Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Firefox MEDIUM 6.1
CVE-2019-11724

Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to …

Fix: 68.0+
Fix from $1,600 2019-07-23
\ MEDIUM 6.5
CVE-2019-1010084

Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unathorised access to data. The co…

Fix: after 1.14
Fix from $1,600 2019-07-17
Mailvelope MEDIUM 6.5
CVE-2019-9149

Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an …

Fix: 3.3.0+
Fix from $1,600 2019-07-09
Growi HIGH 7.5
CVE-2019-13337

In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used b…

Fix: 3.5.0+
Fix from $1,950 2019-07-09
FreeBSD HIGH 8.8
CVE-2019-5602

In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-REL…

No fix yet
Fix from $1,950 2019-07-03
Linear Emerge Essential Firmware HIGH 8.8
CVE-2019-7258EPSS 20%

Linear eMerge E3-Series devices allow Privilege Escalation.

Fix: after 1.00-06
Fix from $1,950 2019-07-02
Minimed 508 Firmware HIGH 7.1
CVE-2019-10964

Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor tr…

Mitigation only
Fix from $1,950 2019-06-28
Sd Wan Firmware HIGH 8.8
CVE-2019-1626

A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated priv…

Fix: after 18.3.6
Fix from $1,950 2019-06-20
Siveillance Video Management Software 2017 R2 HIGH 7.1
CVE-2019-6582

A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance …

Fix: 11.2a / 12.1a+
Fix from $1,950 2019-06-12
Command Centre MEDIUM 6.5
CVE-2019-12492

Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure…

Fix: 7.80.939 / 7.90.961+
Fix from $1,600 2019-06-06
Fortiproxy HIGH 7.5
CVE-2018-13382 KEVEPSS 82%

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, …

Fix: 1.2.9 / 5.4.11+
Fix from $1,950 2019-06-04
Jira MEDIUM 5.3
CVE-2019-3401EPSS 13%

The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate userna…

Fix: 7.13.3 / 8.1.1+
Fix from $1,600 2019-05-22
Jira MEDIUM 5.3
CVE-2019-3403EPSS 53%

The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before versi…

Fix: 7.13.3 / 8.0.4+
Fix from $1,600 2019-05-22
Jira HIGH 7.5
CVE-2019-3399

The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see informatio…

Fix: 7.13.2 / 8.0.2+
Fix from $1,950 2019-04-30
Snapd CRITICAL 9.8
CVE-2019-7304EPSS 61%

Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This iss…

Fix: 2.37.1+
Fix from $2,300 2019-04-23
Sinema Remote Connect Server HIGH 8.8
CVE-2019-6570

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attac…

Fix: 2.0+
Fix from $1,950 2019-04-17
Enterprise Linux HIGH 7.0
CVE-2019-3842

In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p…

Fix: after 241
Fix from $1,950 2019-04-09
Windows 10 HIGH 7.8
CVE-2019-0732

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls …

Patch available
Fix from $1,950 2019-04-09
Odoo HIGH 8.8
CVE-2018-15640EPSS 8%

Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges …

Fix: after 12.0
Fix from $1,950 2019-04-09
Linux Kernel MEDIUM 5.6
CVE-2019-3887

A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1…

Patch available
Fix from $1,600 2019-04-09
Edge MEDIUM 6.8
CVE-2019-0678EPSS 6%

An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to …

Patch available
Fix from $1,600 2019-04-09
Gvfs HIGH 7.0
CVE-2019-3827

An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileg…

Fix: 1.39.4+
Fix from $1,950 2019-03-25
Gluster Storage MEDIUM 6.7
CVE-2019-3831

A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system us…

Fix: after 4.30.8
Fix from $1,600 2019-03-25
Dedecms MEDIUM 6.5
CVE-2019-10014

In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, …

No fix yet
Fix from $1,600 2019-03-24
Webgalamb CRITICAL 9.8
CVE-2018-19515

In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, a…

Fix: after 7.0
Fix from $2,300 2019-03-21
Banking Services From Sap HIGH 8.8
CVE-2019-0276

Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorizatio…

Mitigation only
Fix from $1,950 2019-03-12
Nx Os HIGH 7.8
CVE-2019-1603

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrat…

Fix: 7.0+
Fix from $1,950 2019-03-08
Nx Os HIGH 7.8
CVE-2019-1604

A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privil…

Fix: 6.2 / 7.0+
Fix from $1,950 2019-03-08
Jasperreports Server CRITICAL 9.8
CVE-2018-18815

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server …

Fix: after 7.1.0
Fix from $2,300 2019-03-07
Zonealarm HIGH 7.8
CVE-2018-8790

Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as S…

Fix: after 15.3.064.17729
Fix from $1,950 2019-03-01