Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.5 CVE-2013-7245 The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by le… Adaptive Server Enterprise Mitigation only Fix from $1,9502018-04-24 HIGH 8.1 CVE-2018-1082 A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspende… Moodle after 3.4.1 Fix from $1,9502018-04-04 HIGH 8.8 CVE-2017-0926 Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user … GitLab after 10.3.3 Fix from $1,9502018-03-21 MEDIUM 6.5 CVE-2017-0927 Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use… GitLab after 10.3.3 Fix from $1,6002018-03-21 MEDIUM 6.3 CVE-2016-9575 Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in I… Freeipa Mitigation only Fix from $1,6002018-03-13 MEDIUM 6.5 CVE-2017-9268 In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated user… Open Build Service after 2.8.2 Fix from $1,6002018-03-01 HIGH 8.8 CVE-2017-11398EPSS 8% A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauth… Smart Protection Server after 3.2 Fix from $1,9502018-01-19 CRITICAL 9.8 CVE-2017-16743 An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.3… Fl Switch 3005 Firmware after 1.32 Fix from $2,3002018-01-12 HIGH 7.2 CVE-2017-12160 It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit… Keycloak Mitigation only Fix from $1,9502017-10-26 HIGH 7.5 CVE-2017-1002151 Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization Pagure after 3.3 Fix from $1,9502017-09-14 HIGH 7.2 CVE-2015-3656 Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges… Clearpass after 6.4.6 Fix from $1,9502017-08-29 CRITICAL 9.8 CVE-2017-6044 An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions … Airlink Raven Xe Firmware Mitigation only Fix from $2,3002017-06-30 HIGH 7.5 CVE-2016-1000219 Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files… Kibana 4.1.11 / 4.5.4+ Fix from $1,9502017-06-16 HIGH 7.8 CVE-2014-9945 In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist. Android Patch available Fix from $1,9502017-06-06 HIGH 7.8 CVE-2014-9950 In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist. Android Patch available Fix from $1,9502017-06-06 MEDIUM 6.5 CVE-2017-0896 Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application serv… Zulip Server Patch available Fix from $1,6002017-06-02 HIGH 7.5 CVE-2017-7484 It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, an… PostgreSQL after 9.2.20 Fix from $1,9502017-05-12 MEDIUM 5.3 CVE-2016-5063EPSS 8% The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization… Server Automation after 8.7 Fix from $1,6002017-05-02 MEDIUM 6.5 CVE-2017-2686 Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interfa… Ruggedcom Rox I after 2.9.0 Fix from $1,6002017-03-29 HIGH 8.8 CVE-2017-2689 Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain pri… Ruggedcom Rox I after 2.9.0 Fix from $1,9502017-03-29 MEDIUM 5.3 CVE-2016-7651 An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" c… Iphone Os after 10.1.1 Fix from $1,6002017-02-20 HIGH 7.8 CVE-2016-8443 Possible unauthorized memory access in the hypervisor. Incorrect configuration provides access to subsystem page tables. Product: Android. Versions: … Linux Kernel Mitigation only Fix from $1,9502017-01-12 HIGH 8.8 CVE-2016-9217 A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to … Intercloud Fabric Mitigation only Fix from $1,9502016-12-26 MEDIUM 5.3 CVE-2016-9938 An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 1… Asterisk Mitigation only Fix from $1,6002016-12-12 CRITICAL 10.0 CVE-2016-5788 General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier fo… Bently Nevada 3500\/22m Usb Firmware Mitigation only Fix from $2,3002016-11-25 HIGH 7.5 CVE-2015-1000007 Remote file download vulnerability in wptf-image-gallery v1.03 Wptf Image Gallery No fix yet Fix from $1,9502016-10-06 HIGH 8.1 CVE-2016-7143 The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently … Debian Linux after 3.5.2 Fix from $1,9502016-09-21 CRITICAL 9.8 CVE-2016-0922 EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain acce… Vipr Srm after 3.7.1 Fix from $2,3002016-09-18 HIGH 8.8 CVE-2016-3352EPSS 21% Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it eas… Windows 10 Mitigation only Fix from $1,9502016-09-14 CRITICAL 9.8 CVE-2016-6825 Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2… Rh1288 V3 Server Firmware Mitigation only Fix from $2,3002016-09-07