Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2018-6980
VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registrati…
Vrealize Log Insight
4.6.2 / 4.7.1+
MEDIUM 6.8
CVE-2018-7925
The radio module of some Huawei smartphones Emily-AL00A The versions before 8.1.0.171(C00) have a lock-screen bypass vulnerability. An unauthenticate…
Emily Al00a Firmware
8.1.0.171+
HIGH 7.8
CVE-2018-9488
In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of pri…
Android
Patch available
MEDIUM 6.6
CVE-2018-14665EPSS 27%
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server al…
Enterprise Linux Desktop
Patch available
CRITICAL 9.8
CVE-2018-12369
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain fu…
Firefox
60.1.0 / 61.0+
HIGH 8.8
CVE-2018-1000805
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in…
Ansible Tower
Patch available
MEDIUM 6.5
CVE-2018-15405
A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director coul…
Ucs Director
Mitigation only
MEDIUM 6.5
CVE-2018-0460
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any fil…
Network Functions Virtualization Infrastructure
Mitigation only
MEDIUM 6.5
CVE-2018-0459
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote at…
Network Functions Virtualization Infrastructure
Mitigation only
HIGH 7.8
CVE-2018-9492
In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privi…
Android
Patch available
MEDIUM 6.5
CVE-2018-1250
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could pote…
Emc Unity Firmware
4.3.1.1525703027+
MEDIUM 5.5
CVE-2018-16597
An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or t…
Linux Kernel
4.8+
MEDIUM 6.8
CVE-2018-7929
Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability. An attacker could unlock and u…
Mate Rs Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-1999047
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel …
Jenkins
after 2.137
MEDIUM 6.0
CVE-2018-15468
An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do no…
Xen
after 4.11.0
HIGH 8.1
CVE-2018-10925
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statemen…
Ubuntu Linux
9.5.14 / 9.6.10+
MEDIUM 5.3
CVE-2018-3778
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
Aedes
0.35.0+
MEDIUM 6.5
CVE-2018-5489
NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have been intended to be restricted t…
7 Mode Transition Tool
2.0+
CRITICAL 9.8
CVE-2017-7470
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…
Spacewalk
Mitigation only
HIGH 7.5
CVE-2018-11047
Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, inc…
Cloud Foundry Uaa
4.5.7 / 4.7.6+
HIGH 8.8
CVE-2017-3183
Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full ac…
Xrt Treasury
Mitigation only
HIGH 7.2
CVE-2017-2673
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user…
Openstack
Patch available
HIGH 8.8
CVE-2018-1245
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect co…
Rsa Identity Governance And Lifecycle
Mitigation only
HIGH 7.5
CVE-2018-13109EPSS 36%
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able t…
Dv2210 Firmware
No fix yet
MEDIUM 6.5
CVE-2018-12103
An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/…
Dir 890l Firmware
after 1.21b04beta01
HIGH 8.8
CVE-2017-16773
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass …
Universal Search
1.0.5-0135+
HIGH 7.8
CVE-2018-0337
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrar…
Nx Os
Mitigation only
MEDIUM 6.5
CVE-2018-8927
Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via…
Calendar
2.1.2-0511+
HIGH 8.8
CVE-2017-15695
When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy cod…
Geode
after 1.4.0
HIGH 7.8
CVE-2018-0338
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local att…
Unified Computing System
Mitigation only