-25
Wptf Image Gallery HIGH 7.5
CVE-2015-1000007

Remote file download vulnerability in wptf-image-gallery v1.03

No fix yet
Fix from $1,950 2016-10-06
Debian Linux HIGH 8.1
CVE-2016-7143

The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently …

Fix: after 3.5.2
Fix from $1,950 2016-09-21
Vipr Srm CRITICAL 9.8
CVE-2016-0922

EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain acce…

Fix: after 3.7.1
Fix from $2,300 2016-09-18
Windows 10 HIGH 8.8
CVE-2016-3352EPSS 21%

Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it eas…

Mitigation only
Fix from $1,950 2016-09-14
Rh1288 V3 Server Firmware CRITICAL 9.8
CVE-2016-6825

Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2…

Mitigation only
Fix from $2,300 2016-09-07