Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 MEDIUM 5.5
CVE-2019-1293

An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, …

Patch available
Fix from $1,600 2019-09-11
Windows 10 MEDIUM 5.5
CVE-2019-1251

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…

Patch available
Fix from $1,600 2019-09-11
Windows 10 MEDIUM 6.5
CVE-2019-1252EPSS 61%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…

Patch available
Fix from $1,600 2019-09-11
Excel MEDIUM 5.5
CVE-2019-1263EPSS 8%

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information…

Patch available
Fix from $1,600 2019-09-11
Windows 10 MEDIUM 6.5
CVE-2019-1244EPSS 12%

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…

Patch available
Fix from $1,600 2019-09-11
Windows 10 MEDIUM 6.5
CVE-2019-1245EPSS 13%

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…

Patch available
Fix from $1,600 2019-09-11
Lync MEDIUM 6.5
CVE-2019-1209EPSS 6%

An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'.

Patch available
Fix from $1,600 2019-09-11
Windows 10 MEDIUM 5.5
CVE-2019-1216

An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'.

Patch available
Fix from $1,600 2019-09-11
Windows 10 MEDIUM 5.5
CVE-2019-1219

An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Ma…

Patch available
Fix from $1,600 2019-09-11
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2019-0352

In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an…

Mitigation only
Fix from $1,950 2019-09-10
Limesurvey HIGH 7.5
CVE-2019-16177

In Limesurvey before 3.17.14, the entire database is exposed through browser caching.

Fix: 3.17.14+
Fix from $1,950 2019-09-09
GitLab HIGH 7.5
CVE-2019-11605

An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allow…

Fix: 11.8.10 / 11.9.11+
Fix from $1,950 2019-09-09
GitLab MEDIUM 5.3
CVE-2019-5463

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnera…

Fix: 11.11.7 / 12.0.4+
Fix from $1,600 2019-09-09
Charitable HIGH 7.5
CVE-2018-21011

The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.

Fix: 1.5.14+
Fix from $1,950 2019-09-09
Librenms MEDIUM 5.3
CVE-2019-10667

An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and …

Fix: after 1.47
Fix from $1,600 2019-09-09
Android MEDIUM 5.5
CVE-2019-2103

In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. Thi…

Patch available
Fix from $1,600 2019-09-05
Industrial Network Director CRITICAL 9.8
CVE-2019-1976

A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remo…

Fix: 1.6.0+
Fix from $2,300 2019-09-05
Linux Kernel MEDIUM 5.6
CVE-2019-15902

A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x …

Fix: after 5.2.11
Fix from $1,600 2019-09-04
Vd 1 Firmware CRITICAL 9.8
CVE-2019-11064

A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration…

Fix: after 230
Fix from $2,300 2019-08-29
Fortios MEDIUM 5.3
CVE-2018-13367

An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as ve…

Fix: after 6.2.0
Fix from $1,600 2019-08-23
Wp Support Plus Responsive Ticket System MEDIUM 5.3
CVE-2014-10388

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.

Fix: 4.2+
Fix from $1,600 2019-08-22
Solution Center CRITICAL 9.8
CVE-2019-6177

A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standa…

Mitigation only
Fix from $2,300 2019-08-21
Unified Computing System HIGH 7.5
CVE-2019-1908

A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an…

Fix: 2.0 / 3.0+
Fix from $1,950 2019-08-21
Manageengine Servicedesk Plus MEDIUM 5.3
CVE-2019-15045

AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality

Fix: 10509+
Fix from $1,600 2019-08-21
Debian Linux MEDIUM 6.5
CVE-2019-12746

An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS…

Fix: after 6.0.19
Fix from $1,600 2019-08-21
Api Connect MEDIUM 5.3
CVE-2019-4437

IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID…

Fix: after 2018.4.1.6
Fix from $1,600 2019-08-20
Linux Kernel MEDIUM 5.5
CVE-2017-18550

An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory becaus…

Fix: 4.13+
Fix from $1,600 2019-08-19
Linux Kernel MEDIUM 5.5
CVE-2017-18549

An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory becaus…

Fix: 4.13+
Fix from $1,600 2019-08-19
Clickhouse HIGH 7.5
CVE-2018-14669

ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arb…

Fix: 1.1.54390+
Fix from $1,950 2019-08-15
Fv Flowplayer Video Player MEDIUM 5.3
CVE-2019-14800

The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-ad…

Fix: 7.3.15.727+
Fix from $1,600 2019-08-15