Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Rental Bike Script MEDIUM 6.5
CVE-2019-7434

PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.

No fix yet
Fix from $1,600 2019-03-21
Opensource Classified Ads Script MEDIUM 6.5
CVE-2019-7436

PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory.

No fix yet
Fix from $1,600 2019-03-21
Social Network Tabs CRITICAL 9.8
CVE-2018-20555EPSS 10%

The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, con…

No fix yet
Fix from $2,300 2019-03-21
Wp Jobhunt HIGH 7.5
CVE-2018-19487

The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the adm…

Fix: 2.4+
Fix from $1,950 2019-03-21
Saltos MEDIUM 6.5
CVE-2018-18762EPSS 6%

SaltOS 3.1 r8126 contains a database download vulnerability.

No fix yet
Fix from $1,600 2019-03-21
Lobby Track MEDIUM 5.5
CVE-2018-17482

Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the …

Mitigation only
Fix from $1,600 2019-03-21
Lobby Track MEDIUM 5.5
CVE-2018-17483

Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the …

Mitigation only
Fix from $1,600 2019-03-21
Lobby Track HIGH 7.1
CVE-2018-17484

Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk m…

Mitigation only
Fix from $1,950 2019-03-21
Yast2 Samba Provision HIGH 7.8
CVE-2018-17956

In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samb…

Fix: after 1.0.1
Fix from $1,950 2019-03-15
Cc8800ce Firmware HIGH 7.5
CVE-2018-18205

Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebContent/startup.tar.gz with use…

Mitigation only
Fix from $1,950 2019-03-15
Oceanstor Uds Firmware CRITICAL 9.1
CVE-2015-2254

Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change patch loading information resu…

Fix: 100r002c01spc102+
Fix from $2,300 2019-03-13
Database Security MEDIUM 6.8
CVE-2019-3615

Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose…

Fix: after 4.6.6
Fix from $1,600 2019-03-12
Api Connect MEDIUM 6.5
CVE-2018-2009

IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a lis…

Fix: after 2018.4.1.0
Fix from $1,600 2019-03-11
Traffic Server HIGH 7.5
CVE-2018-11783

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plug…

Fix: after 8.0.1
Fix from $1,950 2019-03-07
Command Line Interface HIGH 8.8
CVE-2019-3781

Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remo…

Fix: 6.43.0+
Fix from $1,950 2019-03-07
Iphone Os CRITICAL 9.8
CVE-2019-6206

An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.…

Fix: 12.1.3+
Fix from $2,300 2019-03-04
Firefox MEDIUM 5.3
CVE-2018-12400

In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows informati…

Fix: 63.0+
Fix from $1,600 2019-02-28
Firefox HIGH 7.1
CVE-2018-12397

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being…

Fix: 60.3.0 / 63.0+
Fix from $1,950 2019-02-28
Bigfix Platform MEDIUM 5.3
CVE-2019-4061EPSS 23%

IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to …

Fix: after 9.5.11
Fix from $1,600 2019-02-27
Spectrum Virtualize Software MEDIUM 6.5
CVE-2018-1775

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated u…

Fix: after 8.2
Fix from $1,600 2019-02-27
Mdm9150 Firmware MEDIUM 5.5
CVE-2018-11845

Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdragon Auto, Snapdragon Compute,…

Mitigation only
Fix from $1,600 2019-02-25
Dir 825 Rev.b Firmware HIGH 7.5
CVE-2019-9126

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via requests for the router_info.xml d…

No fix yet
Fix from $1,950 2019-02-25
Storegrid MEDIUM 5.3
CVE-2014-10079EPSS 9%

In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML so…

No fix yet
Fix from $1,600 2019-02-23
Ios Xr HIGH 7.5
CVE-2019-1681EPSS 6%

A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthenticated, remote attacker to retri…

Fix: 6.5.2+
Fix from $1,950 2019-02-21
True Key MEDIUM 5.5
CVE-2019-3610

Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidenti…

Fix: after 3.1.9211.0
Fix from $1,600 2019-02-13
Android MEDIUM 5.5
CVE-2018-12006

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potenti…

Patch available
Fix from $1,600 2019-02-11
Frog Cms HIGH 7.5
CVE-2018-20776

Frog CMS 0.9.5 provides a directory listing for a /public request.

No fix yet
Fix from $1,950 2019-02-11
Pagure MEDIUM 5.9
CVE-2019-7628

Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to …

Patch available
Fix from $1,600 2019-02-08
Hadoop HIGH 7.5
CVE-2018-1296

In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs,…

Fix: after 2.7.5
Fix from $1,950 2019-02-07
Testrail MEDIUM 5.3
CVE-2019-7535

index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and…

Mitigation only
Fix from $1,600 2019-02-07