Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Expresscart HIGH 8.8
CVE-2018-12457

expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.

Fix: 1.1.6+
Fix from $1,950 2018-06-15
Windows 10 HIGH 7.0
CVE-2018-0982

An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulne…

Patch available
Fix from $1,950 2018-06-14
Windows 10 HIGH 7.0
CVE-2018-1036

An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Wind…

Mitigation only
Fix from $1,950 2018-06-14
Momentum Axel 720p Firmware MEDIUM 6.8
CVE-2018-12259

An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full …

No fix yet
Fix from $1,600 2018-06-12
Firefox CRITICAL 9.8
CVE-2017-7821

A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific…

Fix: after 55.0.3
Fix from $2,300 2018-06-11
Enterprise Linux CRITICAL 9.8
CVE-2017-5456

A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for…

Fix: 52.1.0 / 53.0+
Fix from $2,300 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5426

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be ap…

Fix: 52.0+
Fix from $1,600 2018-06-11
Mac Os X MEDIUM 5.5
CVE-2018-4251

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" component. It allows attackers…

Fix: 10.13.5+
Fix from $1,600 2018-06-08
Swift HIGH 8.8
CVE-2018-4220

An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue involves the "Swift for Ubuntu"…

Fix: 4.1.1+
Fix from $1,950 2018-06-08
Crowbar MEDIUM 5.5
CVE-2012-0433

The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allo…

Fix: after 1.0
Fix from $1,600 2018-06-08
Wide Area Application Services MEDIUM 6.7
CVE-2018-0352

A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local a…

Mitigation only
Fix from $1,600 2018-06-07
Burp HIGH 7.1
CVE-2017-18284

The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to k…

Fix: 2.1.32+
Fix from $1,950 2018-06-04
Burp HIGH 7.1
CVE-2017-18285

The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain re…

Fix: 2.1.32+
Fix from $1,950 2018-06-04
Disk Backup HIGH 8.8
CVE-2018-11191

Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 3 of 6).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11192

Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 4 of 6).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11193

Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 5 of 6).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11194

Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 6 of 6).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Security Guardium Big Data Intelligence MEDIUM 5.4
CVE-2018-1370

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way that allows that resource to…

Patch available
Fix from $1,600 2018-05-29
Windscribe HIGH 7.8
CVE-2018-11334

Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipe\Windscr…

Mitigation only
Fix from $1,950 2018-05-23
Jenkins MEDIUM 5.4
CVE-2017-2612

In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds…

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-05-15
PostgreSQL CRITICAL 9.1
CVE-2018-1115

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same …

Fix: 9.6.9 / 10.4+
Fix from $2,300 2018-05-10
Xenon HIGH 7.5
CVE-2017-4952

VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authenticat…

Fix: after 1.5.3
Fix from $1,950 2018-05-02
Vyprvpn HIGH 7.8
CVE-2018-10645

Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVPN" service. This service esta…

Mitigation only
Fix from $1,950 2018-05-02
Cyberghost HIGH 7.8
CVE-2018-10646

CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes…

Mitigation only
Fix from $1,950 2018-05-02
Safervpn HIGH 7.8
CVE-2018-10647

SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service…

Mitigation only
Fix from $1,950 2018-05-02
Cms Made Simple MEDIUM 6.5
CVE-2018-10518

In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that c…

Fix: after 2.2.7
Fix from $1,600 2018-04-27
Cms Made Simple HIGH 8.8
CVE-2018-10519

CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value withi…

No fix yet
Fix from $1,950 2018-04-27
Cms Made Simple MEDIUM 6.5
CVE-2018-10520

In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that…

Fix: after 2.2.7
Fix from $1,600 2018-04-27
Tunnelbear CRITICAL 9.8
CVE-2018-10381

TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service est…

Mitigation only
Fix from $2,300 2018-04-26
Ipecs Nms CRITICAL 9.8
CVE-2018-10285EPSS 13%

The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attac…

No fix yet
Fix from $2,300 2018-04-22