Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Simplehrm HIGH 7.5
CVE-2013-2499

SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via spoofing a cookie.

Fix: after 2.3
Fix from $1,950 2020-01-27
Syliusresourcebundle MEDIUM 5.3
CVE-2020-5220

Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintend…

Fix: after 1.6.2
Fix from $1,600 2020-01-27
Mediawiki MEDIUM 5.9
CVE-2014-9481

The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted mod…

Fix: 1.19.23 / 1.22.15+
Fix from $1,600 2020-01-27
Pt7135 Firmware HIGH 7.5
CVE-2013-1594EPSS 7%

An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party crede…

No fix yet
Fix from $1,950 2020-01-24
Big Cloud Fabric HIGH 8.8
CVE-2019-19631

An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud…

Fix: 1.1.0 / 4.5.5+
Fix from $1,950 2020-01-24
Mysecureshell MEDIUM 5.5
CVE-2013-4176

mysecureshell 1.31: Local Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2020-01-23
Vanilla HIGH 7.5
CVE-2011-3613

An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

Fix: 2.0.17.9+
Fix from $1,950 2020-01-22
Tizen MEDIUM 6.5
CVE-2018-16264

The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-B…

Mitigation only
Fix from $1,600 2020-01-22
Galaxy Gear Firmware HIGH 7.5
CVE-2018-16269

The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to imp…

No fix yet
Fix from $1,950 2020-01-22
Mirc MEDIUM 5.3
CVE-2011-5282

mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.

Fix: 7.22+
Fix from $1,600 2020-01-21
Yopify MEDIUM 5.3
CVE-2017-3211

Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent purchase data of customers, all…

Fix: after 2017-04-06
Fix from $1,600 2020-01-15
Smp Pro4 Firmware MEDIUM 6.5
CVE-2020-6954

An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This passw…

No fix yet
Fix from $1,600 2020-01-13
Manageengine Eventlog Analyzer HIGH 7.5
CVE-2014-6038EPSS 73%

Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyze…

Fix: after 9.9
Fix from $1,950 2020-01-13
Sp C250sf Firmware HIGH 7.5
CVE-2019-14301

Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).

Fix: 1.02 / 1.09+
Fix from $1,950 2020-01-10
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2019-4559

IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on th…

Fix: after 7.3.3
Fix from $1,600 2020-01-10
Dompdf MEDIUM 6.5
CVE-2014-5011

DOMPDF before 0.6.2 allows Information Disclosure.

Fix: 0.6.2+
Fix from $1,600 2020-01-10
Simplenews MEDIUM 5.3
CVE-2012-2724

The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of…

Mitigation only
Fix from $1,600 2020-01-09
1password MEDIUM 5.5
CVE-2014-3753

AgileBits 1Password through 1.0.9.340 allows security feature bypass

Fix: after 1.0.9.340
Fix from $1,600 2020-01-09
Firefox MEDIUM 5.3
CVE-2019-17018

When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerabi…

Fix: 72.0+
Fix from $1,600 2020-01-08
Android MEDIUM 5.5
CVE-2016-5346

An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing…

Fix: 7.0+
Fix from $1,600 2020-01-08
Norton Mobile Security MEDIUM 5.5
CVE-2016-6587

An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, …

Fix: 3.16+
Fix from $1,600 2020-01-08
Platinum 4410 Firmware CRITICAL 9.8
CVE-2020-6170EPSS 7%

An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the …

No fix yet
Fix from $2,300 2020-01-08
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2014-5209

An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a mali…

Fix: after 14.1.0
Fix from $1,600 2020-01-08
Fortisiem MEDIUM 6.5
CVE-2019-6700

An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker …

Fix: 5.2.5+
Fix from $1,600 2020-01-07
Automated Message Handling System MEDIUM 6.1
CVE-2019-9541

: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script…

Fix: 4.1.5.5+
Fix from $1,600 2020-01-03
GitLab MEDIUM 5.3
CVE-2019-19256

GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

Fix: 12.5.1+
Fix from $1,600 2020-01-03
GitLab MEDIUM 5.3
CVE-2019-19254

GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

Fix: 12.5.1+
Fix from $1,600 2020-01-03
Debian Linux MEDIUM 5.9
CVE-2014-6275

FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages a…

Fix: 5.3.2+
Fix from $1,600 2020-01-02
GitLab MEDIUM 5.3
CVE-2018-20495

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. …

Fix: 11.4.13 / 11.5.6+
Fix from $1,600 2019-12-30
Debian Linux MEDIUM 5.5
CVE-2012-5476

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the adm…

Mitigation only
Fix from $1,600 2019-12-30