Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Ppp MEDIUM 5.5
CVE-2020-15704

The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module loading. A local non-root attacke…

Fix: 2.4.5-5ubuntu1.4 / 2.4.5-5.1ubuntu2.3+
Fix from $1,600 2020-09-01
Security Guardium Insights MEDIUM 5.3
CVE-2020-4172

IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties …

Patch available
Fix from $1,600 2020-08-27
Data Center Network Manager MEDIUM 5.5
CVE-2020-3520

A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obtain confidential information …

Fix: 11.4+
Fix from $1,600 2020-08-26
Open Eclass Platform HIGH 7.5
CVE-2020-24381

GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensu…

Fix: 3.11+
Fix from $1,950 2020-08-19
Windows 10 MEDIUM 5.5
CVE-2020-1510

An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploit…

Patch available
Fix from $1,600 2020-08-17
Webex Meetings Online MEDIUM 5.0
CVE-2020-3472

A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to acces…

Fix: 40.7.0+
Fix from $1,600 2020-08-17
Catalyst Center HIGH 7.5
CVE-2020-3411

A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. Th…

Fix: 1.3.1.4+
Fix from $1,950 2020-08-17
Xenmobile Server HIGH 7.5
CVE-2020-8210

Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.…

Fix: after 10.8.0
Fix from $1,950 2020-08-17
Edgeswitch Firmware MEDIUM 6.5
CVE-2020-8232

An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized informati…

Fix: 1.9.0+
Fix from $1,600 2020-08-17
Graphics Agent MEDIUM 5.5
CVE-2020-13179

Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server me…

Fix: 20.04.1+
Fix from $1,600 2020-08-11
Firefox HIGH 7.4
CVE-2020-15647

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data dis…

Fix: 68.10.1+
Fix from $1,950 2020-08-10
P2p HIGH 8.1
CVE-2020-9525

CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to p…

Fix: after 3.0.3a
Fix from $1,950 2020-08-10
Itop HIGH 7.5
CVE-2020-12777

A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose syste…

Fix: 2.7.1+
Fix from $1,950 2020-08-10
Ip Office HIGH 7.5
CVE-2019-7005

A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network acc…

Fix: after 11.0.4.2
Fix from $1,950 2020-08-07
Fisheye MEDIUM 6.5
CVE-2017-18112

Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability i…

Fix: 4.8.3+
Fix from $1,600 2020-08-05
Tanzu Application Service For Virtual Machines MEDIUM 5.7
CVE-2020-5414

VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains…

Fix: 2.7.15 / 2.7.19+
Fix from $1,600 2020-07-31
Security Guardium MEDIUM 5.3
CVE-2020-4186

IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the syste…

Patch available
Fix from $1,600 2020-07-30
Mediace CRITICAL 9.8
CVE-2020-15086

In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification…

Fix: 7.6.5+
Fix from $2,300 2020-07-29
TYPO3 HIGH 8.8
CVE-2020-15098

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered th…

Fix: 9.5.20 / 10.4.6+
Fix from $1,950 2020-07-29
TYPO3 HIGH 8.1
CVE-2020-15099

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attack…

Fix: 9.5.20 / 10.4.6+
Fix from $1,950 2020-07-29
Mq Appliance MEDIUM 5.5
CVE-2019-4731

IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Forc…

Patch available
Fix from $1,600 2020-07-28
Chrome MEDIUM 6.5
CVE-2020-6514EPSS 8%

Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exp…

Fix: 13.1.2 / 13.6+
Fix from $1,600 2020-07-22
React Native Fast Image MEDIUM 5.3
CVE-2020-7696

This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization:…

Patch available
Fix from $1,600 2020-07-17
Network Security Management HIGH 7.8
CVE-2020-7284

Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to gain unauthorised access to the…

Fix: 9.2.9.55 / 10.1.7.7+
Fix from $1,950 2020-07-03
Prestashop MEDIUM 5.3
CVE-2020-15080

In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. …

Fix: 1.7.6.6+
Fix from $1,600 2020-07-02
Prestashop MEDIUM 5.3
CVE-2020-15081

In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6…

Fix: 1.7.6.6+
Fix from $1,600 2020-07-02
Duckduckgo HIGH 7.5
CVE-2020-15502

The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests …

Fix: after 7.47.1.0
Fix from $1,950 2020-07-02
Digital Network Architecture Center MEDIUM 6.5
CVE-2020-3391

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in cle…

Fix: 1.2.10+
Fix from $1,600 2020-07-02
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4565

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an attacker to obtain sensitive information due to insecure communications being used bet…

Fix: after 10.1.5
Fix from $1,600 2020-06-26
Mir100 Firmware HIGH 7.1
CVE-2020-10274

The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control…

Fix: after 2.8.1.1
Fix from $1,950 2020-06-24