Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Firefox HIGH 8.8
CVE-2018-12391

During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the pro…

Fix: 60.3 / 63.0+
Fix from $1,950 2019-02-28
Data Center Manager HIGH 7.8
CVE-2019-0105

Insufficient file permissions checking in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow authenticated user to p…

Fix: 5.0.2+
Fix from $1,950 2019-02-18
Fedora HIGH 8.1
CVE-2019-7639

An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsissh/sshd_config file, logins su…

No fix yet
Fix from $1,950 2019-02-08
Satellite HIGH 7.2
CVE-2018-14666

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered…

Fix: after 6.4
Fix from $1,950 2019-01-22
Mdm9206 Firmware HIGH 7.8
CVE-2017-8276

Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MS…

Mitigation only
Fix from $1,950 2019-01-18
Bind MEDIUM 6.5
CVE-2018-5741

To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-poli…

Fix: 9.11.5 / 9.12.3+
Fix from $1,600 2019-01-16
Debian Linux MEDIUM 5.3
CVE-2018-20685

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. …

Fix: after 7.9
Fix from $1,600 2019-01-10
Jira HIGH 8.8
CVE-2018-1000412

An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read acce…

Fix: after 3.0.1
Fix from $1,950 2019-01-09
Hipchat HIGH 8.8
CVE-2018-1000418

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall…

Fix: after 2.2.0
Fix from $1,950 2019-01-09
Mesos MEDIUM 6.5
CVE-2018-1000420

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read …

Fix: after 0.17.1
Fix from $1,600 2019-01-09
Windows 10 HIGH 8.8
CVE-2019-0552

An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2…

Patch available
Fix from $1,950 2019-01-08
Zxv10 B860av2.1 Chinamobile Firmware MEDIUM 6.8
CVE-2018-7366

ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 a…

Mitigation only
Fix from $1,600 2018-12-28
Adaptive Security Appliance Software HIGH 8.1
CVE-2018-15465

A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (le…

Fix: 9.4.4.29 / 9.6.4.20+
Fix from $1,950 2018-12-24
Nifi HIGH 7.5
CVE-2018-17195

The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack…

Fix: after 1.7.1
Fix from $1,950 2018-12-19
WordPress MEDIUM 6.5
CVE-2018-20147

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.

Fix: 4.9.9 / 5.0.1+
Fix from $1,600 2018-12-14
Cloud Foundry Uaa Release HIGH 8.8
CVE-2018-15754

Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain acc…

Fix: 66.0+
Fix from $1,950 2018-12-13
Idrac7 Firmware HIGH 8.8
CVE-2018-15774

Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privile…

Fix: 2.61.60.60 / 3.20.21.20+
Fix from $1,950 2018-12-13
Edirectory HIGH 7.5
CVE-2018-17950

Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2

Fix: after 9.1
Fix from $1,950 2018-12-12
Linux Kernel MEDIUM 5.5
CVE-2018-18397

The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowi…

Fix: 4.19.7+
Fix from $1,600 2018-12-12
Business Application Software Integrated Solution HIGH 8.0
CVE-2018-2494

Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeave…

Fix: after 7.53
Fix from $1,950 2018-12-11
Clearpass Policy Manager HIGH 7.2
CVE-2018-7079

Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorizatio…

Fix: 6.6.10 / 6.7.6+
Fix from $1,950 2018-12-07
Openmanage Network Manager HIGH 8.8
CVE-2018-15767EPSS 12%

The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfigur…

Fix: 6.5.3+
Fix from $1,950 2018-11-30
Qts HIGH 7.5
CVE-2018-14748

Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and ea…

Mitigation only
Fix from $1,950 2018-11-28
Terramaster Operating System HIGH 8.8
CVE-2018-13356

Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions.

No fix yet
Fix from $1,950 2018-11-27
Ts5600d1206 Firmware CRITICAL 9.8
CVE-2018-13324EPSS 23%

Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host…

No fix yet
Fix from $2,300 2018-11-26
Linux Kernel HIGH 7.0
CVE-2018-18955EPSS 8%

In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nes…

Fix: 4.19.2+
Fix from $1,950 2018-11-16
Inova Partner MEDIUM 6.4
CVE-2018-15692

Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions.

Fix: after 5.0.5
Fix from $1,600 2018-11-16
Inova Partner MEDIUM 6.4
CVE-2018-15693

Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference.

Fix: after 5.0.5
Fix from $1,600 2018-11-16
Zxhn F670 Firmware HIGH 8.8
CVE-2018-7363

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no author…

Fix: 1.1.10p3t18+
Fix from $1,950 2018-11-16
Nexus Repository Manager HIGH 7.5
CVE-2018-16620

Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.

Fix: 3.14.0+
Fix from $1,950 2018-11-15