Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.3 CVE-2019-4311 IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount … Security Guardium Big Data Intelligence Patch available Fix from $1,6002019-10-29 MEDIUM 6.5 CVE-2019-6144 This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web prot… One Endpoint after 19.08 Fix from $1,6002019-10-23 CRITICAL 9.8 CVE-2019-15900 An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used withou… Doas 6.2+ Fix from $2,3002019-10-18 HIGH 7.5 CVE-2019-14832 A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent… Keycloak 7.0.1+ Fix from $1,9502019-10-15 HIGH 7.5 CVE-2019-17191 The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, v… Private Messenger 4.47.7+ Fix from $1,9502019-10-05 MEDIUM 5.5 CVE-2019-9272 In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to… Android Mitigation only Fix from $1,6002019-09-27 HIGH 7.8 CVE-2019-12671 A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execu… Ios Xe Mitigation only Fix from $1,9502019-09-25 CRITICAL 9.8 CVE-2019-15941 OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorizat… Debian Linux after 2.0.5 Fix from $2,3002019-09-25 HIGH 8.8 CVE-2019-12648 A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access t… iOS Mitigation only Fix from $1,9502019-09-25 HIGH 7.5 CVE-2019-16884 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux… Docker after 19.03.2 Fix from $1,9502019-09-25 MEDIUM 5.3 CVE-2016-10996 The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak. Optinmonster 1.1.4.6+ Fix from $1,6002019-09-20 HIGH 7.5 CVE-2019-6836 A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Pl… Meg6501 0001 Firmware 1.3.7+ Fix from $1,9502019-09-17 MEDIUM 6.5 CVE-2019-6838 A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Pl… Meg6501 0001 Firmware 1.3.7+ Fix from $1,6002019-09-17 HIGH 7.5 CVE-2019-15729 An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information ab… GitLab 12.0.8 / 12.1.8+ Fix from $1,9502019-09-17 CRITICAL 9.8 CVE-2019-14237 On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can… Kinetis Kv1x Firmware No fix yet Fix from $2,3002019-09-12 CRITICAL 9.8 CVE-2019-14236 On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP p… Stm32l0 Firmware No fix yet Fix from $2,3002019-09-12 MEDIUM 5.5 CVE-2019-1289 An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'W… Windows 10 Patch available Fix from $1,6002019-09-11 MEDIUM 5.3 CVE-2019-14995 The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name e… Jira Server 8.4.0+ Fix from $1,6002019-09-11 CRITICAL 9.8 CVE-2019-16114 In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain a… Atutor after 2.2.4 Fix from $2,3002019-09-09 CRITICAL 9.8 CVE-2019-14813EPSS 11% A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en… Openshift Container Platform Patch available Fix from $2,3002019-09-06 HIGH 7.8 CVE-2019-2175 In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could… Android Patch available Fix from $1,9502019-09-05 HIGH 7.8 CVE-2019-14811 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls… Openshift Container Platform 9.50+ Fix from $1,9502019-09-03 HIGH 7.8 CVE-2019-14817 A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged ca… Openshift Container Platform 9.50+ Fix from $1,9502019-09-03 HIGH 8.1 CVE-2019-11247 The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced.… Kubernetes 1.13.9 / 1.14.5+ Fix from $1,9502019-08-29 MEDIUM 5.3 CVE-2019-8445 Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time… Jira Server 7.13.7 / 8.3.2+ Fix from $1,6002019-08-23 MEDIUM 5.3 CVE-2019-8446EPSS 18% The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation c… Jira Server 8.3.2+ Fix from $1,6002019-08-23 MEDIUM 5.3 CVE-2019-13417 Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for… Search Guard 24.0+ Fix from $1,6002019-08-12 HIGH 7.5 CVE-2019-14924 An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but… Gcdwebserver 3.5.3+ Fix from $1,9502019-08-10 CRITICAL 9.1 CVE-2019-1912EPSS 17% A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to … Sf 220 24 Firmware 1.1.4.4+ Fix from $2,3002019-08-07 HIGH 8.8 CVE-2019-13386 In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell comman… Centos Web Panel No fix yet Fix from $1,9502019-07-26