Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Black Duck Hub HIGH 8.1
CVE-2018-1000197

An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users wit…

Fix: after 3.0.3
Fix from $1,950 2018-06-05
Kace System Management Appliance MEDIUM 5.5
CVE-2018-11142

The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible…

No fix yet
Fix from $1,600 2018-05-31
Openflow CRITICAL 9.8
CVE-2018-1000155

OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifi…

Mitigation only
Fix from $2,300 2018-05-24
Storwize V7000 Firmware HIGH 7.6
CVE-2018-1462

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Storwize V7000 Firmware MEDIUM 6.5
CVE-2018-1463

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Spring Framework HIGH 8.8
CVE-2018-1258

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method secur…

Fix: 7.0.0.1 / 8.3+
Fix from $1,950 2018-05-11
Pivotal Application Service MEDIUM 6.5
CVE-2018-1278

Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an a…

Fix: 1.12.22 / 2.0.13+
Fix from $1,600 2018-05-11
Secure Firewall Management Center MEDIUM 6.5
CVE-2018-0278

A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data…

Mitigation only
Fix from $1,600 2018-05-02
Enterprise File Sharing MEDIUM 5.4
CVE-2018-10212

An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another a…

Mitigation only
Fix from $1,600 2018-04-25
Rational Collaborative Lifecycle Management MEDIUM 6.5
CVE-2017-1700

IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), …

Fix: after 6.0.5
Fix from $1,600 2018-04-24
66074 Mge Network Management Card Transverse CRITICAL 9.1
CVE-2018-7245

An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS.…

Mitigation only
Fix from $2,300 2018-04-18
Undertow MEDIUM 5.9
CVE-2017-12196

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that…

Fix: after 1.4.18
Fix from $1,600 2018-04-18
Jenkins MEDIUM 5.4
CVE-2017-2599

Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.…

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-04-11
Vsphere MEDIUM 6.3
CVE-2018-1000152

An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate…

Fix: after 2.16
Fix from $1,600 2018-04-05
GitLab HIGH 7.5
CVE-2017-0922

Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in…

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab HIGH 8.8
CVE-2017-0926

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user …

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab MEDIUM 6.5
CVE-2017-0927

Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use…

Fix: after 10.3.3
Fix from $1,600 2018-03-21
S1 Dispenser Controller Firmware HIGH 7.5
CVE-2017-17668

Memory write mechanism in NCR S1 Dispenser controller before firmware version 0x0156 allows an unauthenticated user to upgrade or downgrade the firmw…

Fix: 0x0156+
Fix from $1,950 2018-03-20
Ubuntu Linux HIGH 8.8
CVE-2018-1057EPSS 10%

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowi…

Fix: 4.5.16 / 4.6.14+
Fix from $1,950 2018-03-13
Freeipa MEDIUM 6.3
CVE-2016-9575

Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in I…

Mitigation only
Fix from $1,600 2018-03-13
Gerrit Trigger MEDIUM 5.4
CVE-2018-1000106

An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and P…

Fix: after 2.27.4
Fix from $1,600 2018-03-13
Job And Node Ownership MEDIUM 6.5
CVE-2018-1000107

An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobP…

Fix: after 0.11.0
Fix from $1,600 2018-03-13
Git MEDIUM 5.3
CVE-2018-1000110

An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network…

Fix: after 3.7.0
Fix from $1,600 2018-03-13
Subversion MEDIUM 5.3
CVE-2018-1000111

An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionReposit…

Fix: after 2.10.2
Fix from $1,600 2018-03-13
Mercurial MEDIUM 5.3
CVE-2018-1000112

An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker wi…

Fix: after 2.2
Fix from $1,600 2018-03-13
Crucible MEDIUM 5.3
CVE-2017-18095

The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comm…

Fix: 4.5.1+
Fix from $1,600 2018-02-19
Endpoint Security HIGH 7.5
CVE-2018-6316

Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privil…

Fix: after 8.5
Fix from $1,950 2018-02-15
Bigfix Remote Control MEDIUM 6.7
CVE-2017-1233

IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to…

Patch available
Fix from $1,600 2018-01-31
Crowd MEDIUM 6.8
CVE-2017-16858

The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an …

Fix: 3.1.2+
Fix from $1,600 2018-01-31
Authoritative HIGH 7.1
CVE-2017-15091

An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some o…

Fix: after 4.0.4
Fix from $1,950 2018-01-23