Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.2 CVE-2018-6980 VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registrati… Vrealize Log Insight 4.6.2 / 4.7.1+ Fix from $1,9502018-11-13 MEDIUM 6.8 CVE-2018-7925 The radio module of some Huawei smartphones Emily-AL00A The versions before 8.1.0.171(C00) have a lock-screen bypass vulnerability. An unauthenticate… Emily Al00a Firmware 8.1.0.171+ Fix from $1,6002018-11-13 HIGH 7.8 CVE-2018-9488 In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of pri… Android Patch available Fix from $1,9502018-11-06 MEDIUM 6.6 CVE-2018-14665EPSS 27% A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server al… Enterprise Linux Desktop Patch available Fix from $1,6002018-10-25 CRITICAL 9.8 CVE-2018-12369 WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain fu… Firefox 60.1.0 / 61.0+ Fix from $2,3002018-10-18 HIGH 8.8 CVE-2018-1000805 Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in… Ansible Tower Patch available Fix from $1,9502018-10-08 MEDIUM 6.5 CVE-2018-15405 A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director coul… Ucs Director Mitigation only Fix from $1,6002018-10-05 MEDIUM 6.5 CVE-2018-0460 A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any fil… Network Functions Virtualization Infrastructure Mitigation only Fix from $1,6002018-10-05 MEDIUM 6.5 CVE-2018-0459 A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote at… Network Functions Virtualization Infrastructure Mitigation only Fix from $1,6002018-10-05 HIGH 7.8 CVE-2018-9492 In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privi… Android Patch available Fix from $1,9502018-10-02 MEDIUM 6.5 CVE-2018-1250 Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could pote… Emc Unity Firmware 4.3.1.1525703027+ Fix from $1,6002018-09-28 MEDIUM 5.5 CVE-2018-16597 An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or t… Linux Kernel 4.8+ Fix from $1,6002018-09-21 MEDIUM 6.8 CVE-2018-7929 Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability. An attacker could unlock and u… Mate Rs Firmware Mitigation only Fix from $1,6002018-09-18 MEDIUM 6.5 CVE-2018-1999047 A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel … Jenkins after 2.137 Fix from $1,6002018-08-23 MEDIUM 6.0 CVE-2018-15468 An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do no… Xen after 4.11.0 Fix from $1,6002018-08-17 HIGH 8.1 CVE-2018-10925 It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statemen… Ubuntu Linux 9.5.14 / 9.6.10+ Fix from $1,9502018-08-09 MEDIUM 5.3 CVE-2018-3778 Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized. Aedes 0.35.0+ Fix from $1,6002018-08-08 MEDIUM 6.5 CVE-2018-5489 NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have been intended to be restricted t… 7 Mode Transition Tool 2.0+ Fix from $1,6002018-08-03 CRITICAL 9.8 CVE-2017-7470 It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati… Spacewalk Mitigation only Fix from $2,3002018-07-27 HIGH 7.5 CVE-2018-11047 Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, inc… Cloud Foundry Uaa 4.5.7 / 4.7.6+ Fix from $1,9502018-07-24 HIGH 8.8 CVE-2017-3183 Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full ac… Xrt Treasury Mitigation only Fix from $1,9502018-07-24 HIGH 7.2 CVE-2017-2673 An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user… Openstack Patch available Fix from $1,9502018-07-19 HIGH 8.8 CVE-2018-1245 RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect co… Rsa Identity Governance And Lifecycle Mitigation only Fix from $1,9502018-07-13 HIGH 7.5 CVE-2018-13109EPSS 36% All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able t… Dv2210 Firmware No fix yet Fix from $1,9502018-07-06 MEDIUM 6.5 CVE-2018-12103 An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/… Dir 890l Firmware after 1.21b04beta01 Fix from $1,6002018-07-05 HIGH 8.8 CVE-2017-16773 Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass … Universal Search 1.0.5-0135+ Fix from $1,9502018-07-05 HIGH 7.8 CVE-2018-0337 A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrar… Nx Os Mitigation only Fix from $1,9502018-06-21 MEDIUM 6.5 CVE-2018-8927 Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via… Calendar 2.1.2-0511+ Fix from $1,6002018-06-14 HIGH 8.8 CVE-2017-15695 When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy cod… Geode after 1.4.0 Fix from $1,9502018-06-13 HIGH 7.8 CVE-2018-0338 A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local att… Unified Computing System Mitigation only Fix from $1,9502018-06-07