Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
FreeBSD MEDIUM 6.5
CVE-2019-5601

In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a b…

No fix yet
Fix from $1,600 2019-07-03
Odoo MEDIUM 6.5
CVE-2018-14865

Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passin…

Patch available
Fix from $1,600 2019-07-03
Data Science Workbench CRITICAL 9.8
CVE-2018-11215

Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.

Fix: after 1.3.0
Fix from $2,300 2019-07-03
Wi Fi Blood Pressure Monitor Firmware MEDIUM 5.9
CVE-2017-11578

It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web m…

No fix yet
Fix from $1,600 2019-07-02
Linear Emerge Essential Firmware HIGH 8.8
CVE-2019-7259EPSS 13%

Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.

Fix: after 1.00-06
Fix from $1,950 2019-07-02
Spectrum Protect HIGH 7.1
CVE-2019-4140

IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IB…

Fix: 7.1.9.300 / 8.1.8.0+
Fix from $1,950 2019-07-02
Tor Browser MEDIUM 5.3
CVE-2019-13075

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involvin…

Fix: after 8.5.3
Fix from $1,600 2019-06-30
Unifying Receiver Firmware MEDIUM 6.5
CVE-2019-13055

Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency tra…

No fix yet
Fix from $1,600 2019-06-29
Containerized Data Importer MEDIUM 6.5
CVE-2019-10175

A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine wheth…

Mitigation only
Fix from $1,600 2019-06-28
Connect Secure MEDIUM 5.3
CVE-2018-20811

A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.

No fix yet
Fix from $1,600 2019-06-28
Pulse Secure Desktop Client HIGH 7.5
CVE-2018-20812

An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse S…

Mitigation only
Fix from $1,950 2019-06-28
Chrome MEDIUM 6.5
CVE-2018-6150

Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted…

Fix: 66.0.3359.117+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6159

Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive inf…

Fix: 68.0.3440.75+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6168

Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from pr…

Fix: 68.0.3440.75+
Fix from $1,600 2019-06-27
Chrome MEDIUM 5.5
CVE-2018-20073

Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.

Fix: 72.0.3626.81+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6134

Information leak in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page.

Fix: 67.0.3396.62+
Fix from $1,600 2019-06-27
Api Connect MEDIUM 5.3
CVE-2018-2011

IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could ai…

Fix: after 2018.4.1.5
Fix from $1,600 2019-06-25
Api Connect MEDIUM 5.3
CVE-2018-2013

IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the …

Fix: after 2018.4.1.5
Fix from $1,600 2019-06-25
Replicator 5th Generation Firmware HIGH 7.5
CVE-2014-9699

The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs, design files (i.e., a histor…

Mitigation only
Fix from $1,950 2019-06-24
Self Service Password Reset HIGH 7.5
CVE-2019-11648

An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be…

Fix: 4.4+
Fix from $1,950 2019-06-24
Data Science Workbench MEDIUM 5.3
CVE-2018-15665

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.

Fix: after 1.4.0
Fix from $1,600 2019-06-21
Magnum CRITICAL 9.8
CVE-2016-7404

OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the inst…

Patch available
Fix from $2,300 2019-06-21
Biyan HIGH 7.5
CVE-2019-11233

EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element to the au…

Fix: after 2.8
Fix from $1,950 2019-06-19
Almond 2015 Firmware HIGH 8.8
CVE-2017-8337

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of…

No fix yet
Fix from $1,950 2019-06-18
Netdata MEDIUM 5.3
CVE-2018-18839

An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "is intentional.

Patch available
Fix from $1,600 2019-06-18
Endoscope Camera Firmware MEDIUM 6.5
CVE-2017-10719

Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-F…

No fix yet
Fix from $1,600 2019-06-17
R8000 Firmware CRITICAL 9.1
CVE-2019-5016

An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of…

Mitigation only
Fix from $2,300 2019-06-17
R8000 Firmware MEDIUM 5.3
CVE-2019-5017

An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadySHARE Printer functionality of…

Mitigation only
Fix from $1,600 2019-06-17
Fusionpbx HIGH 7.2
CVE-2019-11407

app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessiv…

Patch available
Fix from $1,950 2019-06-17
Debian Linux MEDIUM 5.3
CVE-2019-12497

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x…

Fix: after 7.0.8
Fix from $1,600 2019-06-17