Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2017-12167

It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma…

Fix: 7.0.9+
Fix from $1,600 2018-07-26
Certification HIGH 7.5
CVE-2018-10869

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file access…

Mitigation only
Fix from $1,950 2018-07-19
Mobility Services Engine 3365 Firmware MEDIUM 5.5
CVE-2018-0392

A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerabilit…

Mitigation only
Fix from $1,600 2018-07-18
Modx Revolution HIGH 7.2
CVE-2018-1000207EPSS 64%

MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb clas…

Fix: after 2.6.4
Fix from $1,950 2018-07-13
Sensu Core HIGH 8.8
CVE-2018-1000209

Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Windows platforms that can resul…

Fix: 1.4.2-3+
Fix from $1,950 2018-07-13
Doorkeeper HIGH 7.5
CVE-2018-1000211

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in A…

Fix: after 4.2.0
Fix from $1,950 2018-07-13
Mstdlib CRITICAL 9.8
CVE-2018-14043

mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an ex…

Patch available
Fix from $2,300 2018-07-13
762 3000 Firmware MEDIUM 6.5
CVE-2018-12979EPSS 8%

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user …

Fix: 02+
Fix from $1,600 2018-07-12
Flexicapture CRITICAL 9.8
CVE-2018-13791

The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Se…

Mitigation only
Fix from $2,300 2018-07-09
Mycroft Core HIGH 8.1
CVE-2018-1000621

Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket configuration that can result in c…

Fix: after 18.2.8b
Fix from $1,950 2018-07-09
Qemu CRITICAL 9.0
CVE-2017-7471

Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access contro…

Fix: after 2.8.1.1
Fix from $2,300 2018-07-09
Mdm9206 Firmware HIGH 7.7
CVE-2018-11259

Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based devic…

Mitigation only
Fix from $1,950 2018-07-06
Dv2210 Firmware HIGH 7.5
CVE-2018-13110EPSS 6%

All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain ac…

No fix yet
Fix from $1,950 2018-07-06
Onefilecms MEDIUM 6.5
CVE-2018-13122

onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?…

Fix: after 3.6.13
Fix from $1,600 2018-07-03
Powermedia Xms HIGH 7.8
CVE-2018-11642

Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local use…

Fix: after 3.5
Fix from $1,950 2018-07-03
Libpod HIGH 8.8
CVE-2018-10856

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unn…

Fix: 0.6.1+
Fix from $1,950 2018-07-03
Setup MEDIUM 5.3
CVE-2018-1113

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates sec…

Fix: 2.11.4+
Fix from $1,600 2018-07-03
Openshift Container Platform HIGH 8.8
CVE-2018-10843

source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile…

Fix: 3.7.53+
Fix from $1,950 2018-07-02
Liebert Intellislot Firmware HIGH 7.5
CVE-2018-12922

Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/configTelne…

Mitigation only
Fix from $1,950 2018-06-28
Fortianalyzer MEDIUM 6.5
CVE-2018-1354

An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allo…

Fix: after 6.0.0
Fix from $1,600 2018-06-27
Emc Idrac Service Module MEDIUM 6.5
CVE-2018-11053

Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file p…

Patch available
Fix from $1,600 2018-06-26
Corebos MEDIUM 5.3
CVE-2018-1000547

coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to acce…

Fix: after 7.0
Fix from $1,600 2018-06-26
Image Zoom MEDIUM 6.5
CVE-2018-1000510

WP Image Zoom version 1.23 contains a Incorrect Access Control vulnerability in AJAX settings that can result in allows anybody to cause denial of se…

No fix yet
Fix from $1,600 2018-06-26
Ulike HIGH 7.5
CVE-2018-1000511

WP ULike version 2.8.1, 3.1 contains a Incorrect Access Control vulnerability in AJAX that can result in allows anybody to delete any row in certain …

No fix yet
Fix from $1,950 2018-06-26
Froxlor HIGH 7.5
CVE-2018-12642

Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

Fix: after 0.9.39.5
Fix from $1,950 2018-06-22
Passenger MEDIUM 5.3
CVE-2018-12615

An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not …

Fix: 5.3.2+
Fix from $1,600 2018-06-21
Openwrt HIGH 8.8
CVE-2018-11116

OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary …

Mitigation only
Fix from $1,950 2018-06-19
Passenger HIGH 8.8
CVE-2018-12027

An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation…

Fix: 5.3.2+
Fix from $1,950 2018-06-17
Passenger HIGH 7.8
CVE-2018-12028

An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, up…

Fix: 5.3.2+
Fix from $1,950 2018-06-17
System Management Appliance HIGH 7.3
CVE-2018-12335

Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipul…

Mitigation only
Fix from $1,950 2018-06-17