Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.8 CVE-2018-12457 expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header. Expresscart 1.1.6+ Fix from $1,9502018-06-15 HIGH 7.0 CVE-2018-0982 An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulne… Windows 10 Patch available Fix from $1,9502018-06-14 HIGH 7.0 CVE-2018-1036 An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Wind… Windows 10 Mitigation only Fix from $1,9502018-06-14 MEDIUM 6.8 CVE-2018-12259 An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full … Momentum Axel 720p Firmware No fix yet Fix from $1,6002018-06-12 CRITICAL 9.8 CVE-2017-7821 A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific… Firefox after 55.0.3 Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5456 A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for… Enterprise Linux 52.1.0 / 53.0+ Fix from $2,3002018-06-11 MEDIUM 5.3 CVE-2017-5426 On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be ap… Firefox 52.0+ Fix from $1,6002018-06-11 MEDIUM 5.5 CVE-2018-4251 An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" component. It allows attackers… Mac Os X 10.13.5+ Fix from $1,6002018-06-08 HIGH 8.8 CVE-2018-4220 An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue involves the "Swift for Ubuntu"… Swift 4.1.1+ Fix from $1,9502018-06-08 MEDIUM 5.5 CVE-2012-0433 The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allo… Crowbar after 1.0 Fix from $1,6002018-06-08 MEDIUM 6.7 CVE-2018-0352 A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local a… Wide Area Application Services Mitigation only Fix from $1,6002018-06-07 HIGH 7.1 CVE-2017-18284 The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to k… Burp 2.1.32+ Fix from $1,9502018-06-04 HIGH 7.1 CVE-2017-18285 The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain re… Burp 2.1.32+ Fix from $1,9502018-06-04 HIGH 8.8 CVE-2018-11191 Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 3 of 6). Disk Backup 4.0.3.1+ Fix from $1,9502018-06-02 HIGH 8.8 CVE-2018-11192 Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 4 of 6). Disk Backup 4.0.3.1+ Fix from $1,9502018-06-02 HIGH 8.8 CVE-2018-11193 Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 5 of 6). Disk Backup 4.0.3.1+ Fix from $1,9502018-06-02 HIGH 8.8 CVE-2018-11194 Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 6 of 6). Disk Backup 4.0.3.1+ Fix from $1,9502018-06-02 MEDIUM 5.4 CVE-2018-1370 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 specifies permissions for a security-critical resource in a way that allows that resource to… Security Guardium Big Data Intelligence Patch available Fix from $1,6002018-05-29 HIGH 7.8 CVE-2018-11334 Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipe\Windscr… Windscribe Mitigation only Fix from $1,9502018-05-23 MEDIUM 5.4 CVE-2017-2612 In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds… Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-05-15 CRITICAL 9.1 CVE-2018-1115 postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same … PostgreSQL 9.6.9 / 10.4+ Fix from $2,3002018-05-10 HIGH 7.5 CVE-2017-4952 VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authenticat… Xenon after 1.5.3 Fix from $1,9502018-05-02 HIGH 7.8 CVE-2018-10645 Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVPN" service. This service esta… Vyprvpn Mitigation only Fix from $1,9502018-05-02 HIGH 7.8 CVE-2018-10646 CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes… Cyberghost Mitigation only Fix from $1,9502018-05-02 HIGH 7.8 CVE-2018-10647 SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service… Safervpn Mitigation only Fix from $1,9502018-05-02 MEDIUM 6.5 CVE-2018-10518 In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that c… Cms Made Simple after 2.2.7 Fix from $1,6002018-04-27 HIGH 8.8 CVE-2018-10519 CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value withi… Cms Made Simple No fix yet Fix from $1,9502018-04-27 MEDIUM 6.5 CVE-2018-10520 In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that… Cms Made Simple after 2.2.7 Fix from $1,6002018-04-27 CRITICAL 9.8 CVE-2018-10381 TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service est… Tunnelbear Mitigation only Fix from $2,3002018-04-26 CRITICAL 9.8 CVE-2018-10285EPSS 13% The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attac… Ipecs Nms No fix yet Fix from $2,3002018-04-22