Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Advanced Threat Defense MEDIUM 5.5
CVE-2020-7262

Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view sensitive files via a carefu…

Fix: 4.10.0+
Fix from $1,600 2020-06-22
GitLab MEDIUM 5.3
CVE-2020-13264

Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token

Fix: 12.9.8 / 12.10.7+
Fix from $1,600 2020-06-19
Jaeger MEDIUM 5.5
CVE-2020-10750

Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. …

Fix: 1.18.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2016-11075

An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.

Fix: 3.0.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.5
CVE-2016-11078

An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within …

Fix: 3.0.0+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 7.5
CVE-2016-11066

An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.

Fix: 3.2.0+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18895

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via …

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18901

An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON d…

Fix: 3.10.3 / 4.0.4+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18902

An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.

Fix: 3.10.3 / 4.0.4+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18887

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Ansible Tower MEDIUM 6.5
CVE-2020-10782

An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable …

Mitigation only
Fix from $1,600 2020-06-18
Unified Ip Phone 6901 Firmware MEDIUM 5.3
CVE-2020-3360

A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sens…

Fix: after 12.8
Fix from $1,600 2020-06-18
Webex Meetings MEDIUM 5.5
CVE-2020-3347

A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information …

Fix: 40.4.12+
Fix from $1,600 2020-06-18
Omero.web MEDIUM 5.7
CVE-2020-7932

OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a …

Fix: 5.6.3+
Fix from $1,600 2020-06-17
Easergy T300 Firmware HIGH 7.5
CVE-2020-7506

A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unpack the …

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Easergy T300 Firmware HIGH 7.5
CVE-2020-7510

A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtain private …

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Ssb Db HIGH 7.5
CVE-2020-4045

SSB-DB version 20.0.0 has an information disclosure vulnerability. The get() method is supposed to only decrypt messages when you explicitly ask it t…

Patch available
Fix from $1,950 2020-06-11
The Rolling Proximity Identifier CRITICAL 10.0
CVE-2020-13702

The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth…

Fix: after 2020-05-29
Fix from $2,300 2020-06-11
GitLab MEDIUM 5.3
CVE-2020-13268

A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. Thi…

Fix: after 13.0.1
Fix from $1,600 2020-06-10
Fedora MEDIUM 5.3
CVE-2020-12802

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not t…

Fix: 6.4.4+
Fix from $1,600 2020-06-08
Phantompdf HIGH 7.5
CVE-2019-20836

An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstrated by Google Drive.

Fix: 9.5+
Fix from $1,950 2020-06-04
Phantompdf CRITICAL 9.8
CVE-2018-21242

An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows Remote Code Execution via a GoToE or GoToR action.

Fix: 8.3.6+
Fix from $2,300 2020-06-04
Ip Office MEDIUM 5.5
CVE-2020-7030

A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t…

Fix: after 11.0.4.2
Fix from $1,600 2020-06-04
Chrome MEDIUM 6.5
CVE-2011-2863

Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from p…

Fix: 14.0.0.0+
Fix from $1,600 2020-06-03
Gravityforms HIGH 7.5
CVE-2020-13764

common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a …

Fix: 2.4.9+
Fix from $1,950 2020-06-02
Lexiglot MEDIUM 5.3
CVE-2014-8940

Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI.

Fix: after 2014-11-20
Fix from $1,600 2020-06-01
Aegir HIGH 7.5
CVE-2020-11059

In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from environment variables in the brow…

Fix: 21.10.1+
Fix from $1,950 2020-05-27
Mobilefirst Platform Foundation HIGH 7.5
CVE-2020-4226

IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure if unautho…

Patch available
Fix from $1,950 2020-05-27
Firefox Mobile HIGH 7.5
CVE-2020-6830

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was b…

Fix: 25.0+
Fix from $1,950 2020-05-26
Emc Isilon Onefs HIGH 7.5
CVE-2020-5364

Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by default, with a pre-configured c…

Fix: after 8.2.2
Fix from $1,950 2020-05-20