Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Cpanel MEDIUM 5.5
CVE-2018-20870

The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).

Fix: 76.0.8+
Fix from $1,600 2019-07-30
Central Print Services MEDIUM 5.3
CVE-2018-17211

An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers asso…

Fix: after 4.1.4
Fix from $1,600 2019-07-29
Web Player MEDIUM 6.5
CVE-2015-9288

The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credenti…

Fix: 4.6.6f2 / 5.0.3f2+
Fix from $1,600 2019-07-29
Craft Cms MEDIUM 5.3
CVE-2019-14280EPSS 9%

In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,…

Fix: 2.7.10 / 3.2.6+
Fix from $1,600 2019-07-26
Storm HIGH 7.5
CVE-2019-0202

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…

Fix: after 1.2.2
Fix from $1,950 2019-07-26
Mdm9206 Firmware HIGH 7.5
CVE-2018-13897

Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, Snapdragon Conn…

Patch available
Fix from $1,950 2019-07-25
Univention Corporate Server HIGH 7.5
CVE-2019-1010283

Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. The impact …

Fix: after 12.0.1-3
Fix from $1,950 2019-07-17
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2018-2022

IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system…

Fix: 7.2.8+
Fix from $1,600 2019-07-17
Pan Os HIGH 8.8
CVE-2019-1575

Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow f…

Fix: 7.1.24 / 8.0.19+
Fix from $1,950 2019-07-16
Windows 10 MEDIUM 6.5
CVE-2019-1108EPSS 11%

An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Proto…

Patch available
Fix from $1,600 2019-07-15
Office MEDIUM 5.5
CVE-2019-1112EPSS 9%

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information…

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 5.5
CVE-2019-1091

An information disclosure vulnerability exists when Unistore.dll fails to properly handle objects in memory, aka 'Microsoft unistore.dll Information …

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 5.5
CVE-2019-1093

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 6.5
CVE-2019-1094EPSS 7%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 6.5
CVE-2019-1095EPSS 7%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 5.5
CVE-2019-1096

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure V…

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 5.5
CVE-2019-1097

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 5.5
CVE-2019-1071

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosu…

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 5.5
CVE-2019-1073

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosu…

Patch available
Fix from $1,600 2019-07-15
Exchange Server MEDIUM 6.5
CVE-2019-1084EPSS 5%

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authe…

Patch available
Fix from $1,600 2019-07-15
Rust MEDIUM 5.3
CVE-2019-1010299

The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitializ…

Fix: 1.30.0+
Fix from $1,600 2019-07-15
Charge 2 Firmware MEDIUM 6.5
CVE-2014-10374

On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackabi…

Mitigation only
Fix from $1,600 2019-07-15
Glibc MEDIUM 5.3
CVE-2019-1010024

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: g…

No fix yet
Fix from $1,600 2019-07-15
Jazz For Service Management HIGH 7.5
CVE-2019-4193

IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthor…

Fix: after 1.1.3.2
Fix from $1,950 2019-07-11
Security Identity Manager Virtual Appliance MEDIUM 5.3
CVE-2018-1968

IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on th…

Fix: after 7.0.1.12
Fix from $1,600 2019-07-11
Junos MEDIUM 5.8
CVE-2019-0048

On EX4300 Series switches with TCAM optimization enabled, incoming multicast traffic matches an implicit loopback filter rule first, since it has hig…

Patch available
Fix from $1,600 2019-07-11
3par Service Processor Firmware CRITICAL 9.8
CVE-2019-11991

HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.…

Fix: after 4.4
Fix from $2,300 2019-07-09
Nvx220 Firmware HIGH 7.5
CVE-2018-14529

Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes.

No fix yet
Fix from $1,950 2019-07-05
Fedora HIGH 7.8
CVE-2019-13313

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the comm…

Patch available
Fix from $1,950 2019-07-05
Virt Bootstrap HIGH 7.8
CVE-2019-13314

virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password…

No fix yet
Fix from $1,950 2019-07-05