Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
GitLab HIGH 7.5
CVE-2018-20494

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…

Fix: 11.4.13 / 11.5.6+
Fix from $1,950 2019-12-30
Cognos Analytics MEDIUM 6.5
CVE-2019-4343

IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private informati…

Mitigation only
Fix from $1,600 2019-12-30
Ip7160 Firmware HIGH 7.5
CVE-2013-4985EPSS 9%

Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream

No fix yet
Fix from $1,950 2019-12-27
GitLab MEDIUM 5.3
CVE-2018-20492

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A…

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-26
Pandora Fms HIGH 8.8
CVE-2019-19681

Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to defin…

Mitigation only
Fix from $1,950 2019-12-26
Email Subscribers \& Newsletters MEDIUM 6.3
CVE-2019-19984

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settin…

Fix: 4.2.3+
Fix from $1,600 2019-12-26
Debian Linux CRITICAL 9.8
CVE-2012-6094

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

Fix: 1.5.4-1.1+
Fix from $2,300 2019-12-20
Iphone Os MEDIUM 5.7
CVE-2019-8512

This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wi…

Fix: 12.2+
Fix from $1,600 2019-12-18
Enterprise Extension Financial Services HIGH 8.8
CVE-2019-0383

Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.…

Mitigation only
Fix from $1,950 2019-12-17
Enterprise Extension Financial Services HIGH 8.8
CVE-2019-0384

Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.…

Mitigation only
Fix from $1,950 2019-12-17
Photo Station CRITICAL 9.8
CVE-2019-7192 KEVEPSS 88%

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP reco…

Fix: 5.2.11 / 5.4.9+
Fix from $2,300 2019-12-05
Dap 1860 Firmware HIGH 8.8
CVE-2019-19597EPSS 21%

D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an …

No fix yet
Fix from $1,950 2019-12-05
OpenBSD HIGH 7.8
CVE-2019-19520

xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xeno…

No fix yet
Fix from $1,950 2019-12-05
Fedora HIGH 7.5
CVE-2013-4410

ReviewBoard: has an access-control problem in REST API

Fix: 1.6.19 / 1.7.15+
Fix from $1,950 2019-12-02
Cdh MEDIUM 6.5
CVE-2016-3131

Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.

Fix: 5.3.10 / 5.4.10+
Fix from $1,600 2019-11-26
Cdh HIGH 8.8
CVE-2016-4572

In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.

Mitigation only
Fix from $1,950 2019-11-26
Cdh MEDIUM 6.5
CVE-2016-6353

Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security…

Fix: 5.7.0+
Fix from $1,600 2019-11-26
Debian Linux MEDIUM 6.5
CVE-2011-3617

Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

Fix: after 1.8.2
Fix from $1,600 2019-11-26
Chrome MEDIUM 6.5
CVE-2019-5879

Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious …

Fix: 77.0.3865.75+
Fix from $1,600 2019-11-25
Ovirt Engine MEDIUM 6.5
CVE-2015-1780

oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center

Mitigation only
Fix from $1,600 2019-11-22
Script Security HIGH 8.8
CVE-2019-16538

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closure…

Fix: after 1.67
Fix from $1,950 2019-11-21
Trytond HIGH 7.5
CVE-2012-2238

trytond 2.4: ModelView.button fails to validate authorization

Fix: 2.4.2+
Fix from $1,950 2019-11-21
Drupal HIGH 7.5
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type i…

Fix: 7.5+
Fix from $1,950 2019-11-15
Snowhaze HIGH 7.5
CVE-2019-18949

SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a cha…

Fix: 2.6.6+
Fix from $1,950 2019-11-14
Debian Linux HIGH 7.8
CVE-2011-1070

v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mod…

Fix: 0.1.10+
Fix from $1,950 2019-11-14
Micollab MEDIUM 5.3
CVE-2018-18819

A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8…

Fix: after 8.0.2.202
Fix from $1,600 2019-11-12
Cxf CRITICAL 9.8
CVE-2019-12419EPSS 14%

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne…

Fix: 3.2.11 / 3.3.4+
Fix from $2,300 2019-11-06
Icedtea6 CRITICAL 9.1
CVE-2010-2548

IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

Fix: 1.7.4+
Fix from $2,300 2019-10-31
Notebook MEDIUM 5.3
CVE-2018-21030

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload ca…

Fix: 5.5.0+
Fix from $1,600 2019-10-31
Debian Linux HIGH 7.5
CVE-2009-3723

asterisk allows calls on prohibited networks

Fix: 1.6.1.8+
Fix from $1,950 2019-10-29