Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Purevpn HIGH 8.8
CVE-2018-10204

PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service. When configured to use the OpenVPN p…

Mitigation only
Fix from $1,950 2018-04-18
Cms Made Simple HIGH 8.8
CVE-2018-1000158

cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['adm…

No fix yet
Fix from $1,950 2018-04-18
Lightsaml HIGH 7.5
CVE-2018-1000165

LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in src/LightSaml/Model/XmlDSig/…

Fix: 1.3.5+
Fix from $1,950 2018-04-18
Manageengine Desktop Central HIGH 7.2
CVE-2018-5342

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a …

No fix yet
Fix from $1,950 2018-04-18
Protonvpn CRITICAL 9.8
CVE-2018-10169

ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "ProtonVPN Service" service. This service establishe…

Mitigation only
Fix from $2,300 2018-04-16
Nordvpn CRITICAL 9.8
CVE-2018-10170

NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes…

Mitigation only
Fix from $2,300 2018-04-16
Koji CRITICAL 9.1
CVE-2018-1002150

Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vu…

Mitigation only
Fix from $2,300 2018-04-04
Qradar Security Information And Event Manager MEDIUM 5.4
CVE-2017-1624

IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintend…

Patch available
Fix from $1,600 2018-04-04
Bosh Cli HIGH 8.8
CVE-2018-1231

Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH…

Fix: 3.0.1+
Fix from $1,950 2018-03-27
Silk Release HIGH 8.1
CVE-2018-1267

Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an appl…

Fix: 0.2.0+
Fix from $1,950 2018-03-27
Emc Isilon Onefs MEDIUM 6.7
CVE-2018-1203

In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2,…

Fix: after 8.1.0.1
Fix from $1,600 2018-03-26
Heimdal HIGH 7.8
CVE-2018-5349

A vulnerability has been found in Heimdal PRO v2.2.190, but it is most likely also present in Heimdal FREE and Heimdal CORP. Faulty permissions on th…

No fix yet
Fix from $1,950 2018-03-22
Ryzen Mobile Firmware CRITICAL 9.0
CVE-2018-8931

The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.

Mitigation only
Fix from $2,300 2018-03-22
Ryzen Pro Firmware CRITICAL 9.0
CVE-2018-8932

The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZENFALL-4.

Mitigation only
Fix from $2,300 2018-03-22
Epyc Server Firmware CRITICAL 9.0
CVE-2018-8933

The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.

Mitigation only
Fix from $2,300 2018-03-22
Nessus HIGH 7.0
CVE-2018-1141

When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-dire…

Fix: 7.0.3+
Fix from $1,950 2018-03-20
Windows Stemcells HIGH 8.5
CVE-2018-1197

In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata en…

Fix: 1200.14+
Fix from $1,950 2018-03-19
Debian Linux CRITICAL 9.1
CVE-2018-1000132

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data…

Fix: 4.5.1+
Fix from $2,300 2018-03-14
Tivoli Workload Scheduler HIGH 7.8
CVE-2018-1386

IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could…

Mitigation only
Fix from $1,950 2018-03-14
Webmail HIGH 7.5
CVE-2018-1000071

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private ke…

Fix: after 1.3.4
Fix from $1,950 2018-03-13
Iredmail HIGH 7.5
CVE-2018-1000072

iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's pa…

Fix: after 0.9.6
Fix from $1,950 2018-03-13
Ajenti MEDIUM 6.5
CVE-2018-1000080

Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a …

No fix yet
Fix from $1,600 2018-03-13
Vpn HIGH 8.8
CVE-2018-6623

An issue was discovered in Hola 1.79.859. An unprivileged user could modify or overwrite the executable with arbitrary code, which would be executed …

Mitigation only
Fix from $1,950 2018-03-12
Jabberd2 HIGH 7.8
CVE-2017-18225

The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by …

Fix: after 2.6.1
Fix from $1,950 2018-03-12
Jabberd2 MEDIUM 5.5
CVE-2017-18226

The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill a…

Fix: after 2.6.1
Fix from $1,600 2018-03-12
Weblog Expert HIGH 7.8
CVE-2018-7581

\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUILTIN\Users:(ID)C), which allow…

No fix yet
Fix from $1,950 2018-03-09
Openshift HIGH 7.1
CVE-2018-1069

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the U…

Mitigation only
Fix from $1,950 2018-03-09
Rapid Scada HIGH 7.8
CVE-2018-5313

A vulnerability allows local attackers to escalate privilege on Rapid Scada 5.5.0 because of weak C:\SCADA permissions. The specific flaw exists with…

No fix yet
Fix from $1,950 2018-03-08
Drupal MEDIUM 5.3
CVE-2017-6928

Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allow…

Fix: 7.57+
Fix from $1,600 2018-03-01
Open Build Service MEDIUM 6.5
CVE-2017-9268

In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated user…

Fix: after 2.8.2
Fix from $1,600 2018-03-01