Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
CRITICAL 9.8 CVE-2015-5463 AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers… Axiom after 9.5.3 Fix from $2,3002019-04-03 HIGH 8.8 CVE-2019-3849 A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content… Moodle 3.4.8 / 3.5.5+ Fix from $1,9502019-03-26 CRITICAL 9.8 CVE-2015-3954 Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and… Plum A\+ Infusion System Firmware after 13.6 Fix from $2,3002019-03-25 HIGH 8.1 CVE-2019-3785 Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with… Capi Release 1.78.0+ Fix from $1,9502019-03-13 HIGH 7.8 CVE-2019-1603 A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrat… Nx Os 7.0+ Fix from $1,9502019-03-08 HIGH 7.8 CVE-2019-1604 A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privil… Nx Os 6.2 / 7.0+ Fix from $1,9502019-03-08 MEDIUM 5.5 CVE-2018-9867 In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the Sonic… Sonicosv after 5.9.1.10 Fix from $1,6002019-02-19 HIGH 7.2 CVE-2018-14666 An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered… Satellite after 6.4 Fix from $1,9502019-01-22 MEDIUM 5.7 CVE-2018-14662 It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d… Ceph 13.2.4+ Fix from $1,6002019-01-15 HIGH 8.1 CVE-2018-15465 A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (le… Adaptive Security Appliance Software 9.4.4.29 / 9.6.4.20+ Fix from $1,9502018-12-24 HIGH 8.1 CVE-2018-14637 The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th… Keycloak 4.6.0+ Fix from $1,9502018-11-30 HIGH 8.8 CVE-2018-17933 VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execut… Vgo Firmware Mitigation only Fix from $1,9502018-10-30 CRITICAL 9.8 CVE-2016-10734 ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php. Projectsend Mitigation only Fix from $2,3002018-10-29 MEDIUM 6.5 CVE-2018-15405 A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director coul… Ucs Director Mitigation only Fix from $1,6002018-10-05 MEDIUM 6.5 CVE-2018-0460 A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any fil… Network Functions Virtualization Infrastructure Mitigation only Fix from $1,6002018-10-05 MEDIUM 6.5 CVE-2018-0459 A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote at… Network Functions Virtualization Infrastructure Mitigation only Fix from $1,6002018-10-05 MEDIUM 5.3 CVE-2018-3829 In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles… Elastic Cloud Enterprise 1.1.4+ Fix from $1,6002018-09-19 HIGH 7.8 CVE-2016-7035 An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged accou… Enterprise Linux Server after 1.1.16 Fix from $1,9502018-09-10 HIGH 8.8 CVE-2016-7071 It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authent… Cloudforms Management Engine 5.6.2.2 / 5.7.0.7+ Fix from $1,9502018-09-10 MEDIUM 5.3 CVE-2018-3778 Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized. Aedes 0.35.0+ Fix from $1,6002018-08-08 MEDIUM 6.5 CVE-2018-0391 A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the … Prime Collaboration after 12.2 Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-12466 openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links. Open Build Service 9.2.4+ Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-12467 Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDe… Open Build Service 2.9.4+ Fix from $1,6002018-08-01 CRITICAL 9.0 CVE-2017-2589 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored … Jboss Fuse Mitigation only Fix from $2,3002018-07-26 HIGH 7.8 CVE-2018-10906 In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use… Debian Linux 2.9.8 / 3.2.5+ Fix from $1,9502018-07-24 MEDIUM 6.5 CVE-2018-0393 A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to m… Mobility Services Engine 3365 Firmware Mitigation only Fix from $1,6002018-07-18 HIGH 8.1 CVE-2018-10861 A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po… Ceph Storage Patch available Fix from $1,9502018-07-10 HIGH 8.8 CVE-2017-16773 Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass … Universal Search 1.0.5-0135+ Fix from $1,9502018-07-05 MEDIUM 5.3 CVE-2018-1113 setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates sec… Setup 2.11.4+ Fix from $1,6002018-07-03 CRITICAL 9.1 CVE-2017-16726 Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to… Twincat Mitigation only Fix from $2,3002018-06-27