Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 5.5 CVE-2017-12167 It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma… Jboss Enterprise Application Platform 7.0.9+ Fix from $1,6002018-07-26 HIGH 7.5 CVE-2018-10869 redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file access… Certification Mitigation only Fix from $1,9502018-07-19 MEDIUM 5.5 CVE-2018-0392 A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerabilit… Mobility Services Engine 3365 Firmware Mitigation only Fix from $1,6002018-07-18 HIGH 7.2 CVE-2018-1000207EPSS 64% MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb clas… Modx Revolution after 2.6.4 Fix from $1,9502018-07-13 HIGH 8.8 CVE-2018-1000209 Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Windows platforms that can resul… Sensu Core 1.4.2-3+ Fix from $1,9502018-07-13 HIGH 7.5 CVE-2018-1000211 Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in A… Doorkeeper after 4.2.0 Fix from $1,9502018-07-13 CRITICAL 9.8 CVE-2018-14043 mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an ex… Mstdlib Patch available Fix from $2,3002018-07-13 MEDIUM 6.5 CVE-2018-12979EPSS 8% An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user … 762 3000 Firmware 02+ Fix from $1,6002018-07-12 CRITICAL 9.8 CVE-2018-13791 The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Se… Flexicapture Mitigation only Fix from $2,3002018-07-09 HIGH 8.1 CVE-2018-1000621 Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket configuration that can result in c… Mycroft Core after 18.2.8b Fix from $1,9502018-07-09 CRITICAL 9.0 CVE-2017-7471 Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access contro… Qemu after 2.8.1.1 Fix from $2,3002018-07-09 HIGH 7.7 CVE-2018-11259 Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based devic… Mdm9206 Firmware Mitigation only Fix from $1,9502018-07-06 HIGH 7.5 CVE-2018-13110EPSS 6% All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain ac… Dv2210 Firmware No fix yet Fix from $1,9502018-07-06 MEDIUM 6.5 CVE-2018-13122 onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?… Onefilecms after 3.6.13 Fix from $1,6002018-07-03 HIGH 7.8 CVE-2018-11642 Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local use… Powermedia Xms after 3.5 Fix from $1,9502018-07-03 HIGH 8.8 CVE-2018-10856 It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unn… Libpod 0.6.1+ Fix from $1,9502018-07-03 MEDIUM 5.3 CVE-2018-1113 setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates sec… Setup 2.11.4+ Fix from $1,6002018-07-03 HIGH 8.8 CVE-2018-10843 source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile… Openshift Container Platform 3.7.53+ Fix from $1,9502018-07-02 HIGH 7.5 CVE-2018-12922 Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/configTelne… Liebert Intellislot Firmware Mitigation only Fix from $1,9502018-06-28 MEDIUM 6.5 CVE-2018-1354 An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allo… Fortianalyzer after 6.0.0 Fix from $1,6002018-06-27 MEDIUM 6.5 CVE-2018-11053 Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file p… Emc Idrac Service Module Patch available Fix from $1,6002018-06-26 MEDIUM 5.3 CVE-2018-1000547 coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to acce… Corebos after 7.0 Fix from $1,6002018-06-26 MEDIUM 6.5 CVE-2018-1000510 WP Image Zoom version 1.23 contains a Incorrect Access Control vulnerability in AJAX settings that can result in allows anybody to cause denial of se… Image Zoom No fix yet Fix from $1,6002018-06-26 HIGH 7.5 CVE-2018-1000511 WP ULike version 2.8.1, 3.1 contains a Incorrect Access Control vulnerability in AJAX that can result in allows anybody to delete any row in certain … Ulike No fix yet Fix from $1,9502018-06-26 HIGH 7.5 CVE-2018-12642 Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user. Froxlor after 0.9.39.5 Fix from $1,9502018-06-22 MEDIUM 5.3 CVE-2018-12615 An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not … Passenger 5.3.2+ Fix from $1,6002018-06-21 HIGH 8.8 CVE-2018-11116 OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary … Openwrt Mitigation only Fix from $1,9502018-06-19 HIGH 8.8 CVE-2018-12027 An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation… Passenger 5.3.2+ Fix from $1,9502018-06-17 HIGH 7.8 CVE-2018-12028 An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, up… Passenger 5.3.2+ Fix from $1,9502018-06-17 HIGH 7.3 CVE-2018-12335 Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipul… System Management Appliance Mitigation only Fix from $1,9502018-06-17