Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.1 CVE-2018-1000197 An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users wit… Black Duck Hub after 3.0.3 Fix from $1,9502018-06-05 MEDIUM 5.5 CVE-2018-11142 The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible… Kace System Management Appliance No fix yet Fix from $1,6002018-05-31 CRITICAL 9.8 CVE-2018-1000155 OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifi… Openflow Mitigation only Fix from $2,3002018-05-24 HIGH 7.6 CVE-2018-1462 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6… Storwize V7000 Firmware 7.5.0.14 / 7.7.1.9+ Fix from $1,9502018-05-17 MEDIUM 6.5 CVE-2018-1463 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6… Storwize V7000 Firmware 7.5.0.14 / 7.7.1.9+ Fix from $1,6002018-05-17 HIGH 8.8 CVE-2018-1258 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method secur… Spring Framework 7.0.0.1 / 8.3+ Fix from $1,9502018-05-11 MEDIUM 6.5 CVE-2018-1278 Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an a… Pivotal Application Service 1.12.22 / 2.0.13+ Fix from $1,6002018-05-11 MEDIUM 6.5 CVE-2018-0278 A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data… Secure Firewall Management Center Mitigation only Fix from $1,6002018-05-02 MEDIUM 5.4 CVE-2018-10212 An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another a… Enterprise File Sharing Mitigation only Fix from $1,6002018-04-25 MEDIUM 6.5 CVE-2017-1700 IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), … Rational Collaborative Lifecycle Management after 6.0.5 Fix from $1,6002018-04-24 CRITICAL 9.1 CVE-2018-7245 An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS.… 66074 Mge Network Management Card Transverse Mitigation only Fix from $2,3002018-04-18 MEDIUM 5.9 CVE-2017-12196 undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that… Undertow after 1.4.18 Fix from $1,6002018-04-18 MEDIUM 5.4 CVE-2017-2599 Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.… Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-04-11 MEDIUM 6.3 CVE-2018-1000152 An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate… Vsphere after 2.16 Fix from $1,6002018-04-05 HIGH 7.5 CVE-2017-0922 Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in… GitLab after 10.3.3 Fix from $1,9502018-03-21 HIGH 8.8 CVE-2017-0926 Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user … GitLab after 10.3.3 Fix from $1,9502018-03-21 MEDIUM 6.5 CVE-2017-0927 Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use… GitLab after 10.3.3 Fix from $1,6002018-03-21 HIGH 7.5 CVE-2017-17668 Memory write mechanism in NCR S1 Dispenser controller before firmware version 0x0156 allows an unauthenticated user to upgrade or downgrade the firmw… S1 Dispenser Controller Firmware 0x0156+ Fix from $1,9502018-03-20 HIGH 8.8 CVE-2018-1057EPSS 10% On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowi… Ubuntu Linux 4.5.16 / 4.6.14+ Fix from $1,9502018-03-13 MEDIUM 6.3 CVE-2016-9575 Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in I… Freeipa Mitigation only Fix from $1,6002018-03-13 MEDIUM 5.4 CVE-2018-1000106 An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and P… Gerrit Trigger after 2.27.4 Fix from $1,6002018-03-13 MEDIUM 6.5 CVE-2018-1000107 An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobP… Job And Node Ownership after 0.11.0 Fix from $1,6002018-03-13 MEDIUM 5.3 CVE-2018-1000110 An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network… Git after 3.7.0 Fix from $1,6002018-03-13 MEDIUM 5.3 CVE-2018-1000111 An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionReposit… Subversion after 2.10.2 Fix from $1,6002018-03-13 MEDIUM 5.3 CVE-2018-1000112 An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker wi… Mercurial after 2.2 Fix from $1,6002018-03-13 MEDIUM 5.3 CVE-2017-18095 The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comm… Crucible 4.5.1+ Fix from $1,6002018-02-19 HIGH 7.5 CVE-2018-6316 Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privil… Endpoint Security after 8.5 Fix from $1,9502018-02-15 MEDIUM 6.7 CVE-2017-1233 IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to… Bigfix Remote Control Patch available Fix from $1,6002018-01-31 MEDIUM 6.8 CVE-2017-16858 The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an … Crowd 3.1.2+ Fix from $1,6002018-01-31 HIGH 7.1 CVE-2017-15091 An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some o… Authoritative after 4.0.4 Fix from $1,9502018-01-23