Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.8 CVE-2018-10204 PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service. When configured to use the OpenVPN p… Purevpn Mitigation only Fix from $1,9502018-04-18 HIGH 8.8 CVE-2018-1000158 cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['adm… Cms Made Simple No fix yet Fix from $1,9502018-04-18 HIGH 7.5 CVE-2018-1000165 LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in src/LightSaml/Model/XmlDSig/… Lightsaml 1.3.5+ Fix from $1,9502018-04-18 HIGH 7.2 CVE-2018-5342 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a … Manageengine Desktop Central No fix yet Fix from $1,9502018-04-18 CRITICAL 9.8 CVE-2018-10169 ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "ProtonVPN Service" service. This service establishe… Protonvpn Mitigation only Fix from $2,3002018-04-16 CRITICAL 9.8 CVE-2018-10170 NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes… Nordvpn Mitigation only Fix from $2,3002018-04-16 CRITICAL 9.1 CVE-2018-1002150 Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vu… Koji Mitigation only Fix from $2,3002018-04-04 MEDIUM 5.4 CVE-2017-1624 IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintend… Qradar Security Information And Event Manager Patch available Fix from $1,6002018-04-04 HIGH 8.8 CVE-2018-1231 Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH… Bosh Cli 3.0.1+ Fix from $1,9502018-03-27 HIGH 8.1 CVE-2018-1267 Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an appl… Silk Release 0.2.0+ Fix from $1,9502018-03-27 MEDIUM 6.7 CVE-2018-1203 In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2,… Emc Isilon Onefs after 8.1.0.1 Fix from $1,6002018-03-26 HIGH 7.8 CVE-2018-5349 A vulnerability has been found in Heimdal PRO v2.2.190, but it is most likely also present in Heimdal FREE and Heimdal CORP. Faulty permissions on th… Heimdal No fix yet Fix from $1,9502018-03-22 CRITICAL 9.0 CVE-2018-8931 The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1. Ryzen Mobile Firmware Mitigation only Fix from $2,3002018-03-22 CRITICAL 9.0 CVE-2018-8932 The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZENFALL-4. Ryzen Pro Firmware Mitigation only Fix from $2,3002018-03-22 CRITICAL 9.0 CVE-2018-8933 The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3. Epyc Server Firmware Mitigation only Fix from $2,3002018-03-22 HIGH 7.0 CVE-2018-1141 When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-dire… Nessus 7.0.3+ Fix from $1,9502018-03-20 HIGH 8.5 CVE-2018-1197 In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata en… Windows Stemcells 1200.14+ Fix from $1,9502018-03-19 CRITICAL 9.1 CVE-2018-1000132 Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data… Debian Linux 4.5.1+ Fix from $2,3002018-03-14 HIGH 7.8 CVE-2018-1386 IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could… Tivoli Workload Scheduler Mitigation only Fix from $1,9502018-03-14 HIGH 7.5 CVE-2018-1000071 roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private ke… Webmail after 1.3.4 Fix from $1,9502018-03-13 HIGH 7.5 CVE-2018-1000072 iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's pa… Iredmail after 0.9.6 Fix from $1,9502018-03-13 MEDIUM 6.5 CVE-2018-1000080 Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a … Ajenti No fix yet Fix from $1,6002018-03-13 HIGH 8.8 CVE-2018-6623 An issue was discovered in Hola 1.79.859. An unprivileged user could modify or overwrite the executable with arbitrary code, which would be executed … Vpn Mitigation only Fix from $1,9502018-03-12 HIGH 7.8 CVE-2017-18225 The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by … Jabberd2 after 2.6.1 Fix from $1,9502018-03-12 MEDIUM 5.5 CVE-2017-18226 The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill a… Jabberd2 after 2.6.1 Fix from $1,6002018-03-12 HIGH 7.8 CVE-2018-7581 \ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUILTIN\Users:(ID)C), which allow… Weblog Expert No fix yet Fix from $1,9502018-03-09 HIGH 7.1 CVE-2018-1069 Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the U… Openshift Mitigation only Fix from $1,9502018-03-09 HIGH 7.8 CVE-2018-5313 A vulnerability allows local attackers to escalate privilege on Rapid Scada 5.5.0 because of weak C:\SCADA permissions. The specific flaw exists with… Rapid Scada No fix yet Fix from $1,9502018-03-08 MEDIUM 5.3 CVE-2017-6928 Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allow… Drupal 7.57+ Fix from $1,6002018-03-01 MEDIUM 6.5 CVE-2017-9268 In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated user… Open Build Service after 2.8.2 Fix from $1,6002018-03-01