Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2018-20494 An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A… GitLab 11.4.13 / 11.5.6+ Fix from $1,9502019-12-30 MEDIUM 6.5 CVE-2019-4343 IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker to transfer private informati… Cognos Analytics Mitigation only Fix from $1,6002019-12-30 HIGH 7.5 CVE-2013-4985EPSS 9% Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream Ip7160 Firmware No fix yet Fix from $1,9502019-12-27 MEDIUM 5.3 CVE-2018-20492 An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect A… GitLab 11.4.13 / 11.5.6+ Fix from $1,6002019-12-26 HIGH 8.8 CVE-2019-19681 Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to defin… Pandora Fms Mitigation only Fix from $1,9502019-12-26 MEDIUM 6.3 CVE-2019-19984 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settin… Email Subscribers \& Newsletters 4.2.3+ Fix from $1,6002019-12-26 CRITICAL 9.8 CVE-2012-6094 cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system Debian Linux 1.5.4-1.1+ Fix from $2,3002019-12-20 MEDIUM 5.7 CVE-2019-8512 This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wi… Iphone Os 12.2+ Fix from $1,6002019-12-18 HIGH 8.8 CVE-2019-0383 Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.… Enterprise Extension Financial Services Mitigation only Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-0384 Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.… Enterprise Extension Financial Services Mitigation only Fix from $1,9502019-12-17 CRITICAL 9.8 CVE-2019-7192 KEVEPSS 88% This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP reco… Photo Station 5.2.11 / 5.4.9+ Fix from $2,3002019-12-05 HIGH 8.8 CVE-2019-19597EPSS 21% D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an … Dap 1860 Firmware No fix yet Fix from $1,9502019-12-05 HIGH 7.8 CVE-2019-19520 xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xeno… OpenBSD No fix yet Fix from $1,9502019-12-05 HIGH 7.5 CVE-2013-4410 ReviewBoard: has an access-control problem in REST API Fedora 1.6.19 / 1.7.15+ Fix from $1,9502019-12-02 MEDIUM 6.5 CVE-2016-3131 Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls. Cdh 5.3.10 / 5.4.10+ Fix from $1,6002019-11-26 HIGH 8.8 CVE-2016-4572 In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges. Cdh Mitigation only Fix from $1,9502019-11-26 MEDIUM 6.5 CVE-2016-6353 Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security… Cdh 5.7.0+ Fix from $1,6002019-11-26 MEDIUM 6.5 CVE-2011-3617 Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases. Debian Linux after 1.8.2 Fix from $1,6002019-11-26 MEDIUM 6.5 CVE-2019-5879 Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious … Chrome 77.0.3865.75+ Fix from $1,6002019-11-25 MEDIUM 6.5 CVE-2015-1780 oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center Ovirt Engine Mitigation only Fix from $1,6002019-11-22 HIGH 8.8 CVE-2019-16538 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closure… Script Security after 1.67 Fix from $1,9502019-11-21 HIGH 7.5 CVE-2012-2238 trytond 2.4: ModelView.button fails to validate authorization Trytond 2.4.2+ Fix from $1,9502019-11-21 HIGH 7.5 CVE-2011-2726 An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type i… Drupal 7.5+ Fix from $1,9502019-11-15 HIGH 7.5 CVE-2019-18949 SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a cha… Snowhaze 2.6.6+ Fix from $1,9502019-11-14 HIGH 7.8 CVE-2011-1070 v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mod… Debian Linux 0.1.10+ Fix from $1,9502019-11-14 MEDIUM 5.3 CVE-2018-18819 A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8… Micollab after 8.0.2.202 Fix from $1,6002019-11-12 CRITICAL 9.8 CVE-2019-12419EPSS 14% Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne… Cxf 3.2.11 / 3.3.4+ Fix from $2,3002019-11-06 CRITICAL 9.1 CVE-2010-2548 IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. Icedtea6 1.7.4+ Fix from $2,3002019-10-31 MEDIUM 5.3 CVE-2018-21030 Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload ca… Notebook 5.5.0+ Fix from $1,6002019-10-31 HIGH 7.5 CVE-2009-3723 asterisk allows calls on prohibited networks Debian Linux 1.6.1.8+ Fix from $1,9502019-10-29