Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2018-12168 Privilege escalation in file permissions in Intel Computing Improvement Program before version 2.2.0.03942 may allow an authenticated user to potenti… Computing Improvement Program 2.2.0.03942+ Fix from $1,9502018-09-12 HIGH 7.8 CVE-2018-12148 Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute … Driver \& Support Assistant 3.5.0.1+ Fix from $1,9502018-09-12 HIGH 8.8 CVE-2018-13411 An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to… Manageengine Desktop Central 10.0.282+ Fix from $1,9502018-09-12 HIGH 7.8 CVE-2018-13412 An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running… Manageengine Desktop Central 10.0.282+ Fix from $1,9502018-09-12 HIGH 7.5 CVE-2018-15502 Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests fo… Loading Docs Mitigation only Fix from $1,9502018-09-12 HIGH 7.5 CVE-2018-11078 Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could … Emc Vplex Geosynchrony 6.1+ Fix from $1,9502018-09-11 HIGH 8.8 CVE-2018-16715 An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub… Ctes Windows Agent after 1.0.0.1479 Fix from $1,9502018-09-08 MEDIUM 5.3 CVE-2018-16703 A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can fu… Gleez Cms Mitigation only Fix from $1,6002018-09-07 HIGH 7.5 CVE-2018-1000660 TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b85d contains a Insecure Permi… Tock 1.2+ Fix from $1,9502018-09-06 HIGH 8.1 CVE-2018-16145 The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can… Opsview 5.3.1 / 5.4.2+ Fix from $1,9502018-09-05 CRITICAL 9.8 CVE-2018-15681 An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass… Xbtit No fix yet Fix from $2,3002018-09-05 HIGH 7.8 CVE-2018-16545 Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve arbitrary code execution via f… Asset Manager after 1.0.1230.0 Fix from $1,9502018-09-05 HIGH 7.1 CVE-2018-6598 An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices. Any app co-located on the device can send… Wonder Rc555l Firmware Mitigation only Fix from $1,9502018-08-29 MEDIUM 5.3 CVE-2018-15869 An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validati… Packer 1.3.0+ Fix from $1,6002018-08-25 MEDIUM 5.5 CVE-2018-15809 AccuPOS 2017.8 is installed with the insecure "Authenticated Users: Modify" permission for files within the installation path. This may allow local a… Accupos Mitigation only Fix from $1,6002018-08-23 CRITICAL 9.8 CVE-2018-1000226EPSS 12% Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be … Cobbler Mitigation only Fix from $2,3002018-08-20 HIGH 8.8 CVE-2018-1000649 LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functi… Librehealth Ehr No fix yet Fix from $1,9502018-08-20 HIGH 7.5 CVE-2018-15491 A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to … Antilogger 1.9.3.602+ Fix from $1,9502018-08-18 CRITICAL 9.8 CVE-2018-14981 Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005. Android Mitigation only Fix from $2,3002018-08-17 CRITICAL 9.8 CVE-2018-14982 Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004. Android Mitigation only Fix from $2,3002018-08-17 CRITICAL 9.8 CVE-2018-15482 Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006. Android Mitigation only Fix from $2,3002018-08-17 HIGH 7.8 CVE-2018-5546 The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can al… Big Ip Access Policy Manager Client after 12.1.3 Fix from $1,9502018-08-17 HIGH 7.8 CVE-2018-11453 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) a… Simatic Step 7 \(tia Portal\) Mitigation only Fix from $1,9502018-08-07 HIGH 8.6 CVE-2018-11454 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) a… Simatic Step 7 \(tia Portal\) No fix yet Fix from $1,9502018-08-07 HIGH 7.5 CVE-2018-1551 IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administ… Websphere Mq after 9.0.0.3 Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-5490 Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "re… Clustered Data Ontap 8.3+ Fix from $1,9502018-08-03 MEDIUM 6.5 CVE-2018-12466 openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links. Open Build Service 9.2.4+ Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-12467 Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDe… Open Build Service 2.9.4+ Fix from $1,6002018-08-01 HIGH 7.8 CVE-2016-8637 A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio… Dracut 045+ Fix from $1,9502018-08-01 HIGH 8.1 CVE-2017-2590 A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while mod… Enterprise Linux 4.4.0+ Fix from $1,9502018-07-27