Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Cpp Ethereum HIGH 8.1
CVE-2017-12113

An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7…

No fix yet
Fix from $1,950 2018-01-19
Aleth HIGH 8.1
CVE-2017-12116

An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce8…

No fix yet
Fix from $1,950 2018-01-19
Cpp Ethereum HIGH 8.1
CVE-2017-12118

An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073…

No fix yet
Fix from $1,950 2018-01-19
Cpp Ethereum HIGH 8.1
CVE-2017-12112

An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c…

No fix yet
Fix from $1,950 2018-01-19
Cpp Ethereum MEDIUM 6.8
CVE-2017-12114

An exploitable improper authorization vulnerability exists in admin_peers API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c07…

No fix yet
Fix from $1,600 2018-01-19
Cpp Ethereum HIGH 8.1
CVE-2017-12115

An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce…

No fix yet
Fix from $1,950 2018-01-19
Cpp Ethereum HIGH 8.1
CVE-2017-12117

An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c07…

No fix yet
Fix from $1,950 2018-01-19
Debian Linux MEDIUM 6.5
CVE-2017-12197

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di…

Fix: after 1.8
Fix from $1,600 2018-01-18
Webex Meetings Server HIGH 8.1
CVE-2018-0110

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has b…

Mitigation only
Fix from $1,950 2018-01-18
Prime Infrastructure MEDIUM 5.9
CVE-2018-0096

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Mitigation only
Fix from $1,600 2018-01-18
Fl Switch 3005 Firmware CRITICAL 9.8
CVE-2017-16743

An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.3…

Fix: after 1.32
Fix from $2,300 2018-01-12
Solution Manager HIGH 8.8
CVE-2018-2361

In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required…

Mitigation only
Fix from $1,950 2018-01-09
Vrealize Operations For Horizon HIGH 7.8
CVE-2017-4946

The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could r…

Fix: 6.5.1+
Fix from $1,950 2018-01-05
Splunk CRITICAL 9.8
CVE-2017-17067

Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the…

Fix: 6.3.12 / 6.4.9+
Fix from $2,300 2017-11-30
Business Process Manager MEDIUM 6.5
CVE-2017-1628

IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorizati…

Mitigation only
Fix from $1,600 2017-11-27
Zulip Server HIGH 8.8
CVE-2017-0910

In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the …

Fix: 1.7.1+
Fix from $1,950 2017-11-27
P10 Lite Firmware MEDIUM 5.5
CVE-2017-8216

Warsaw Huawei Smart phones with software of versions earlier than Warsaw-AL00C00B180, versions earlier than Warsaw-TL10C01B180 have a permission cont…

Mitigation only
Fix from $1,600 2017-11-22
Fusionsphere Openstack HIGH 7.8
CVE-2017-8192

FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability. Due to improper authorization, an attacker with low privilege may exp…

Mitigation only
Fix from $1,950 2017-11-22
Qnx Software Development Platform CRITICAL 9.6
CVE-2017-3891

In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with…

Mitigation only
Fix from $2,300 2017-11-14
Identity Services Engine HIGH 7.8
CVE-2017-12261

A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local at…

Mitigation only
Fix from $1,950 2017-11-02
Chrome MEDIUM 6.5
CVE-2017-5060

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed …

Fix: 58.0.3029.81 / 58.0.3029.83+
Fix from $1,600 2017-10-27
MySQL MEDIUM 6.5
CVE-2017-10379

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earl…

Fix: 5.5.57 / 10.0.32+
Fix from $1,600 2017-10-19
Pi Integrator For Business Analystics CRITICAL 9.8
CVE-2017-9653

An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure befo…

Mitigation only
Fix from $2,300 2017-08-14
Tomcat HIGH 7.5
CVE-2016-6797EPSS 8%

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.4…

Fix: after 8.5.4
Fix from $1,950 2017-08-10
Windows 10 HIGH 7.5
CVE-2017-8633

Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Win…

Patch available
Fix from $1,950 2017-08-08
Sunny Boy 3600 Firmware CRITICAL 9.8
CVE-2017-9855

An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system.…

Mitigation only
Fix from $2,300 2017-08-05
Asr 5000 Series Software HIGH 7.5
CVE-2017-6672

A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x co…

Mitigation only
Fix from $1,950 2017-07-25
3scale Api Management Platform CRITICAL 9.8
CVE-2017-7512

Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attack…

Mitigation only
Fix from $2,300 2017-07-07
Odoo HIGH 8.8
CVE-2017-10805

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth mod…

Patch available
Fix from $1,950 2017-07-04
Bamboo HIGH 8.8
CVE-2017-8907

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and t…

Mitigation only
Fix from $1,950 2017-06-14