Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Chrome MEDIUM 6.5
CVE-2019-13744

Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted H…

Fix: 79.0.3945.79+
Fix from $1,600 2019-12-10
Mod Wsgi HIGH 7.5
CVE-2014-0242EPSS 9%

mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type …

Fix: 3.4+
Fix from $1,950 2019-12-09
Sros2 MEDIUM 5.3
CVE-2019-19625

SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS…

Patch available
Fix from $1,600 2019-12-06
Sros2 MEDIUM 5.3
CVE-2019-19627

SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_kind configuration. (SROS2 pr…

No fix yet
Fix from $1,600 2019-12-06
Fedora MEDIUM 5.5
CVE-2012-1105

An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Serv…

Patch available
Fix from $1,600 2019-12-05
Iwr 3000n Firmware HIGH 7.2
CVE-2019-19007

Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled, a related issue…

Mitigation only
Fix from $1,950 2019-12-05
FreeBSD HIGH 7.5
CVE-2011-2480

Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signed…

Fix: 8.2+
Fix from $1,950 2019-11-27
Fedora MEDIUM 6.5
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIP…

Fix: 4.6.7 / 4.7.4+
Fix from $1,600 2019-11-27
Ubuntu Linux HIGH 7.5
CVE-2019-18679EPSS 41%

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when pro…

Fix: after 4.8
Fix from $1,950 2019-11-26
GitLab HIGH 7.5
CVE-2019-18460

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch int…

Fix: after 12.4.0
Fix from $1,950 2019-11-26
Cdh HIGH 7.5
CVE-2016-5724

Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.

Fix: 5.9.0+
Fix from $1,950 2019-11-26
Cloudera Manager HIGH 7.5
CVE-2015-6495

There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.

Fix: 4.8.6 / 5.0.7+
Fix from $1,950 2019-11-26
Nova MEDIUM 5.9
CVE-2011-4076

OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a…

Fix: 2012.1+
Fix from $1,600 2019-11-26
Ansible MEDIUM 6.5
CVE-2019-10217

A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP m…

Fix: 2.8.4+
Fix from $1,600 2019-11-25
Chrome HIGH 7.4
CVE-2019-5880

Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTM…

Fix: 77.0.3865.75+
Fix from $1,950 2019-11-25
Debian Linux MEDIUM 5.5
CVE-2012-5644

libuser has information disclosure when moving user's home directory

Fix: 0.59+
Fix from $1,600 2019-11-25
Fedora HIGH 7.5
CVE-2012-5535

gnome-system-log polkit policy allows arbitrary files on the system to be read

No fix yet
Fix from $1,950 2019-11-25
W3 Total Cache HIGH 7.5
CVE-2012-6078

W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.

Fix: 0.9.2.5+
Fix from $1,950 2019-11-22
W3 Total Cache HIGH 7.5
CVE-2012-6079

W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash…

Fix: 0.9.2.5+
Fix from $1,950 2019-11-22
W3 Total Cache HIGH 7.5
CVE-2012-6077EPSS 5%

W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.

Fix: 0.9.2.5+
Fix from $1,950 2019-11-22
Nexus 543 Firmware HIGH 7.5
CVE-2013-3314EPSS 7%

The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and sy…

No fix yet
Fix from $1,950 2019-11-21
Bmx P34x Firmware HIGH 7.5
CVE-2019-6852

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communicati…

Mitigation only
Fix from $1,950 2019-11-20
PostgreSQL HIGH 7.5
CVE-2015-3167

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different err…

Fix: 9.0.20 / 9.1.16+
Fix from $1,950 2019-11-20
Debian Linux HIGH 7.5
CVE-2013-1817

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive informatio…

Fix: 1.19.4 / 1.20.3+
Fix from $1,950 2019-11-20
Nifi MEDIUM 5.3
CVE-2019-10083

When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most …

Fix: after 1.9.2
Fix from $1,600 2019-11-19
Debian Linux MEDIUM 5.5
CVE-2012-0843

uzbl: Information disclosure via world-readable cookies storage file

Mitigation only
Fix from $1,600 2019-11-19
Mpack HIGH 7.5
CVE-2011-4919

mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

No fix yet
Fix from $1,950 2019-11-19
Debian Linux MEDIUM 5.5
CVE-2012-0842

surf: cookie jar has read access from other local user

Fix: 0.5+
Fix from $1,600 2019-11-19
Iterm2 HIGH 7.5
CVE-2019-19022

iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allo…

Fix: after 3.3.6
Fix from $1,950 2019-11-17
Debian Linux HIGH 7.5
CVE-2013-7089

ClamAV before 0.97.7: dbg_printhex possible information leak

Fix: 0.97.7+
Fix from $1,950 2019-11-15