Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.1 CVE-2019-11724 Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to … Firefox 68.0+ Fix from $1,6002019-07-23 MEDIUM 6.5 CVE-2019-1010084 Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unathorised access to data. The co… \ after 1.14 Fix from $1,6002019-07-17 MEDIUM 6.5 CVE-2019-9149 Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an … Mailvelope 3.3.0+ Fix from $1,6002019-07-09 HIGH 7.5 CVE-2019-13337 In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used b… Growi 3.5.0+ Fix from $1,9502019-07-09 HIGH 8.8 CVE-2019-5602 In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-REL… FreeBSD No fix yet Fix from $1,9502019-07-03 HIGH 8.8 CVE-2019-7258EPSS 20% Linear eMerge E3-Series devices allow Privilege Escalation. Linear Emerge Essential Firmware after 1.00-06 Fix from $1,9502019-07-02 HIGH 7.1 CVE-2019-10964 Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor tr… Minimed 508 Firmware Mitigation only Fix from $1,9502019-06-28 HIGH 8.8 CVE-2019-1626 A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated priv… Sd Wan Firmware after 18.3.6 Fix from $1,9502019-06-20 HIGH 7.1 CVE-2019-6582 A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance … Siveillance Video Management Software 2017 R2 11.2a / 12.1a+ Fix from $1,9502019-06-12 MEDIUM 6.5 CVE-2019-12492 Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure… Command Centre 7.80.939 / 7.90.961+ Fix from $1,6002019-06-06 HIGH 7.5 CVE-2018-13382 KEVEPSS 82% An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, … Fortiproxy 1.2.9 / 5.4.11+ Fix from $1,9502019-06-04 MEDIUM 5.3 CVE-2019-3401EPSS 13% The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate userna… Jira 7.13.3 / 8.1.1+ Fix from $1,6002019-05-22 MEDIUM 5.3 CVE-2019-3403EPSS 53% The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before versi… Jira 7.13.3 / 8.0.4+ Fix from $1,6002019-05-22 HIGH 7.5 CVE-2019-3399 The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see informatio… Jira 7.13.2 / 8.0.2+ Fix from $1,9502019-04-30 CRITICAL 9.8 CVE-2019-7304EPSS 61% Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This iss… Snapd 2.37.1+ Fix from $2,3002019-04-23 HIGH 8.8 CVE-2019-6570 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attac… Sinema Remote Connect Server 2.0+ Fix from $1,9502019-04-17 HIGH 7.0 CVE-2019-3842 In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p… Enterprise Linux after 241 Fix from $1,9502019-04-09 HIGH 7.8 CVE-2019-0732 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls … Windows 10 Patch available Fix from $1,9502019-04-09 HIGH 8.8 CVE-2018-15640EPSS 8% Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges … Odoo after 12.0 Fix from $1,9502019-04-09 MEDIUM 5.6 CVE-2019-3887 A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1… Linux Kernel Patch available Fix from $1,6002019-04-09 MEDIUM 6.8 CVE-2019-0678EPSS 6% An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to … Edge Patch available Fix from $1,6002019-04-09 HIGH 7.0 CVE-2019-3827 An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileg… Gvfs 1.39.4+ Fix from $1,9502019-03-25 MEDIUM 6.7 CVE-2019-3831 A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system us… Gluster Storage after 4.30.8 Fix from $1,6002019-03-25 MEDIUM 6.5 CVE-2019-10014 In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, … Dedecms No fix yet Fix from $1,6002019-03-24 CRITICAL 9.8 CVE-2018-19515 In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, a… Webgalamb after 7.0 Fix from $2,3002019-03-21 HIGH 8.8 CVE-2019-0276 Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorizatio… Banking Services From Sap Mitigation only Fix from $1,9502019-03-12 HIGH 7.8 CVE-2019-1603 A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrat… Nx Os 7.0+ Fix from $1,9502019-03-08 HIGH 7.8 CVE-2019-1604 A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privil… Nx Os 6.2 / 7.0+ Fix from $1,9502019-03-08 CRITICAL 9.8 CVE-2018-18815 The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server … Jasperreports Server after 7.1.0 Fix from $2,3002019-03-07 HIGH 7.8 CVE-2018-8790 Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as S… Zonealarm after 15.3.064.17729 Fix from $1,9502019-03-01