Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Computing Improvement Program HIGH 7.8
CVE-2018-12168

Privilege escalation in file permissions in Intel Computing Improvement Program before version 2.2.0.03942 may allow an authenticated user to potenti…

Fix: 2.2.0.03942+
Fix from $1,950 2018-09-12
Driver \& Support Assistant HIGH 7.8
CVE-2018-12148

Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute …

Fix: 3.5.0.1+
Fix from $1,950 2018-09-12
Manageengine Desktop Central HIGH 8.8
CVE-2018-13411

An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to…

Fix: 10.0.282+
Fix from $1,950 2018-09-12
Manageengine Desktop Central HIGH 7.8
CVE-2018-13412

An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running…

Fix: 10.0.282+
Fix from $1,950 2018-09-12
Loading Docs HIGH 7.5
CVE-2018-15502

Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests fo…

Mitigation only
Fix from $1,950 2018-09-12
Emc Vplex Geosynchrony HIGH 7.5
CVE-2018-11078

Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could …

Fix: 6.1+
Fix from $1,950 2018-09-11
Ctes Windows Agent HIGH 8.8
CVE-2018-16715

An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub…

Fix: after 1.0.0.1479
Fix from $1,950 2018-09-08
Gleez Cms MEDIUM 5.3
CVE-2018-16703

A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can fu…

Mitigation only
Fix from $1,600 2018-09-07
Tock HIGH 7.5
CVE-2018-1000660

TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b85d contains a Insecure Permi…

Fix: 1.2+
Fix from $1,950 2018-09-06
Opsview HIGH 8.1
CVE-2018-16145

The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can…

Fix: 5.3.1 / 5.4.2+
Fix from $1,950 2018-09-05
Xbtit CRITICAL 9.8
CVE-2018-15681

An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass…

No fix yet
Fix from $2,300 2018-09-05
Asset Manager HIGH 7.8
CVE-2018-16545

Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve arbitrary code execution via f…

Fix: after 1.0.1230.0
Fix from $1,950 2018-09-05
Wonder Rc555l Firmware HIGH 7.1
CVE-2018-6598

An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices. Any app co-located on the device can send…

Mitigation only
Fix from $1,950 2018-08-29
Packer MEDIUM 5.3
CVE-2018-15869

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validati…

Fix: 1.3.0+
Fix from $1,600 2018-08-25
Accupos MEDIUM 5.5
CVE-2018-15809

AccuPOS 2017.8 is installed with the insecure "Authenticated Users: Modify" permission for files within the installation path. This may allow local a…

Mitigation only
Fix from $1,600 2018-08-23
Cobbler CRITICAL 9.8
CVE-2018-1000226EPSS 12%

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be …

Mitigation only
Fix from $2,300 2018-08-20
Librehealth Ehr HIGH 8.8
CVE-2018-1000649

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functi…

No fix yet
Fix from $1,950 2018-08-20
Antilogger HIGH 7.5
CVE-2018-15491

A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to …

Fix: 1.9.3.602+
Fix from $1,950 2018-08-18
Android CRITICAL 9.8
CVE-2018-14981

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005.

Mitigation only
Fix from $2,300 2018-08-17
Android CRITICAL 9.8
CVE-2018-14982

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.

Mitigation only
Fix from $2,300 2018-08-17
Android CRITICAL 9.8
CVE-2018-15482

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.

Mitigation only
Fix from $2,300 2018-08-17
Big Ip Access Policy Manager Client HIGH 7.8
CVE-2018-5546

The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can al…

Fix: after 12.1.3
Fix from $1,950 2018-08-17
Simatic Step 7 \(tia Portal\) HIGH 7.8
CVE-2018-11453

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) a…

Mitigation only
Fix from $1,950 2018-08-07
Simatic Step 7 \(tia Portal\) HIGH 8.6
CVE-2018-11454

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) a…

No fix yet
Fix from $1,950 2018-08-07
Websphere Mq HIGH 7.5
CVE-2018-1551

IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administ…

Fix: after 9.0.0.3
Fix from $1,950 2018-08-06
Clustered Data Ontap HIGH 8.8
CVE-2018-5490

Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "re…

Fix: 8.3+
Fix from $1,950 2018-08-03
Open Build Service MEDIUM 6.5
CVE-2018-12466

openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.

Fix: 9.2.4+
Fix from $1,600 2018-08-01
Open Build Service MEDIUM 6.5
CVE-2018-12467

Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDe…

Fix: 2.9.4+
Fix from $1,600 2018-08-01
Dracut HIGH 7.8
CVE-2016-8637

A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio…

Fix: 045+
Fix from $1,950 2018-08-01
Enterprise Linux HIGH 8.1
CVE-2017-2590

A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while mod…

Fix: 4.4.0+
Fix from $1,950 2018-07-27