Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Vrealize Log Insight HIGH 7.2
CVE-2018-6980

VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registrati…

Fix: 4.6.2 / 4.7.1+
Fix from $1,950 2018-11-13
Emily Al00a Firmware MEDIUM 6.8
CVE-2018-7925

The radio module of some Huawei smartphones Emily-AL00A The versions before 8.1.0.171(C00) have a lock-screen bypass vulnerability. An unauthenticate…

Fix: 8.1.0.171+
Fix from $1,600 2018-11-13
Android HIGH 7.8
CVE-2018-9488

In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of pri…

Patch available
Fix from $1,950 2018-11-06
Enterprise Linux Desktop MEDIUM 6.6
CVE-2018-14665EPSS 27%

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server al…

Patch available
Fix from $1,600 2018-10-25
Firefox CRITICAL 9.8
CVE-2018-12369

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain fu…

Fix: 60.1.0 / 61.0+
Fix from $2,300 2018-10-18
Ansible Tower HIGH 8.8
CVE-2018-1000805

Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in…

Patch available
Fix from $1,950 2018-10-08
Ucs Director MEDIUM 6.5
CVE-2018-15405

A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director coul…

Mitigation only
Fix from $1,600 2018-10-05
Network Functions Virtualization Infrastructure MEDIUM 6.5
CVE-2018-0460

A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any fil…

Mitigation only
Fix from $1,600 2018-10-05
Network Functions Virtualization Infrastructure MEDIUM 6.5
CVE-2018-0459

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote at…

Mitigation only
Fix from $1,600 2018-10-05
Android HIGH 7.8
CVE-2018-9492

In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privi…

Patch available
Fix from $1,950 2018-10-02
Emc Unity Firmware MEDIUM 6.5
CVE-2018-1250

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could pote…

Fix: 4.3.1.1525703027+
Fix from $1,600 2018-09-28
Linux Kernel MEDIUM 5.5
CVE-2018-16597

An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or t…

Fix: 4.8+
Fix from $1,600 2018-09-21
Mate Rs Firmware MEDIUM 6.8
CVE-2018-7929

Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability. An attacker could unlock and u…

Mitigation only
Fix from $1,600 2018-09-18
Jenkins MEDIUM 6.5
CVE-2018-1999047

A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel …

Fix: after 2.137
Fix from $1,600 2018-08-23
Xen MEDIUM 6.0
CVE-2018-15468

An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do no…

Fix: after 4.11.0
Fix from $1,600 2018-08-17
Ubuntu Linux HIGH 8.1
CVE-2018-10925

It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statemen…

Fix: 9.5.14 / 9.6.10+
Fix from $1,950 2018-08-09
Aedes MEDIUM 5.3
CVE-2018-3778

Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.

Fix: 0.35.0+
Fix from $1,600 2018-08-08
7 Mode Transition Tool MEDIUM 6.5
CVE-2018-5489

NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have been intended to be restricted t…

Fix: 2.0+
Fix from $1,600 2018-08-03
Spacewalk CRITICAL 9.8
CVE-2017-7470

It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…

Mitigation only
Fix from $2,300 2018-07-27
Cloud Foundry Uaa HIGH 7.5
CVE-2018-11047

Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, inc…

Fix: 4.5.7 / 4.7.6+
Fix from $1,950 2018-07-24
Xrt Treasury HIGH 8.8
CVE-2017-3183

Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full ac…

Mitigation only
Fix from $1,950 2018-07-24
Openstack HIGH 7.2
CVE-2017-2673

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user…

Patch available
Fix from $1,950 2018-07-19
Rsa Identity Governance And Lifecycle HIGH 8.8
CVE-2018-1245

RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect co…

Mitigation only
Fix from $1,950 2018-07-13
Dv2210 Firmware HIGH 7.5
CVE-2018-13109EPSS 36%

All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able t…

No fix yet
Fix from $1,950 2018-07-06
Dir 890l Firmware MEDIUM 6.5
CVE-2018-12103

An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/…

Fix: after 1.21b04beta01
Fix from $1,600 2018-07-05
Universal Search HIGH 8.8
CVE-2017-16773

Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass …

Fix: 1.0.5-0135+
Fix from $1,950 2018-07-05
Nx Os HIGH 7.8
CVE-2018-0337

A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrar…

Mitigation only
Fix from $1,950 2018-06-21
Calendar MEDIUM 6.5
CVE-2018-8927

Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via…

Fix: 2.1.2-0511+
Fix from $1,600 2018-06-14
Geode HIGH 8.8
CVE-2017-15695

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy cod…

Fix: after 1.4.0
Fix from $1,950 2018-06-13
Unified Computing System HIGH 7.8
CVE-2018-0338

A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local att…

Mitigation only
Fix from $1,950 2018-06-07