Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Acrobat MEDIUM 6.5
CVE-2020-29075EPSS 8%

Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information…

Fix: after 20.013.20066
Fix from $1,600 2021-02-23
Aqt1000 Firmware HIGH 7.5
CVE-2020-11281

Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in Snapdragon …

Mitigation only
Fix from $1,950 2021-02-22
Channels HIGH 7.4
CVE-2020-35681

Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.Asg…

Fix: 3.0.3+
Fix from $1,950 2021-02-22
Emc Powerprotect Cyber Recovery MEDIUM 6.0
CVE-2021-21512

Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high privileged Cyb…

Mitigation only
Fix from $1,600 2021-02-19
Otrs MEDIUM 6.5
CVE-2021-21435

Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG…

Fix: after 8.0.10
Fix from $1,600 2021-02-08
Bamboo MEDIUM 5.3
CVE-2021-26067

Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory …

Fix: 7.2.2+
Fix from $1,600 2021-01-28
Cloud Pak For Security MEDIUM 5.3
CVE-2020-4815

IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response headers that could be used in …

Patch available
Fix from $1,600 2021-01-27
Qualcomm MEDIUM 5.5
CVE-2020-3687

Local privilege escalation in admin services in Windows environment can occur due to an arbitrary read issue.

No fix yet
Fix from $1,600 2021-01-21
Vtiger Crm MEDIUM 6.5
CVE-2020-19363

Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.

No fix yet
Fix from $1,600 2021-01-20
Fastify Csrf HIGH 8.8
CVE-2020-28482

This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts…

Fix: 3.0.0+
Fix from $1,950 2021-01-19
Junos MEDIUM 6.8
CVE-2021-0210

An Information Exposure vulnerability in J-Web of Juniper Networks Junos OS allows an unauthenticated attacker to elevate their privileges over the t…

Mitigation only
Fix from $1,600 2021-01-15
Contrail Networking MEDIUM 5.0
CVE-2021-0212

An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve …

Fix: 1911.31+
Fix from $1,600 2021-01-15
Tomcat MEDIUM 5.9
CVE-2021-24122EPSS 23%

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 t…

Fix: after 9.0.39
Fix from $1,600 2021-01-14
Itop HIGH 7.7
CVE-2020-4079

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal…

Fix: 2.7.2+
Fix from $1,950 2021-01-12
Netweaver Master Data Management HIGH 7.5
CVE-2021-21469

When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an e…

Mitigation only
Fix from $1,950 2021-01-12
Websphere Extreme Scale MEDIUM 5.3
CVE-2020-4336

IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav…

Fix: 8.6.1.4+
Fix from $1,600 2021-01-06
Joomla\! HIGH 7.5
CVE-2020-35611

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the …

Fix: after 3.9.22
Fix from $1,950 2020-12-28
Remote Application Server MEDIUM 5.3
CVE-2020-35710

Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even wi…

No fix yet
Fix from $1,600 2020-12-25
Nport Iaw5000a I\/o Firmware MEDIUM 5.3
CVE-2020-25192

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be displayed without proper authori…

Fix: after 2.1
Fix from $1,600 2020-12-23
Plcnext Firmware MEDIUM 5.5
CVE-2020-12518

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protecte…

Fix: 2021.0+
Fix from $1,600 2020-12-17
Financial Transaction Manager For Multiplatform MEDIUM 5.3
CVE-2020-4908

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog…

Patch available
Fix from $1,600 2020-12-16
Netcrunch CRITICAL 9.8
CVE-2019-14480

AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or…

Fix: after 11.0.0.5282
Fix from $2,300 2020-12-16
Android MEDIUM 6.5
CVE-2020-0488

In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data.…

Patch available
Fix from $1,600 2020-12-15
Xhq MEDIUM 5.3
CVE-2019-19283

A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive information about the server…

Fix: 6.1.0.0+
Fix from $1,600 2020-12-14
Curl HIGH 7.5
CVE-2020-8169

curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network…

Fix: 1.0.1.1 / 2.2+
Fix from $1,950 2020-12-14
3.0t Signa Hdxt Firmware CRITICAL 9.8
CVE-2020-25179

GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.

Mitigation only
Fix from $2,300 2020-12-14
Jabber CRITICAL 9.9
CVE-2020-27134

Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary …

Mitigation only
Fix from $2,300 2020-12-11
GitLab MEDIUM 5.3
CVE-2020-26413EPSS 35%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in u…

Fix: 13.6.2+
Fix from $1,600 2020-12-11
GitLab MEDIUM 5.3
CVE-2020-26417

Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6…

Fix: 13.4.7 / 13.5.5+
Fix from $1,600 2020-12-11
Icloud MEDIUM 6.5
CVE-2020-9849

An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and …

Fix: 7.0 / 11.0.1+
Fix from $1,600 2020-12-08