Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Control M\/agent HIGH 7.5
CVE-2019-19218

BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.

Mitigation only
Fix from $1,950 2020-04-30
Grafana MEDIUM 5.5
CVE-2020-12458

An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana…

Fix: after 6.7.3
Fix from $1,600 2020-04-29
Grafana MEDIUM 5.5
CVE-2020-12459

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain…

Fix: after 6.3.6
Fix from $1,600 2020-04-29
Control Builder M HIGH 7.8
CVE-2020-8472

Insufficient folder permissions used by system functions in ABB System 800xA products OPCServer for AC800M (versions 6.0 and earlier) and Control Bui…

Fix: after 6.1
Fix from $1,950 2020-04-29
800xa Base System HIGH 7.8
CVE-2020-8473

Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modif…

Fix: after 6.1
Fix from $1,950 2020-04-29
Correos Express HIGH 7.5
CVE-2020-12120

The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password …

Fix: after 1.7
Fix from $1,950 2020-04-27
Tivoli Monitoring HIGH 7.0
CVE-2020-4311

IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially crafted file, an attacker co…

Patch available
Fix from $1,950 2020-04-23
Wac505 Firmware MEDIUM 5.4
CVE-2019-20693

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

Fix: 8.0.6.4+
Fix from $1,600 2020-04-16
Infosphere Information Server HIGH 7.3
CVE-2020-4347

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permission…

Mitigation only
Fix from $1,950 2020-04-16
Proset\/wireless Wifi HIGH 7.8
CVE-2020-0557

Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potent…

Fix: 19.51.27.1 / 20.70.16.4+
Fix from $1,950 2020-04-15
Targetcli Fb HIGH 7.8
CVE-2020-10699

A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the…

Patch available
Fix from $1,950 2020-04-15
Dvr Interface MEDIUM 6.5
CVE-2020-10513

The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the attacker to remotely manipulate …

Fix: 20200103+
Fix from $1,600 2020-04-15
Rslinx Classic HIGH 7.8
CVE-2020-10642

In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker could modify a registry key, which could lead to th…

Fix: after 4.11.00
Fix from $1,950 2020-04-13
Qqbrowser HIGH 7.8
CVE-2020-10551

QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated …

Fix: 10.5.3870.400+
Fix from $1,950 2020-04-09
Android CRITICAL 9.1
CVE-2018-21081

An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the runtime permissions of the firs…

Mitigation only
Fix from $2,300 2020-04-08
Security Information Queue MEDIUM 5.3
CVE-2020-4289

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow a remote attacker to obtain sensitive information, cau…

Patch available
Fix from $1,600 2020-04-08
Xampp HIGH 8.8
CVE-2020-11107EPSS 22%

An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe confi…

Fix: 7.2.29 / 7.3.16+
Fix from $1,950 2020-04-02
Endpoint Security MEDIUM 6.7
CVE-2020-7263

Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrat…

Mitigation only
Fix from $1,600 2020-04-01
Ac1750 Firmware HIGH 7.8
CVE-2020-10883EPSS 6%

This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. …

No fix yet
Fix from $1,950 2020-03-25
Perun HIGH 7.5
CVE-2020-5281

In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from Perun LDAP. Issue is fixed in …

Fix: 3.9.1+
Fix from $1,950 2020-03-25
Openshift HIGH 7.0
CVE-2020-1707

A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pas…

Fix: 4.3+
Fix from $1,950 2020-03-20
Openshift HIGH 7.8
CVE-2020-1709

A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd f…

Fix: 4.3+
Fix from $1,950 2020-03-20
Template Service Broker Operator HIGH 7.0
CVE-2020-1705

A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerab…

Fix: 4.3.0+
Fix from $1,950 2020-03-19
Horizon Client HIGH 7.8
CVE-2019-5543

For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Wi…

Fix: 5.3.0 / 11.0.0+
Fix from $1,950 2020-03-16
Fusion HIGH 7.8
CVE-2020-3948

Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability…

Fix: 11.5.2 / 15.5.2+
Fix from $1,950 2020-03-16
Android HIGH 7.8
CVE-2019-2089

In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could lead to a local escalation of …

Mitigation only
Fix from $1,950 2020-03-15
Xtremio Management Server MEDIUM 6.7
CVE-2019-18577

Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall p…

Fix: 6.3.0+
Fix from $1,600 2020-03-13
GitLab MEDIUM 6.5
CVE-2019-13009

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were …

Fix: after 12.0.2
Fix from $1,600 2020-03-10
GitLab HIGH 7.5
CVE-2019-12441

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. The protected branches feature contained a access control issue…

Fix: after 11.11.0
Fix from $1,950 2020-03-10
Openshift Container Platform HIGH 7.0
CVE-2020-1706

It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify th…

Mitigation only
Fix from $1,950 2020-03-09