Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.5 CVE-2019-13416 Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cl… Search Guard 24.3+ Fix from $1,6002019-08-13 HIGH 8.8 CVE-2019-1934 A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attack… Adaptive Security Appliance Software after 8.2 Fix from $1,9502019-08-07 CRITICAL 9.1 CVE-2019-1912EPSS 17% A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to … Sf 220 24 Firmware 1.1.4.4+ Fix from $2,3002019-08-07 HIGH 7.1 CVE-2019-2386 After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and becom… MongoDB 3.4.22 / 3.6.13+ Fix from $1,9502019-08-06 MEDIUM 5.7 CVE-2018-20945 bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354). Cpanel 62.0.39 / 66.0.35+ Fix from $1,6002019-08-01 HIGH 7.2 CVE-2016-10848 cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81). Cpanel 11.48.5.2 / 11.50.4.3+ Fix from $1,9502019-08-01 HIGH 8.1 CVE-2016-10859 cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65). Cpanel 11.48.4.8 / 11.50.3.1+ Fix from $1,9502019-08-01 HIGH 8.8 CVE-2018-17210 An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perfor… Central Print Services after 4.1.4 Fix from $1,9502019-07-20 MEDIUM 6.5 CVE-2018-19578 GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the J… GitLab 11.5.1+ Fix from $1,6002019-07-10 HIGH 7.5 CVE-2018-19581 GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerab… GitLab 11.3.11 / 11.4.8+ Fix from $1,9502019-07-10 HIGH 8.8 CVE-2018-19569 GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability th… GitLab 11.3.11 / 11.4.8+ Fix from $1,9502019-07-10 HIGH 7.5 CVE-2017-9325 The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs. Cdh after 5.11.1 Fix from $1,9502019-07-03 HIGH 7.5 CVE-2017-8409 An issue was discovered on D-Link DCS-1130 devices. The device requires that a user logging to the device to provide a username and password. However… Dcs 1130 Firmware No fix yet Fix from $1,9502019-07-02 MEDIUM 6.5 CVE-2018-16073 Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a cra… Chrome 69.0.3497.81+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-16074 Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a cra… Chrome 69.0.3497.81+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-16077 Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML… Chrome 69.0.3497.81+ Fix from $1,6002019-06-27 MEDIUM 5.4 CVE-2018-16086 Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malici… Chrome 69.0.3497.81+ Fix from $1,6002019-06-27 HIGH 7.5 CVE-2019-10154 A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations. Moodle 3.6.4+ Fix from $1,9502019-06-26 MEDIUM 5.3 CVE-2019-1897 A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to … Rv110w Firmware No fix yet Fix from $1,6002019-06-20 MEDIUM 5.3 CVE-2019-1898EPSS 41% A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to … Rv110w Firmware No fix yet Fix from $1,6002019-06-20 MEDIUM 5.3 CVE-2019-1899 A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list … Rv110w Firmware No fix yet Fix from $1,6002019-06-20 MEDIUM 5.5 CVE-2017-8252 Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdragon Auto, Snapdragon Compute, … Ipq4019 Firmware Mitigation only Fix from $1,6002019-06-14 HIGH 7.8 CVE-2018-13908 Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon Auto, Snapdragon Compute, Sna… Ipq8074 Firmware Mitigation only Fix from $1,9502019-06-14 HIGH 8.8 CVE-2019-6581 A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance … Siveillance Video Management Software 2017 R2 11.2a / 12.1a+ Fix from $1,9502019-06-12 HIGH 7.1 CVE-2019-6582 A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance … Siveillance Video Management Software 2017 R2 11.2a / 12.1a+ Fix from $1,9502019-06-12 MEDIUM 5.4 CVE-2019-1842 A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfu… Ios Xr Firmware Mitigation only Fix from $1,6002019-06-05 HIGH 7.2 CVE-2017-8777 Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization. Ox Cloud after 1.4.0 Fix from $1,9502019-05-22 MEDIUM 6.8 CVE-2019-1851 A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker … Identity Services Engine Mitigation only Fix from $1,6002019-05-16 HIGH 7.2 CVE-2019-1859 A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-s… Sg200 50 Firmware 1.4.10.6+ Fix from $1,9502019-05-03 HIGH 7.0 CVE-2019-3842 In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p… Enterprise Linux after 241 Fix from $1,9502019-04-09