Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.1 CVE-2018-1417 Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manag… Java Sdk Mitigation only Fix from $1,9502018-02-22 HIGH 7.8 CVE-2018-7408 An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g n… Npm Patch available Fix from $1,9502018-02-22 HIGH 8.8 CVE-2018-7311 PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability. The software installs a privileged helper tool that runs as the r… Privatevpn Mitigation only Fix from $1,9502018-02-21 CRITICAL 9.8 CVE-2018-1164 This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.… P 870h 51 Firmware Mitigation only Fix from $2,3002018-02-21 HIGH 7.8 CVE-2018-1168 This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must fi… Sys600 Firmware Mitigation only Fix from $1,9502018-02-21 MEDIUM 5.3 CVE-2018-7169 An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where s… Shadow No fix yet Fix from $1,6002018-02-15 HIGH 7.8 CVE-2017-13236 In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege wi… Android No fix yet Fix from $1,9502018-02-12 HIGH 8.1 CVE-2018-1000025 Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVer… Firebase Admin Sdk For Php after 3.8.0 Fix from $1,9502018-02-09 HIGH 7.0 CVE-2018-1053 In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in curr… PostgreSQL 9.3.21 / 9.4.16+ Fix from $1,9502018-02-09 HIGH 7.8 CVE-2018-6606 An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to r… Antimalware No fix yet Fix from $1,9502018-02-04 HIGH 7.8 CVE-2018-6593 An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to r… Antimalware No fix yet Fix from $1,9502018-02-03 MEDIUM 5.5 CVE-2018-6536 An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which mi… Icinga after 2.8.1 Fix from $1,6002018-02-02 HIGH 7.8 CVE-2017-16928 The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a cra… Arq after 5.10 Fix from $1,9502018-01-31 HIGH 7.8 CVE-2017-16945 The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via … Arq after 5.10 Fix from $1,9502018-01-31 HIGH 8.8 CVE-2017-1000403 Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effecti… Speaks\! after 0.1.1 Fix from $1,9502018-01-26 MEDIUM 6.7 CVE-2018-0088 A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow a… Industrial Ethernet 4010 Series Firmware Mitigation only Fix from $1,6002018-01-18 HIGH 7.5 CVE-2018-0089 A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to a… Policy Suite Mitigation only Fix from $1,9502018-01-18 CRITICAL 9.8 CVE-2017-16885EPSS 33% Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Chan… Lm53q1 Firmware No fix yet Fix from $2,3002018-01-12 HIGH 8.8 CVE-2017-17867EPSS 11% Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the o… Iopsys after 3.14 Fix from $1,9502018-01-04 HIGH 7.8 CVE-2018-0752 The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Win… Windows 10 Patch available Fix from $1,9502018-01-04 HIGH 7.8 CVE-2017-1000485 Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authentication information via stand… Nylas Mail Mitigation only Fix from $1,9502018-01-03 HIGH 8.8 CVE-2017-5260EPSS 8% In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the nor… Cnpilot R190v Firmware after 4.3.2-r4 Fix from $1,9502017-12-20 MEDIUM 5.4 CVE-2017-1266 IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by uninte… Security Guardium Mitigation only Fix from $1,6002017-12-20 CRITICAL 9.8 CVE-2017-15877 Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view the password and user database. Gpweb No fix yet Fix from $2,3002017-12-19 HIGH 7.5 CVE-2017-17568 Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might… Posty Readymade Classifieds No fix yet Fix from $1,9502017-12-13 HIGH 7.8 CVE-2017-13168 An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233. Ubuntu Linux No fix yet Fix from $1,9502017-12-06 HIGH 7.8 CVE-2017-16895 The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 … Arq 5.10+ Fix from $1,9502017-12-01 HIGH 7.0 CVE-2017-16933 etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gai… Icinga after 2.8.0 Fix from $1,9502017-11-24 MEDIUM 6.5 CVE-2017-8158 FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the … Fusioncompute Mitigation only Fix from $1,6002017-11-22 HIGH 7.8 CVE-2017-16882 Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account… Icinga after 1.14.0 Fix from $1,9502017-11-18