Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Nas Os HIGH 7.5
CVE-2018-12301

Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.…

Mitigation only
Fix from $1,950 2019-05-13
Harp MEDIUM 5.3
CVE-2019-5437

Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp …

Fix: after 0.29.0
Fix from $1,600 2019-05-10
Aruba Instant HIGH 7.5
CVE-2018-7083

If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time i…

Fix: 4.2.4.12 / 6.5.4.11+
Fix from $1,950 2019-05-10
Open Xchange Appsuite HIGH 7.5
CVE-2017-12884

OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure.

Fix: after 7.8.4
Fix from $1,950 2019-05-10
Cloud App Management MEDIUM 5.3
CVE-2018-1990

IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a specially …

Patch available
Fix from $1,600 2019-05-10
Identity Manager HIGH 7.5
CVE-2016-1600

The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.

Fix: 4.6+
Fix from $1,950 2019-05-09
Wpbackupplus HIGH 7.5
CVE-2018-19456

The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders…

Fix: after 2018-11-22
Fix from $1,950 2019-05-07
Fl Switch 3005 Firmware MEDIUM 5.3
CVE-2018-13991

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images.

Fix: after 1.34
Fix from $1,600 2019-05-07
Contour Diabetes HIGH 7.5
CVE-2018-18975

An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communications between the app and Asce…

Fix: 2.4.30+
Fix from $1,950 2019-05-06
Contour Diabetes HIGH 7.5
CVE-2018-18977

An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reverse engineer the codebase to …

Fix: 2.5.0+
Fix from $1,950 2019-05-06
Airlink Es450 Firmware MEDIUM 6.5
CVE-2018-4067

An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.…

No fix yet
Fix from $1,600 2019-05-06
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4070EPSS 18%

An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…

No fix yet
Fix from $1,950 2019-05-06
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4071EPSS 19%

An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…

No fix yet
Fix from $1,950 2019-05-06
Airlink Es450 Firmware MEDIUM 5.3
CVE-2018-4068EPSS 11%

An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request …

Mitigation only
Fix from $1,600 2019-05-06
Airlink Es450 Firmware HIGH 7.5
CVE-2018-4069

An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManag…

No fix yet
Fix from $1,950 2019-05-06
Spring Data Java Persistence Api MEDIUM 5.3
CVE-2019-3797

This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘…

Fix: after 2.1.5
Fix from $1,600 2019-05-06
Application Policy Infrastructure Controller MEDIUM 5.3
CVE-2019-1692

A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenti…

Fix: 4.1+
Fix from $1,600 2019-05-03
Honeypress HIGH 7.5
CVE-2019-11633

HoneyPress through 2016-09-27 can be fingerprinted by attackers because of the ingrained unique www.atxsec.com and ayylmao.wpengine.com hostnames wit…

Fix: after 2016-09-27
Fix from $1,950 2019-05-01
Linux Kernel MEDIUM 5.5
CVE-2018-20509

The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address informat…

Mitigation only
Fix from $1,600 2019-04-30
Linux Kernel MEDIUM 5.5
CVE-2018-20510

The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address …

Mitigation only
Fix from $1,600 2019-04-30
Emptoris Contract Management MEDIUM 5.3
CVE-2018-1961

IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from error messages. IBM X-Force …

Fix: after 10.1.3.0
Fix from $1,600 2019-04-29
Jetty MEDIUM 5.3
CVE-2019-10246

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource dir…

Fix: after 3.1.3
Fix from $1,600 2019-04-22
Debian Linux MEDIUM 5.3
CVE-2019-10247EPSS 6%

In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combinati…

Fix: after 3.1.3
Fix from $1,600 2019-04-22
Nova HIGH 8.6
CVE-2011-3147

Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesyst…

Fix: 2012.1+
Fix from $1,950 2019-04-22
Build Cache Node CRITICAL 9.8
CVE-2019-11403

In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings …

Fix: 5.2 / 2018.5.2+
Fix from $2,300 2019-04-22
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2018-1729

IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-…

Fix: after 7.3.2
Fix from $1,600 2019-04-19
GitLab MEDIUM 5.3
CVE-2019-9225

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect A…

Fix: 11.6.10 / 11.7.6+
Fix from $1,600 2019-04-17
GitLab MEDIUM 5.3
CVE-2019-9175

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Informat…

Fix: 11.6.10 / 11.7.6+
Fix from $1,600 2019-04-17
Fortisiem HIGH 7.2
CVE-2018-13378

An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source…

Fix: after 5.2.0
Fix from $1,950 2019-04-17
Cp 1604 Firmware CRITICAL 9.1
CVE-2018-13808

A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). An attacker with network access to port 23/tcp could extract i…

Fix: after 2.8
Fix from $2,300 2019-04-17