Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.1 CVE-2017-12113 An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7… Cpp Ethereum No fix yet Fix from $1,9502018-01-19 HIGH 8.1 CVE-2017-12116 An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce8… Aleth No fix yet Fix from $1,9502018-01-19 HIGH 8.1 CVE-2017-12118 An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073… Cpp Ethereum No fix yet Fix from $1,9502018-01-19 HIGH 8.1 CVE-2017-12112 An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c… Cpp Ethereum No fix yet Fix from $1,9502018-01-19 MEDIUM 6.8 CVE-2017-12114 An exploitable improper authorization vulnerability exists in admin_peers API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c07… Cpp Ethereum No fix yet Fix from $1,6002018-01-19 HIGH 8.1 CVE-2017-12115 An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce… Cpp Ethereum No fix yet Fix from $1,9502018-01-19 HIGH 8.1 CVE-2017-12117 An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c07… Cpp Ethereum No fix yet Fix from $1,9502018-01-19 MEDIUM 6.5 CVE-2017-12197 It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di… Debian Linux after 1.8 Fix from $1,6002018-01-18 HIGH 8.1 CVE-2018-0110 A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has b… Webex Meetings Server Mitigation only Fix from $1,9502018-01-18 MEDIUM 5.9 CVE-2018-0096 A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to … Prime Infrastructure Mitigation only Fix from $1,6002018-01-18 CRITICAL 9.8 CVE-2017-16743 An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.3… Fl Switch 3005 Firmware after 1.32 Fix from $2,3002018-01-12 HIGH 8.8 CVE-2018-2361 In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required… Solution Manager Mitigation only Fix from $1,9502018-01-09 HIGH 7.8 CVE-2017-4946 The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could r… Vrealize Operations For Horizon 6.5.1+ Fix from $1,9502018-01-05 CRITICAL 9.8 CVE-2017-17067 Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the… Splunk 6.3.12 / 6.4.9+ Fix from $2,3002017-11-30 MEDIUM 6.5 CVE-2017-1628 IBM Business Process Manager 8.6.0.0 allows authenticated users to stop and resume the Event Manager by calling a REST API with incorrect authorizati… Business Process Manager Mitigation only Fix from $1,6002017-11-27 HIGH 8.8 CVE-2017-0910 In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the … Zulip Server 1.7.1+ Fix from $1,9502017-11-27 MEDIUM 5.5 CVE-2017-8216 Warsaw Huawei Smart phones with software of versions earlier than Warsaw-AL00C00B180, versions earlier than Warsaw-TL10C01B180 have a permission cont… P10 Lite Firmware Mitigation only Fix from $1,6002017-11-22 HIGH 7.8 CVE-2017-8192 FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability. Due to improper authorization, an attacker with low privilege may exp… Fusionsphere Openstack Mitigation only Fix from $1,9502017-11-22 CRITICAL 9.6 CVE-2017-3891 In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with… Qnx Software Development Platform Mitigation only Fix from $2,3002017-11-14 HIGH 7.8 CVE-2017-12261 A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local at… Identity Services Engine Mitigation only Fix from $1,9502017-11-02 MEDIUM 6.5 CVE-2017-5060 Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed … Chrome 58.0.3029.81 / 58.0.3029.83+ Fix from $1,6002017-10-27 MEDIUM 6.5 CVE-2017-10379 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earl… MySQL 5.5.57 / 10.0.32+ Fix from $1,6002017-10-19 CRITICAL 9.8 CVE-2017-9653 An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure befo… Pi Integrator For Business Analystics Mitigation only Fix from $2,3002017-08-14 HIGH 7.5 CVE-2016-6797EPSS 8% The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.4… Tomcat after 8.5.4 Fix from $1,9502017-08-10 HIGH 7.5 CVE-2017-8633 Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Win… Windows 10 Patch available Fix from $1,9502017-08-08 CRITICAL 9.8 CVE-2017-9855 An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system.… Sunny Boy 3600 Firmware Mitigation only Fix from $2,3002017-08-05 HIGH 7.5 CVE-2017-6672 A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x co… Asr 5000 Series Software Mitigation only Fix from $1,9502017-07-25 CRITICAL 9.8 CVE-2017-7512 Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attack… 3scale Api Management Platform Mitigation only Fix from $2,3002017-07-07 HIGH 8.8 CVE-2017-10805 In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth mod… Odoo Patch available Fix from $1,9502017-07-04 HIGH 8.8 CVE-2017-8907 Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and t… Bamboo Mitigation only Fix from $1,9502017-06-14