Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Stashcat HIGH 7.2
CVE-2020-13129

An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with…

Fix: after 3.9.1
Fix from $1,950 2020-05-18
Android MEDIUM 5.0
CVE-2020-0092

In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification content due to a permissions bypa…

Patch available
Fix from $1,600 2020-05-14
Jetselect MEDIUM 6.5
CVE-2019-13023

An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, a…

Mitigation only
Fix from $1,600 2020-05-14
Spark HIGH 8.8
CVE-2020-12772

An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC …

No fix yet
Fix from $1,950 2020-05-12
Ansible Engine MEDIUM 5.0
CVE-2020-1746

A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well a…

Fix: 2.7.17 / 2.8.11+
Fix from $1,600 2020-05-12
Active Resource HIGH 7.5
CVE-2020-8151

There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to acce…

Fix: 5.1.1+
Fix from $1,950 2020-05-12
Keycloak MEDIUM 5.5
CVE-2020-1698

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe…

Fix: 9.0.0+
Fix from $1,600 2020-05-11
Remote Kiln Control HIGH 7.5
CVE-2019-18867

Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including sourc…

Fix: 3.0.0+
Fix from $1,950 2020-05-07
Secure Firewall Threat Defense HIGH 7.5
CVE-2020-3259 KEVEPSS 69%

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $1,950 2020-05-06
Fedora HIGH 7.2
CVE-2020-11033

In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying…

Fix: 9.4.6+
Fix from $1,950 2020-05-05
Archer MEDIUM 5.5
CVE-2020-5331

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored…

Fix: 6.7.0.3+
Fix from $1,600 2020-05-04
Laquis Scada MEDIUM 5.5
CVE-2020-10618

LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.

Fix: after 4.3.1
Fix from $1,600 2020-05-04
Big Iq Centralized Management MEDIUM 5.5
CVE-2020-5890

On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a QKView, credentials for bindin…

Fix: 14.1.2.4 / 15.1.0.2+
Fix from $1,600 2020-04-30
Oscp MEDIUM 6.5
CVE-2020-6865

ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimize the response of failure to …

Mitigation only
Fix from $1,600 2020-04-30
Moonlight HIGH 8.2
CVE-2020-11024

In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack. The bug has been fixed in Moonlight v4.0.1 for i…

Fix: 4.0.1+
Fix from $1,950 2020-04-29
Http Client HIGH 7.5
CVE-2020-11021

Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenar…

Fix: 1.0.8+
Fix from $1,950 2020-04-29
Rundeck MEDIUM 6.5
CVE-2020-11009

In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not autho…

Fix: 3.2.6+
Fix from $1,600 2020-04-29
D8500 Firmware MEDIUM 6.5
CVE-2017-18853

Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R…

Fix: after 1.0.7.10
Fix from $1,600 2020-04-29
800xa System CRITICAL 9.8
CVE-2020-8481

For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder…

Mitigation only
Fix from $2,300 2020-04-29
Ac1450 Firmware HIGH 7.5
CVE-2016-11059

Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-06, D500 before 2017-01-06, D1…

Fix: 2017-01-06+
Fix from $1,950 2020-04-28
D7000 Firmware HIGH 7.5
CVE-2018-21168

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7000 before 1.0.1.52, D7800 before 1.0.1.31, D8500 before …

Fix: 1.0.0.20 / 1.0.1.14+
Fix from $1,950 2020-04-27
Xtrabackup MEDIUM 6.5
CVE-2020-10997

Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments pa…

Fix: 2.4.20 / 8.0.11+
Fix from $1,600 2020-04-27
Advanced Woo Search HIGH 7.5
CVE-2020-12070

The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search …

Fix: after 1.99
Fix from $1,950 2020-04-24
Helm MEDIUM 5.0
CVE-2020-11013

Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0. `lookup` is a Helm template function introduced…

Fix: 3.2.0+
Fix from $1,600 2020-04-24
Cloud App Management MEDIUM 5.3
CVE-2019-4751

IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker further information about th…

Mitigation only
Fix from $1,600 2020-04-24
D6220 Firmware MEDIUM 6.5
CVE-2017-18704

Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.32, D6400 before 1.0.0.60, D85…

Fix: 1.0.0.32 / 1.0.0.60+
Fix from $1,600 2020-04-24
R7800 Firmware MEDIUM 6.5
CVE-2017-18712

Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.28, R6100 before 1.0.1.20, R75…

Fix: 1.0.0.48 / 1.0.0.118+
Fix from $1,600 2020-04-24
R7800 Firmware MEDIUM 6.5
CVE-2017-18713

Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.28, R6700 before 1.0.1.36, R69…

Fix: 1.0.0.48 / 1.0.1.28+
Fix from $1,600 2020-04-24
D1500 Firmware HIGH 7.5
CVE-2018-21139

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1…

Fix: 1.0.0.27 / 1.0.0.46+
Fix from $1,950 2020-04-23
Nginx Controller MEDIUM 5.5
CVE-2020-5866

In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive…

Fix: 3.3.0+
Fix from $1,600 2020-04-23