Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Abusefilter MEDIUM 5.3
CVE-2019-18987

An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been ma…

Fix: after 1.34
Fix from $1,600 2019-11-15
Wndr4700 Firmware HIGH 7.5
CVE-2013-3070

An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK…

Patch available
Fix from $1,950 2019-11-14
Moodle MEDIUM 5.3
CVE-2012-1169

Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are show…

Fix: 2.2.2+
Fix from $1,600 2019-11-14
Moodle HIGH 7.5
CVE-2012-1155

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from …

Fix: 1.9.17 / 2.0.8+
Fix from $1,950 2019-11-14
Ckeditor HIGH 7.5
CVE-2011-4972

hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to rea…

Patch available
Fix from $1,950 2019-11-13
Intercom HIGH 7.5
CVE-2019-14365

The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the vict…

Fix: after 1.2.1
Fix from $1,950 2019-11-12
Wp Slacksync HIGH 7.5
CVE-2019-14366

WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the vict…

Fix: after 1.8.5
Fix from $1,950 2019-11-12
Slack Chat HIGH 7.5
CVE-2019-14367

Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, m…

Fix: after 1.5.5
Fix from $1,950 2019-11-12
Windows 10 MEDIUM 5.5
CVE-2019-1436

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure V…

Patch available
Fix from $1,600 2019-11-12
Windows 10 MEDIUM 6.5
CVE-2019-1439EPSS 76%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…

Patch available
Fix from $1,600 2019-11-12
Windows 10 MEDIUM 5.5
CVE-2019-1440

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure V…

Patch available
Fix from $1,600 2019-11-12
Excel MEDIUM 5.5
CVE-2019-1446EPSS 8%

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information…

Patch available
Fix from $1,600 2019-11-12
Office MEDIUM 5.5
CVE-2019-1402

An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Micros…

Patch available
Fix from $1,600 2019-11-12
Windows 10 MEDIUM 5.5
CVE-2019-1374EPSS 7%

An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Infor…

Patch available
Fix from $1,600 2019-11-12
Windows 10 MEDIUM 5.5
CVE-2019-1381

An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows …

Patch available
Fix from $1,600 2019-11-12
Windows 10 MEDIUM 5.3
CVE-2019-1324

An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP…

Patch available
Fix from $1,600 2019-11-12
Open Enclave Software Development Kit MEDIUM 5.5
CVE-2019-1370

An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Inf…

Fix: after 0.7.0
Fix from $1,600 2019-11-12
Device Manager HIGH 7.5
CVE-2018-21026

A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.

Fix: 8.6.5-00 / 8.7.0-00+
Fix from $1,950 2019-11-12
Cognos Controller MEDIUM 5.3
CVE-2019-4412

IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to …

Patch available
Fix from $1,600 2019-11-09
Tasy Emr MEDIUM 5.3
CVE-2019-13557

In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access …

Fix: after 3.02.1757
Fix from $1,600 2019-11-08
Jboss Operations Network MEDIUM 6.5
CVE-2008-5083

In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.

Fix: 2.1.2+
Fix from $1,600 2019-11-08
Debian Linux HIGH 7.5
CVE-2010-2450

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed …

Patch available
Fix from $1,950 2019-11-07
Mf910s Firmware MEDIUM 6.2
CVE-2019-3422

The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of…

No fix yet
Fix from $1,600 2019-11-07
Debian Linux HIGH 7.5
CVE-2009-5045

Dump Servlet information leak in jetty before 6.1.22.

Fix: 6.1.22+
Fix from $1,950 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4900

TYPO3 before 4.5.4 allows Information Disclosure in the backend.

Fix: 4.5.4+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4901

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4627

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
Firepower Extensible Operating System MEDIUM 5.5
CVE-2019-1734

A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local…

Fix: 2.2.2.91 / 2.3.1.111+
Fix from $1,600 2019-11-05
Enterprise Chat And Email MEDIUM 6.5
CVE-2019-1877

A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through…

No fix yet
Fix from $1,600 2019-11-05
TYPO3 MEDIUM 5.3
CVE-2010-3673

TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.

Fix: 4.2.13 / 4.3.4+
Fix from $1,600 2019-11-05