Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Security Guardium Big Data Intelligence MEDIUM 5.3
CVE-2019-4311

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount …

Patch available
Fix from $1,600 2019-10-29
One Endpoint MEDIUM 6.5
CVE-2019-6144

This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web prot…

Fix: after 19.08
Fix from $1,600 2019-10-23
Doas CRITICAL 9.8
CVE-2019-15900

An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used withou…

Fix: 6.2+
Fix from $2,300 2019-10-18
Keycloak HIGH 7.5
CVE-2019-14832

A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent…

Fix: 7.0.1+
Fix from $1,950 2019-10-15
Private Messenger HIGH 7.5
CVE-2019-17191

The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, v…

Fix: 4.47.7+
Fix from $1,950 2019-10-05
Android MEDIUM 5.5
CVE-2019-9272

In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to…

Mitigation only
Fix from $1,600 2019-09-27
Ios Xe HIGH 7.8
CVE-2019-12671

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execu…

Mitigation only
Fix from $1,950 2019-09-25
Debian Linux CRITICAL 9.8
CVE-2019-15941

OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorizat…

Fix: after 2.0.5
Fix from $2,300 2019-09-25
iOS HIGH 8.8
CVE-2019-12648

A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access t…

Mitigation only
Fix from $1,950 2019-09-25
Docker HIGH 7.5
CVE-2019-16884

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux…

Fix: after 19.03.2
Fix from $1,950 2019-09-25
Optinmonster MEDIUM 5.3
CVE-2016-10996

The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak.

Fix: 1.1.4.6+
Fix from $1,600 2019-09-20
Meg6501 0001 Firmware HIGH 7.5
CVE-2019-6836

A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Pl…

Fix: 1.3.7+
Fix from $1,950 2019-09-17
Meg6501 0001 Firmware MEDIUM 6.5
CVE-2019-6838

A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Pl…

Fix: 1.3.7+
Fix from $1,600 2019-09-17
GitLab HIGH 7.5
CVE-2019-15729

An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information ab…

Fix: 12.0.8 / 12.1.8+
Fix from $1,950 2019-09-17
Kinetis Kv1x Firmware CRITICAL 9.8
CVE-2019-14237

On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can…

No fix yet
Fix from $2,300 2019-09-12
Stm32l0 Firmware CRITICAL 9.8
CVE-2019-14236

On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP p…

No fix yet
Fix from $2,300 2019-09-12
Windows 10 MEDIUM 5.5
CVE-2019-1289

An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'W…

Patch available
Fix from $1,600 2019-09-11
Jira Server MEDIUM 5.3
CVE-2019-14995

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name e…

Fix: 8.4.0+
Fix from $1,600 2019-09-11
Atutor CRITICAL 9.8
CVE-2019-16114

In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain a…

Fix: after 2.2.4
Fix from $2,300 2019-09-09
Openshift Container Platform CRITICAL 9.8
CVE-2019-14813EPSS 11%

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en…

Patch available
Fix from $2,300 2019-09-06
Android HIGH 7.8
CVE-2019-2175

In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could…

Patch available
Fix from $1,950 2019-09-05
Openshift Container Platform HIGH 7.8
CVE-2019-14811

A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls…

Fix: 9.50+
Fix from $1,950 2019-09-03
Openshift Container Platform HIGH 7.8
CVE-2019-14817

A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged ca…

Fix: 9.50+
Fix from $1,950 2019-09-03
Kubernetes HIGH 8.1
CVE-2019-11247

The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced.…

Fix: 1.13.9 / 1.14.5+
Fix from $1,950 2019-08-29
Jira Server MEDIUM 5.3
CVE-2019-8445

Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time…

Fix: 7.13.7 / 8.3.2+
Fix from $1,600 2019-08-23
Jira Server MEDIUM 5.3
CVE-2019-8446EPSS 18%

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation c…

Fix: 8.3.2+
Fix from $1,600 2019-08-23
Search Guard MEDIUM 5.3
CVE-2019-13417

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for…

Fix: 24.0+
Fix from $1,600 2019-08-12
Gcdwebserver HIGH 7.5
CVE-2019-14924

An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but…

Fix: 3.5.3+
Fix from $1,950 2019-08-10
Sf 220 24 Firmware CRITICAL 9.1
CVE-2019-1912EPSS 17%

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to …

Fix: 1.1.4.4+
Fix from $2,300 2019-08-07
Centos Web Panel HIGH 8.8
CVE-2019-13386

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell comman…

No fix yet
Fix from $1,950 2019-07-26