Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Tomcat HIGH 7.5
CVE-2020-17527EPSS 25%

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTT…

Fix: 21.1.2+
Fix from $1,950 2020-12-03
Growi HIGH 7.5
CVE-2020-5676

GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.

Fix: after 4.1.3
Fix from $1,950 2020-12-03
Bigbluebutton HIGH 7.5
CVE-2020-29043

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can cr…

Fix: after 2.2.29
Fix from $1,950 2020-11-26
Wepresent Wipg 1600w Firmware CRITICAL 9.8
CVE-2020-28333

Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not u…

No fix yet
Fix from $2,300 2020-11-24
Rsg35 Firmware MEDIUM 6.5
CVE-2020-12496

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.…

Fix: 2.0.0+
Fix from $1,600 2020-11-19
Moodle MEDIUM 5.3
CVE-2020-25703

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affec…

Fix: after 3.9.2
Fix from $1,600 2020-11-19
Iot Field Network Director HIGH 7.5
CVE-2020-26076

A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on a…

Fix: 4.6.1+
Fix from $1,950 2020-11-18
Radar Covid Backend Dp3t Server MEDIUM 5.3
CVE-2020-26230

Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identification and de-anonymization of…

Fix: 1.0.7 / 1.0.8+
Fix from $1,600 2020-11-13
Pan Os HIGH 7.5
CVE-2020-2022

An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administ…

Fix: 8.1.17 / 9.0.11+
Fix from $1,950 2020-11-12
32s330 Firmware MEDIUM 6.5
CVE-2020-27403

A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporatio…

No fix yet
Fix from $1,600 2020-11-10
Visual Components Network License Server HIGH 7.5
CVE-2020-10291

Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making …

Mitigation only
Fix from $1,950 2020-11-06
Bluedata Epic MEDIUM 6.5
CVE-2020-7196

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos pass…

Fix: after 4.0
Fix from $1,600 2020-10-26
Account Lockout Examiner HIGH 7.5
CVE-2020-15931

Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administ…

Fix: 5.1+
Fix from $1,950 2020-10-20
Otrs MEDIUM 5.3
CVE-2020-1777

Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as in chat transcriptions inside…

Fix: after 8.0.6
Fix from $1,600 2020-10-15
Debian Linux MEDIUM 5.5
CVE-2020-15250

In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste…

Fix: 3.1.1 / 4.13.1+
Fix from $1,600 2020-10-12
Pcvue HIGH 7.5
CVE-2020-26869

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitima…

Fix: 12.0.17+
Fix from $1,950 2020-10-12
Whatsapp HIGH 7.5
CVE-2020-1902

A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from…

Fix: after 2.20.140
Fix from $1,950 2020-10-06
Core HIGH 7.5
CVE-2020-15235

In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would normally be hidden to everyone ex…

Fix: after 41edf92
Fix from $1,950 2020-10-05
Sma100 Firmware MEDIUM 5.3
CVE-2020-5132

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerab…

Mitigation only
Fix from $1,600 2020-09-30
Unified Communications Manager MEDIUM 6.5
CVE-2019-15963

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view s…

Fix: after 12.5
Fix from $1,600 2020-09-23
Geforce Now HIGH 7.5
CVE-2020-5975

NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensiti…

Fix: 2.0.23+
Fix from $1,950 2020-09-18
Data Center MEDIUM 5.3
CVE-2020-14181EPSS 100%

Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili…

Fix: 7.13.6 / 8.5.7+
Fix from $1,600 2020-09-17
Helpdesk MEDIUM 6.5
CVE-2018-19947

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sen…

Fix: 3.0.3+
Fix from $1,600 2020-09-11
Experience Manager HIGH 7.5
CVE-2020-9733

An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If e…

Fix: after 6.5.5.0
Fix from $1,950 2020-09-10
Spectrum Power 4 MEDIUM 5.3
CVE-2020-15790

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susc…

Fix: 4.70+
Fix from $1,600 2020-09-09
Apq8009 Firmware MEDIUM 5.5
CVE-2020-3643

u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…

Mitigation only
Fix from $1,600 2020-09-08
Apq8009 Firmware MEDIUM 5.5
CVE-2020-3644

u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in Snapdragon Auto, S…

Mitigation only
Fix from $1,600 2020-09-08
Asyncos MEDIUM 6.5
CVE-2020-3547

A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Mana…

Fix: after 13.6.1-193
Fix from $1,600 2020-09-04
Jabber MEDIUM 6.5
CVE-2020-3498

A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is …

Fix: 12.1.3 / 12.5.2+
Fix from $1,600 2020-09-04
Jabber MEDIUM 5.7
CVE-2020-3537

A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulne…

Fix: 12.1.3 / 12.5.2+
Fix from $1,600 2020-09-04