Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-12391
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the pro…
Firefox
60.3 / 63.0+
HIGH 7.8
CVE-2019-0105
Insufficient file permissions checking in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow authenticated user to p…
Data Center Manager
5.0.2+
HIGH 8.1
CVE-2019-7639
An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsissh/sshd_config file, logins su…
Fedora
No fix yet
HIGH 7.2
CVE-2018-14666
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered…
Satellite
after 6.4
HIGH 7.8
CVE-2017-8276
Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MS…
Mdm9206 Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-5741
To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-poli…
Bind
9.11.5 / 9.12.3+
MEDIUM 5.3
CVE-2018-20685
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. …
Debian Linux
after 7.9
HIGH 8.8
CVE-2018-1000412
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read acce…
Jira
after 3.0.1
HIGH 8.8
CVE-2018-1000418
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall…
Hipchat
after 2.2.0
MEDIUM 6.5
CVE-2018-1000420
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read …
Mesos
after 0.17.1
HIGH 8.8
CVE-2019-0552
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2…
Windows 10
Patch available
MEDIUM 6.8
CVE-2018-7366
ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 a…
Zxv10 B860av2.1 Chinamobile Firmware
Mitigation only
HIGH 8.1
CVE-2018-15465
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (le…
Adaptive Security Appliance Software
9.4.4.29 / 9.6.4.20+
HIGH 7.5
CVE-2018-17195
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack…
Nifi
after 1.7.1
MEDIUM 6.5
CVE-2018-20147
In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.
WordPress
4.9.9 / 5.0.1+
HIGH 8.8
CVE-2018-15754
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain acc…
Cloud Foundry Uaa Release
66.0+
HIGH 8.8
CVE-2018-15774
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privile…
Idrac7 Firmware
2.61.60.60 / 3.20.21.20+
HIGH 7.5
CVE-2018-17950
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
Edirectory
after 9.1
MEDIUM 5.5
CVE-2018-18397
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowi…
Linux Kernel
4.19.7+
HIGH 8.0
CVE-2018-2494
Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeave…
Business Application Software Integrated Solution
after 7.53
HIGH 7.2
CVE-2018-7079
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorizatio…
Clearpass Policy Manager
6.6.10 / 6.7.6+
HIGH 8.8
CVE-2018-15767EPSS 12%
The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfigur…
Openmanage Network Manager
6.5.3+
HIGH 7.5
CVE-2018-14748
Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and ea…
Qts
Mitigation only
HIGH 8.8
CVE-2018-13356
Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions.
Terramaster Operating System
No fix yet
CRITICAL 9.8
CVE-2018-13324EPSS 23%
Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host…
Ts5600d1206 Firmware
No fix yet
HIGH 7.0
CVE-2018-18955EPSS 8%
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nes…
Linux Kernel
4.19.2+
MEDIUM 6.4
CVE-2018-15692
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions.
Inova Partner
after 5.0.5
MEDIUM 6.4
CVE-2018-15693
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference.
Inova Partner
after 5.0.5
HIGH 8.8
CVE-2018-7363
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no author…
Zxhn F670 Firmware
1.1.10p3t18+
HIGH 7.5
CVE-2018-16620
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
Nexus Repository Manager
3.14.0+