Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Manageengine Admanager Plus HIGH 7.0
CVE-2018-19374

Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permis…

No fix yet
Fix from $1,950 2019-04-30
Zenfone 3 Max Firmware HIGH 7.1
CVE-2018-14980

The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-k…

Mitigation only
Fix from $1,950 2019-04-25
Hi3510 Firmware HIGH 8.8
CVE-2019-10710

Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a net…

Mitigation only
Fix from $1,950 2019-04-23
Kubernetes MEDIUM 5.0
CVE-2019-11244

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), writt…

Fix: after 1.14.1
Fix from $1,600 2019-04-22
Media Sdk HIGH 7.8
CVE-2018-18094

Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to potentially enable escalation …

Patch available
Fix from $1,950 2019-04-17
GitLab HIGH 8.1
CVE-2019-9222

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Pe…

Fix: 11.6.10 / 11.7.6+
Fix from $1,950 2019-04-17
Jetson Tx2 HIGH 7.8
CVE-2018-6269

NVIDIA Jetson TX2 contains a vulnerability in the kernel driver where input/output control (IOCTL) handling for user mode requests could create a non…

Mitigation only
Fix from $1,950 2019-04-12
Orchestrator HIGH 8.8
CVE-2018-17305

UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to priv…

Fix: after 2018.2.4
Fix from $1,950 2019-04-11
Securityserver Cse Firmware MEDIUM 6.5
CVE-2018-19589

Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM product package allows an SO au…

No fix yet
Fix from $1,600 2019-04-09
Walinuxagent MEDIUM 6.5
CVE-2019-0804EPSS 5%

An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information…

Fix: 2.2.38+
Fix from $1,600 2019-04-09
Spectrum Protect For Virtual Environments MEDIUM 5.5
CVE-2018-1787

IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.

Fix: after 8.1.6.1
Fix from $1,600 2019-04-08
Mac Os X MEDIUM 5.5
CVE-2018-4324

A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls. This issue affected versions pri…

Fix: 10.14+
Fix from $1,600 2019-04-03
Mac Os X MEDIUM 5.5
CVE-2018-4178

A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This i…

Fix: 10.13.4+
Fix from $1,600 2019-04-03
Galaxy HIGH 7.8
CVE-2018-3974

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install directory. An attacker can overw…

No fix yet
Fix from $1,950 2019-04-02
Galaxy HIGH 7.8
CVE-2018-4049

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Wi…

Mitigation only
Fix from $1,950 2019-04-02
Galaxy MEDIUM 5.5
CVE-2018-4051

An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An atta…

Mitigation only
Fix from $1,600 2019-04-02
Pronestor Health Monitoring HIGH 7.3
CVE-2018-19113

The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGR…

Fix: 8.1.12.0+
Fix from $1,950 2019-04-01
Galaxy HIGH 7.8
CVE-2018-4050

An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An atta…

Mitigation only
Fix from $1,950 2019-04-01
Nagios Xi HIGH 7.8
CVE-2019-9166

Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xi…

Fix: 5.5.11+
Fix from $1,950 2019-03-28
Pluto1203 CRITICAL 9.8
CVE-2017-9626

Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based application…

Mitigation only
Fix from $2,300 2019-03-27
Mosquitto MEDIUM 6.5
CVE-2018-12546

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoke…

Fix: after 1.5.5
Fix from $1,600 2019-03-27
Kioware Server HIGH 7.8
CVE-2018-18435

KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyo…

Fix: after 4.9.6
Fix from $1,950 2019-03-21
Agent Desktop Plus HIGH 7.5
CVE-2018-15508

Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on po…

No fix yet
Fix from $1,950 2019-03-21
Agent Desktop Plus CRITICAL 9.8
CVE-2018-15509

Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).

No fix yet
Fix from $2,300 2019-03-18
Satcom Sailor 800 Firmware HIGH 7.5
CVE-2018-19393

Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. …

Mitigation only
Fix from $1,950 2019-03-15
Access Manager HIGH 7.8
CVE-2018-18254

An issue was discovered in CapMon Access Manager 5.4.1.1005. An unprivileged user can read the cal_whitelist table in the Custom App Launcher (CAL) d…

Fix: after 5.4.1.1005
Fix from $1,950 2019-03-15
Graphics Driver MEDIUM 6.3
CVE-2018-12223

Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.505…

Patch available
Fix from $1,600 2019-03-14
Capability Licensing Service MEDIUM 6.7
CVE-2018-12200

Insufficient access control in Intel(R) Capability Licensing Service before version 1.50.638.1 may allow an unprivileged user to potentially escalate…

Fix: 1.50.638.1+
Fix from $1,600 2019-03-14
Memu HIGH 7.8
CVE-2018-20621

An issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planti…

No fix yet
Fix from $1,950 2019-03-13
Nx Os HIGH 7.8
CVE-2019-1618

A vulnerability in the Tetration Analytics agent for Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local at…

Fix: 7.0+
Fix from $1,950 2019-03-11