Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
X950 Firmware HIGH 7.5
CVE-2011-3269

Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Sca…

Mitigation only
Fix from $1,950 2020-03-09
X860 Firmware MEDIUM 5.3
CVE-2011-4538

Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.

Mitigation only
Fix from $1,600 2020-03-09
Manageengine Password Manager Pro MEDIUM 6.5
CVE-2016-1159

In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry…

Mitigation only
Fix from $1,600 2020-03-09
Mahara MEDIUM 6.5
CVE-2020-9282

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network respo…

Fix: 18.10.5 / 19.04.4+
Fix from $1,600 2020-03-09
Zammad HIGH 7.5
CVE-2020-10096

An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either rem…

Fix: after 3.2.0
Fix from $1,950 2020-03-05
Oneview Global Dashboard HIGH 7.5
CVE-2020-7130

HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of…

Mitigation only
Fix from $1,950 2020-03-04
Prime Collaboration Provisioning MEDIUM 5.3
CVE-2020-3193

A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to ob…

Fix: 12.6+
Fix from $1,600 2020-03-04
Jackson Databind CRITICAL 9.8
CVE-2019-14893

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of ma…

Fix: 2.8.11.5 / 2.9.10+
Fix from $2,300 2020-03-02
Decision Manager CRITICAL 9.8
CVE-2019-14892EPSS 6%

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2020-03-02
Asus Firmware MEDIUM 5.3
CVE-2018-8877

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows rem…

Fix: 3.0.0.4.382.50470 / 384.4+
Fix from $1,600 2020-02-27
Asuswrt Merlin MEDIUM 5.3
CVE-2018-8878

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows rem…

Fix: 3.0.0.4.382.50470 / 384.4+
Fix from $1,600 2020-02-27
Course Manager MEDIUM 6.5
CVE-2020-9337

In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.

Mitigation only
Fix from $1,600 2020-02-26
Buddypress HIGH 7.5
CVE-2020-5244

In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. Th…

Fix: 5.1.2+
Fix from $1,950 2020-02-24
Debian Linux MEDIUM 5.5
CVE-2012-0844

Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

Fix: after 2.8
Fix from $1,600 2020-02-21
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2013-3587EPSS 6%

The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted d…

Fix: after 12.1.2
Fix from $1,600 2020-02-21
Otrs MEDIUM 6.5
CVE-2013-3551

Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS IT…

Fix: 3.0.8 / 3.0.20+
Fix from $1,600 2020-02-21
Otrs MEDIUM 6.5
CVE-2013-4088

Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not p…

Fix: 3.0.21 / 3.1.17+
Fix from $1,600 2020-02-21
Linux Kernel MEDIUM 5.5
CVE-2011-4915

fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.

Fix: after 3.1
Fix from $1,600 2020-02-20
Zxv10 W300 Firmware HIGH 7.5
CVE-2014-4019EPSS 13%

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows…

No fix yet
Fix from $1,950 2020-02-20
Ansible MEDIUM 5.5
CVE-2014-4658

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtai…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Wpcentral HIGH 8.8
CVE-2020-9043EPSS 8%

The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.

Fix: 1.5.1+
Fix from $1,950 2020-02-17
Xclarity Administrator HIGH 7.5
CVE-2019-6193

An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated…

Fix: 2.6.6+
Fix from $1,950 2020-02-14
Risknet Acquirer HIGH 7.5
CVE-2013-5687

RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.

No fix yet
Fix from $1,950 2020-02-14
Magento HIGH 7.5
CVE-2012-6091

Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.

Fix: 1.7.0.2+
Fix from $1,950 2020-02-13
Viber MEDIUM 5.5
CVE-2018-3987

An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats…

No fix yet
Fix from $1,600 2020-02-13
Netweaver Application Server Java MEDIUM 5.8
CVE-2020-6190

Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about th…

Mitigation only
Fix from $1,600 2020-02-12
Android HIGH 7.5
CVE-2011-3901

Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.

No fix yet
Fix from $1,950 2020-02-12
Tube Map MEDIUM 5.9
CVE-2013-6681

Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability

Fix: 3.0.22+
Fix from $1,600 2020-02-12
Smartlight Rainbow Led Smart Bulb Firmware MEDIUM 6.5
CVE-2017-18642

Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to sniffing, reverse engineerin…

Fix: after 2017-08-06
Fix from $1,600 2020-02-10
Systems Insight Manager MEDIUM 5.7
CVE-2012-1994

HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information

Fix: 7.0+
Fix from $1,600 2020-02-10