Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.1 CVE-2018-14980 The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-k… Zenfone 3 Max Firmware Mitigation only Fix from $1,9502019-04-25 HIGH 8.8 CVE-2019-10710 Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a net… Hi3510 Firmware Mitigation only Fix from $1,9502019-04-23 MEDIUM 5.0 CVE-2019-11244 In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), writt… Kubernetes after 1.14.1 Fix from $1,6002019-04-22 HIGH 7.8 CVE-2018-18094 Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to potentially enable escalation … Media Sdk Patch available Fix from $1,9502019-04-17 HIGH 8.1 CVE-2019-9222 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Pe… GitLab 11.6.10 / 11.7.6+ Fix from $1,9502019-04-17 HIGH 7.8 CVE-2018-6269 NVIDIA Jetson TX2 contains a vulnerability in the kernel driver where input/output control (IOCTL) handling for user mode requests could create a non… Jetson Tx2 Mitigation only Fix from $1,9502019-04-12 HIGH 8.8 CVE-2018-17305 UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to priv… Orchestrator after 2018.2.4 Fix from $1,9502019-04-11 MEDIUM 6.5 CVE-2018-19589 Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM product package allows an SO au… Securityserver Cse Firmware No fix yet Fix from $1,6002019-04-09 MEDIUM 6.5 CVE-2019-0804EPSS 5% An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information… Walinuxagent 2.2.38+ Fix from $1,6002019-04-09 MEDIUM 5.5 CVE-2018-1787 IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872. Spectrum Protect For Virtual Environments after 8.1.6.1 Fix from $1,6002019-04-08 MEDIUM 5.5 CVE-2018-4324 A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls. This issue affected versions pri… Mac Os X 10.14+ Fix from $1,6002019-04-03 MEDIUM 5.5 CVE-2018-4178 A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This i… Mac Os X 10.13.4+ Fix from $1,6002019-04-03 HIGH 7.8 CVE-2018-3974 An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install directory. An attacker can overw… Galaxy No fix yet Fix from $1,9502019-04-02 HIGH 7.8 CVE-2018-4049 An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Wi… Galaxy Mitigation only Fix from $1,9502019-04-02 MEDIUM 5.5 CVE-2018-4051 An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An atta… Galaxy Mitigation only Fix from $1,6002019-04-02 HIGH 7.3 CVE-2018-19113 The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGR… Pronestor Health Monitoring 8.1.12.0+ Fix from $1,9502019-04-01 HIGH 7.8 CVE-2018-4050 An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An atta… Galaxy Mitigation only Fix from $1,9502019-04-01 HIGH 7.8 CVE-2019-9166 Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xi… Nagios Xi 5.5.11+ Fix from $1,9502019-03-28 CRITICAL 9.8 CVE-2017-9626 Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based application… Pluto1203 Mitigation only Fix from $2,3002019-03-27 MEDIUM 6.5 CVE-2018-12546 In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoke… Mosquitto after 1.5.5 Fix from $1,6002019-03-27 HIGH 7.8 CVE-2018-18435 KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyo… Kioware Server after 4.9.6 Fix from $1,9502019-03-21 HIGH 7.5 CVE-2018-15508 Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on po… Agent Desktop Plus No fix yet Fix from $1,9502019-03-21 CRITICAL 9.8 CVE-2018-15509 Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2). Agent Desktop Plus No fix yet Fix from $2,3002019-03-18 HIGH 7.5 CVE-2018-19393 Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. … Satcom Sailor 800 Firmware Mitigation only Fix from $1,9502019-03-15 HIGH 7.8 CVE-2018-18254 An issue was discovered in CapMon Access Manager 5.4.1.1005. An unprivileged user can read the cal_whitelist table in the Custom App Launcher (CAL) d… Access Manager after 5.4.1.1005 Fix from $1,9502019-03-15 MEDIUM 6.3 CVE-2018-12223 Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.505… Graphics Driver Patch available Fix from $1,6002019-03-14 MEDIUM 6.7 CVE-2018-12200 Insufficient access control in Intel(R) Capability Licensing Service before version 1.50.638.1 may allow an unprivileged user to potentially escalate… Capability Licensing Service 1.50.638.1+ Fix from $1,6002019-03-14 HIGH 7.8 CVE-2018-20621 An issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planti… Memu No fix yet Fix from $1,9502019-03-13 HIGH 7.8 CVE-2019-1618 A vulnerability in the Tetration Analytics agent for Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local at… Nx Os 7.0+ Fix from $1,9502019-03-11 HIGH 7.8 CVE-2019-1601 A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a… Nx Os 6.0 / 6.2+ Fix from $1,9502019-03-08