Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Mdm9150 Firmware HIGH 7.8
CVE-2019-2257

Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Sna…

Mitigation only
Fix from $1,950 2019-06-14
Ite Tech Consumer Infrared Driver HIGH 7.8
CVE-2018-3702

Improper permissions in the installer for the ITE Tech* Consumer Infrared Driver for Windows 10 versions before 5.4.3.0 may allow an authenticated us…

Fix: 5.4.3.0+
Fix from $1,950 2019-06-13
Bcm4335c0 Firmware HIGH 8.8
CVE-2018-19860

Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not pro…

Mitigation only
Fix from $1,950 2019-06-07
Datagate Mk2 Firmware HIGH 7.8
CVE-2019-12777

An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace sec…

No fix yet
Fix from $1,950 2019-06-07
Sentinel Ldk MEDIUM 6.5
CVE-2019-8283

Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal i…

Fix: 7.92+
Fix from $1,600 2019-06-07
Mackeeper CRITICAL 9.8
CVE-2018-10171

Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyzer.AdwareAnalyzerPrivilegedHe…

Mitigation only
Fix from $2,300 2019-06-05
Landesk Management Suite CRITICAL 9.0
CVE-2019-12373

Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to …

Mitigation only
Fix from $2,300 2019-06-03
Firejail HIGH 8.8
CVE-2019-12589

In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restrictions for a process that is joi…

Fix: 0.9.60+
Fix from $1,950 2019-06-03
Ib Wrb302n Firmware MEDIUM 6.8
CVE-2018-20008

iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi credential…

No fix yet
Fix from $1,600 2019-05-28
Panda Antivirus CRITICAL 9.8
CVE-2019-12042

Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda pro…

Fix: 18.07.03+
Fix from $2,300 2019-05-23
Websphere Mq HIGH 7.8
CVE-2019-4078

IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute code as an administrator due to…

Fix: after 9.1.0.1
Fix from $1,950 2019-05-23
Libvirt HIGH 8.8
CVE-2019-10132

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati…

Fix: after 4.1.0
Fix from $1,950 2019-05-22
Xperience CRITICAL 9.1
CVE-2019-12102

Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/inser…

Fix: after 12.0
Fix from $2,300 2019-05-22
Brava\! HIGH 7.4
CVE-2019-12270

OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displayli…

Fix: after 16.4
Fix from $1,950 2019-05-21
Acu Wizard HIGH 7.8
CVE-2019-0138

Improper directory permissions in Intel(R) ACU Wizard version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation…

Fix: after 12.0.0.129
Fix from $1,950 2019-05-17
Quartus Ii HIGH 7.8
CVE-2019-0171

Improper directory permissions in the installer for Intel(R) Quartus(R) software may allow an authenticated user to potentially enable escalation of …

Fix: after 18.1
Fix from $1,950 2019-05-17
GitLab HIGH 7.5
CVE-2018-20500

An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 1…

Fix: 11.4.13 / 11.5.6+
Fix from $1,950 2019-05-17
Proset\/wireless Wifi HIGH 7.8
CVE-2018-3701

Improper directory permissions in the installer for Intel(R) PROSet/Wireless WiFi Software version 20.100 and earlier may allow an authenticated user…

Fix: after 20.100
Fix from $1,950 2019-05-17
Converged Security Management Engine Firmware HIGH 7.8
CVE-2019-0086

Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.…

Fix: 3.1.65 / 11.8.65+
Fix from $1,950 2019-05-17
Smart Ai Speaker Firmware MEDIUM 6.8
CVE-2018-20007

Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical attackers to obtain a root shel…

No fix yet
Fix from $1,600 2019-05-16
GitLab MEDIUM 6.5
CVE-2019-10115

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.…

Fix: 11.7.8 / 11.8.4+
Fix from $1,600 2019-05-16
GitLab MEDIUM 6.5
CVE-2019-10110

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.…

Fix: 11.7.8 / 11.8.4+
Fix from $1,600 2019-05-15
Fedora HIGH 8.8
CVE-2019-11328

An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit thi…

Fix: 3.2.0+
Fix from $1,950 2019-05-14
Foxit Reader HIGH 7.8
CVE-2019-8342

A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorrect permission set.

Mitigation only
Fix from $1,950 2019-05-13
Roav Dashcam A1 Firmware HIGH 7.5
CVE-2018-4028

An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. The H…

No fix yet
Fix from $1,950 2019-05-13
Nas Os HIGH 7.5
CVE-2018-12296EPSS 11%

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information ab…

No fix yet
Fix from $1,950 2019-05-13
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4072EPSS 27%

An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…

No fix yet
Fix from $1,950 2019-05-06
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4073EPSS 26%

An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…

No fix yet
Fix from $1,950 2019-05-06
Nexus 9000 Series Application Centric Infrastructure MEDIUM 6.7
CVE-2019-1803

A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allo…

Mitigation only
Fix from $1,600 2019-05-03
Manageengine Admanager Plus HIGH 7.0
CVE-2018-19374

Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permis…

No fix yet
Fix from $1,950 2019-04-30