Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.8 CVE-2018-12391 During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the pro… Firefox 60.3 / 63.0+ Fix from $1,9502019-02-28 HIGH 7.8 CVE-2019-0105 Insufficient file permissions checking in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow authenticated user to p… Data Center Manager 5.0.2+ Fix from $1,9502019-02-18 HIGH 8.1 CVE-2019-7639 An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsissh/sshd_config file, logins su… Fedora No fix yet Fix from $1,9502019-02-08 HIGH 7.2 CVE-2018-14666 An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered… Satellite after 6.4 Fix from $1,9502019-01-22 HIGH 7.8 CVE-2017-8276 Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MS… Mdm9206 Firmware Mitigation only Fix from $1,9502019-01-18 MEDIUM 6.5 CVE-2018-5741 To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-poli… Bind 9.11.5 / 9.12.3+ Fix from $1,6002019-01-16 MEDIUM 5.3 CVE-2018-20685 In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. … Debian Linux after 7.9 Fix from $1,6002019-01-10 HIGH 8.8 CVE-2018-1000412 An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read acce… Jira after 3.0.1 Fix from $1,9502019-01-09 HIGH 8.8 CVE-2018-1000418 An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall… Hipchat after 2.2.0 Fix from $1,9502019-01-09 MEDIUM 6.5 CVE-2018-1000420 An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read … Mesos after 0.17.1 Fix from $1,6002019-01-09 HIGH 8.8 CVE-2019-0552 An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2… Windows 10 Patch available Fix from $1,9502019-01-08 MEDIUM 6.8 CVE-2018-7366 ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 a… Zxv10 B860av2.1 Chinamobile Firmware Mitigation only Fix from $1,6002018-12-28 HIGH 8.1 CVE-2018-15465 A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (le… Adaptive Security Appliance Software 9.4.4.29 / 9.6.4.20+ Fix from $1,9502018-12-24 HIGH 7.5 CVE-2018-17195 The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack… Nifi after 1.7.1 Fix from $1,9502018-12-19 MEDIUM 6.5 CVE-2018-20147 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files. WordPress 4.9.9 / 5.0.1+ Fix from $1,6002018-12-14 HIGH 8.8 CVE-2018-15754 Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain acc… Cloud Foundry Uaa Release 66.0+ Fix from $1,9502018-12-13 HIGH 8.8 CVE-2018-15774 Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privile… Idrac7 Firmware 2.61.60.60 / 3.20.21.20+ Fix from $1,9502018-12-13 HIGH 7.5 CVE-2018-17950 Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 Edirectory after 9.1 Fix from $1,9502018-12-12 MEDIUM 5.5 CVE-2018-18397 The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowi… Linux Kernel 4.19.7+ Fix from $1,6002018-12-12 HIGH 8.0 CVE-2018-2494 Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeave… Business Application Software Integrated Solution after 7.53 Fix from $1,9502018-12-11 HIGH 7.2 CVE-2018-7079 Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorizatio… Clearpass Policy Manager 6.6.10 / 6.7.6+ Fix from $1,9502018-12-07 HIGH 8.8 CVE-2018-15767EPSS 12% The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfigur… Openmanage Network Manager 6.5.3+ Fix from $1,9502018-11-30 HIGH 7.5 CVE-2018-14748 Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and ea… Qts Mitigation only Fix from $1,9502018-11-28 HIGH 8.8 CVE-2018-13356 Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions. Terramaster Operating System No fix yet Fix from $1,9502018-11-27 CRITICAL 9.8 CVE-2018-13324EPSS 23% Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host… Ts5600d1206 Firmware No fix yet Fix from $2,3002018-11-26 HIGH 7.0 CVE-2018-18955EPSS 8% In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nes… Linux Kernel 4.19.2+ Fix from $1,9502018-11-16 MEDIUM 6.4 CVE-2018-15692 Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions. Inova Partner after 5.0.5 Fix from $1,6002018-11-16 MEDIUM 6.4 CVE-2018-15693 Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference. Inova Partner after 5.0.5 Fix from $1,6002018-11-16 HIGH 8.8 CVE-2018-7363 All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no author… Zxhn F670 Firmware 1.1.10p3t18+ Fix from $1,9502018-11-16 HIGH 7.5 CVE-2018-16620 Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control. Nexus Repository Manager 3.14.0+ Fix from $1,9502018-11-15