Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Jetson Tx2 MEDIUM 5.5
CVE-2018-6239

NVIDIA Jetson TX2 contains a vulnerability by means of speculative execution where local and unprivileged code may access the contents of cached info…

Mitigation only
Fix from $1,600 2019-04-12
Junos CRITICAL 9.1
CVE-2019-0040

On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dro…

Mitigation only
Fix from $2,300 2019-04-10
Fortios MEDIUM 5.3
CVE-2018-13366

An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname…

Fix: after 5.6.7
Fix from $1,600 2019-04-09
Kura MEDIUM 5.3
CVE-2019-10243

In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to …

Fix: after 4.0.0
Fix from $1,600 2019-04-09
Api Connect MEDIUM 5.3
CVE-2019-4051

Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, netw…

Fix: after 2018.4.1.3
Fix from $1,600 2019-04-08
Business Automation Workflow MEDIUM 5.3
CVE-2018-1885

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a spec…

Fix: after 8.5.0.2
Fix from $1,600 2019-04-08
Linux Kernel MEDIUM 5.5
CVE-2018-20449

The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information …

Patch available
Fix from $1,600 2019-04-04
Mdm9206 Firmware MEDIUM 5.5
CVE-2018-11971

Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in Snapdragon Auto,…

Mitigation only
Fix from $1,600 2019-04-04
Iphone Os MEDIUM 5.5
CVE-2018-4431

A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tv…

Fix: 5.1.2 / 10.14.2+
Fix from $1,600 2019-04-03
Mac Os X MEDIUM 5.5
CVE-2018-4403

This issue was addressed by removing additional entitlements. This issue affected versions prior to macOS Mojave 10.14.1.

Fix: 10.14.1+
Fix from $1,600 2019-04-03
Iphone Os MEDIUM 5.5
CVE-2018-4379

A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked devi…

Fix: 12.0.1+
Fix from $1,600 2019-04-03
Iphone Os MEDIUM 5.5
CVE-2018-4380

A lock screen issue allowed access to photos and contacts on a locked device. This issue was addressed by restricting options offered on a locked dev…

Fix: 12.1+
Fix from $1,600 2019-04-03
Iphone Os MEDIUM 5.5
CVE-2018-4355

A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.

Fix: 10.14 / 12.0+
Fix from $1,600 2019-04-03
Cups MEDIUM 5.9
CVE-2018-4300

The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when th…

Fix: 2.2.10+
Fix from $1,600 2019-04-03
Safari HIGH 8.1
CVE-2018-4311

The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, …

Fix: 5.0 / 7.7+
Fix from $1,950 2019-04-03
Mac Os X MEDIUM 5.5
CVE-2018-4289

An information disclosure issue was addressed by removing the vulnerable code. This issue affected versions prior to macOS High Sierra 10.13.6.

Fix: 10.13.6+
Fix from $1,600 2019-04-03
Galaxy MEDIUM 5.5
CVE-2018-4052

An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker…

Mitigation only
Fix from $1,600 2019-04-02
Infosphere Information Server MEDIUM 6.5
CVE-2018-1917

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM …

Mitigation only
Fix from $1,600 2019-04-02
File Station MEDIUM 5.3
CVE-2018-13288

Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attacker…

Fix: 1.1.5-0125 / 1.2.2-0250+
Fix from $1,600 2019-04-01
Router Manager MEDIUM 5.3
CVE-2018-13289

Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain …

Fix: 1.1.7-6941-2+
Fix from $1,600 2019-04-01
Application Service MEDIUM 6.5
CVE-2018-13294

Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to ob…

Fix: 1.5.4-0320+
Fix from $1,600 2019-04-01
Application Service MEDIUM 6.5
CVE-2018-13295

Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated us…

Fix: 1.5.4-0320+
Fix from $1,600 2019-04-01
Drive Server MEDIUM 5.3
CVE-2018-13297

Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive syste…

Fix: 1.1.2-10562+
Fix from $1,600 2019-04-01
Ansible Tower HIGH 7.2
CVE-2019-3869

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A mal…

Fix: 3.3.5 / 3.4.3+
Fix from $1,950 2019-03-28
Solutions Business Manager HIGH 7.5
CVE-2018-19643

Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

Fix: 11.5+
Fix from $1,950 2019-03-27
Lifecare Pca Infusion System Firmware HIGH 7.5
CVE-2015-1012

Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA …

Fix: after 5.0
Fix from $1,950 2019-03-25
Ovirt Engine HIGH 8.8
CVE-2017-7510

In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.

Mitigation only
Fix from $1,950 2019-03-25
Plum A\+ Infusion System Firmware HIGH 7.5
CVE-2015-3952

Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, an…

Fix: after 13.6
Fix from $1,950 2019-03-25
Property Rental Software MEDIUM 6.5
CVE-2019-7429

PHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as the wp-con…

No fix yet
Fix from $1,600 2019-03-21
Image Sharing Script MEDIUM 6.5
CVE-2019-7431

PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory.

No fix yet
Fix from $1,600 2019-03-21