Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Cryptocat MEDIUM 5.3
CVE-2013-4110

Cryptocat has an Unspecified Chat Participant User List Disclosure

No fix yet
Fix from $1,600 2019-11-05
Kube State Metrics MEDIUM 6.5
CVE-2019-10223

A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that en…

No fix yet
Fix from $1,600 2019-11-05
TYPO3 MEDIUM 6.5
CVE-2010-3664

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-04
Cryptocat HIGH 7.5
CVE-2013-4105

Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure

Fix: 2.0.22+
Fix from $1,950 2019-11-04
Cryptocat HIGH 7.5
CVE-2013-2261EPSS 12%

Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure

Fix: 2.0.22+
Fix from $1,950 2019-11-04
Cryptocat HIGH 7.5
CVE-2013-2262

Cryptocat strophe.js before 2.0.22 has information disclosure

Fix: 2.0.22+
Fix from $1,950 2019-11-04
Update Infrastructure MEDIUM 5.5
CVE-2013-4518

RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates

No fix yet
Fix from $1,600 2019-11-04
Debian Linux HIGH 7.5
CVE-2013-2600

MiniUPnPd has information disclosure use of snprintf()

No fix yet
Fix from $1,950 2019-11-01
In App \& Desktop Notifications MEDIUM 5.3
CVE-2019-16908

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira …

Fix: 1.6.14_j8+
Fix from $1,600 2019-11-01
Icedtea6 CRITICAL 9.1
CVE-2010-2783

IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.

Fix: 1.7.4+
Fix from $2,300 2019-10-31
Rexpert MEDIUM 5.3
CVE-2019-17321

ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak use…

Fix: after 1.0.0.527
Fix from $1,600 2019-10-30
Elasticsearch MEDIUM 5.3
CVE-2019-7619

Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker c…

Fix: after 7.3.2
Fix from $1,600 2019-10-30
Modicon M580 Firmware HIGH 7.5
CVE-2019-6849

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure …

Mitigation only
Fix from $1,950 2019-10-29
Modicon M580 Firmware HIGH 7.5
CVE-2019-6850

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure …

Mitigation only
Fix from $1,950 2019-10-29
Modicon M580 Firmware HIGH 7.5
CVE-2019-6851EPSS 30%

A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmwar…

Mitigation only
Fix from $1,950 2019-10-29
Checkuser MEDIUM 6.5
CVE-2019-18611

An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made a…

Fix: after 1.34
Fix from $1,600 2019-10-29
Abusefilter MEDIUM 5.3
CVE-2019-18612

An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or…

Fix: after 1.34
Fix from $1,600 2019-10-29
Mediawiki HIGH 7.5
CVE-2012-0046

mediawiki allows deleted text to be exposed

Fix: 1.17.2 / 1.18.1+
Fix from $1,950 2019-10-29
Dir 865l Firmware MEDIUM 6.5
CVE-2013-4856

D-Link DIR-865L has Information Disclosure.

No fix yet
Fix from $1,600 2019-10-25
Cloud Orchestrator MEDIUM 6.5
CVE-2019-4397

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitive information in URL paramete…

Fix: after 2.5.0.9
Fix from $1,600 2019-10-24
Topmeeting HIGH 7.5
CVE-2019-13410

TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive informa…

Fix: 8.8+
Fix from $1,950 2019-10-17
WordPress MEDIUM 5.3
CVE-2019-17671EPSS 37%

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

Fix: 5.2.4+
Fix from $1,600 2019-10-17
Spa112 Firmware MEDIUM 6.5
CVE-2019-15257

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote at…

Fix: 1.4.1+
Fix from $1,600 2019-10-16
Spa112 Firmware MEDIUM 6.5
CVE-2019-12704

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote at…

Fix: 1.4.1+
Fix from $1,600 2019-10-16
Spa112 Firmware MEDIUM 6.5
CVE-2019-12708

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote at…

Fix: 1.4.1+
Fix from $1,600 2019-10-16
Imageassist HIGH 8.2
CVE-2019-3767

Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted informati…

Fix: 8.7.15+
Fix from $1,950 2019-10-14
Android MEDIUM 5.5
CVE-2019-2183

In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching optimization. This could lead …

Patch available
Fix from $1,600 2019-10-11
Axioma Premium Responsive HIGH 7.5
CVE-2015-9486

The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as use…

Fix: after 2015-05-15
Fix from $1,950 2019-10-11
Almera Responsive Portfolio HIGH 7.5
CVE-2015-9487

The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as u…

Fix: after 2015-05-15
Fix from $1,950 2019-10-11
Almera Responsive Portfolio Site Template HIGH 7.5
CVE-2015-9488

The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive info…

Fix: after 2015-05-15
Fix from $1,950 2019-10-11