Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Dr. Safety HIGH 7.5
CVE-2018-18334

A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to byp…

Fix: 3.0.1478+
Fix from $1,950 2019-02-05
Bigfix Compliance MEDIUM 5.3
CVE-2017-1177

IBM BigFix Compliance 1.7 through 1.9.91 discloses sensitive information to unauthorized users. The information can be used to mount further attacks …

Fix: after 1.9.91
Fix from $1,600 2019-02-05
Suremdm MEDIUM 6.5
CVE-2018-15655

An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible.

Fix: 6.35+
Fix from $1,600 2019-02-05
Suremdm HIGH 7.5
CVE-2018-15656

An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/…

Fix: 2018-11-27+
Fix from $1,950 2019-02-05
Suremdm HIGH 7.5
CVE-2018-15658

An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to …

Fix: 2018-11-27+
Fix from $1,950 2019-02-05
Suremdm MEDIUM 6.5
CVE-2018-15659

An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications. Cross-origin access is possi…

Fix: 6.35+
Fix from $1,600 2019-02-05
Dir 823g Firmware HIGH 7.5
CVE-2019-7388

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers…

No fix yet
Fix from $1,950 2019-02-05
Tivoli Application Dependency Discovery Manager HIGH 7.5
CVE-2018-1675

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are …

Fix: after 7.3.0.5
Fix from $1,950 2019-02-04
Zed MEDIUM 5.3
CVE-2019-7312

Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANSSI qualification submission) …

Fix: 1.0.195 / 1.0.199+
Fix from $1,600 2019-02-03
Content Management CRITICAL 9.8
CVE-2018-18941

In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the v…

No fix yet
Fix from $2,300 2019-01-31
Trusted Firmware A MEDIUM 5.3
CVE-2018-19440

ARM Trusted Firmware-A allows information disclosure.

Fix: after 2.0
Fix from $1,600 2019-01-30
Open Xchange Appsuite MEDIUM 5.3
CVE-2018-12610

OX App Suite 7.8.4 and earlier allows Information Exposure.

Fix: after 7.8.4
Fix from $1,600 2019-01-30
Ceph HIGH 7.5
CVE-2018-16889

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files …

Fix: after 13.2.4
Fix from $1,950 2019-01-28
Identity Services Engine MEDIUM 6.5
CVE-2018-0187

A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential info…

Mitigation only
Fix from $1,600 2019-01-23
Mdm9607 Firmware MEDIUM 5.5
CVE-2017-18332

Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in version…

Mitigation only
Fix from $1,600 2019-01-18
Connect MEDIUM 5.3
CVE-2018-19718

Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead to exposure of the privilege…

Fix: after 9.8.1
Fix from $1,600 2019-01-18
Team Foundation Server MEDIUM 6.5
CVE-2019-0647

An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation …

Patch available
Fix from $1,600 2019-01-17
Ubuntu Linux HIGH 7.5
CVE-2018-5738EPSS 11%

Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are p…

Mitigation only
Fix from $1,950 2019-01-16
Debian Linux MEDIUM 5.2
CVE-2019-3811

A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the…

Fix: 2.1+
Fix from $1,600 2019-01-15
Concourse HIGH 7.5
CVE-2019-3803

Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a us…

Fix: 4.2.2+
Fix from $1,950 2019-01-12
Mac Os X HIGH 7.5
CVE-2018-4217

In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.

Fix: 10.13.5+
Fix from $1,950 2019-01-11
Mac Os X MEDIUM 5.5
CVE-2018-4179

In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

Fix: 10.13.4+
Fix from $1,600 2019-01-11
Iphone Os HIGH 7.5
CVE-2018-4185

In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transi…

Fix: 4.3 / 10.13.4+
Fix from $1,950 2019-01-11
Safari HIGH 7.5
CVE-2018-4186

In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with ad…

Fix: 11.1+
Fix from $1,950 2019-01-11
Apple Tv MEDIUM 6.5
CVE-2016-4643

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing o…

Fix: 9.2.2 / 9.3.3+
Fix from $1,600 2019-01-11
Apple Tv MEDIUM 6.5
CVE-2016-4644

In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authent…

Fix: 9.2.2 / 9.3.3+
Fix from $1,600 2019-01-11
Unified Communications Manager HIGH 8.8
CVE-2018-0474

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view d…

Mitigation only
Fix from $1,950 2019-01-10
Elfinder MEDIUM 5.9
CVE-2019-5884

php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.

Fix: 2.1.45+
Fix from $1,600 2019-01-10
Mate Screensaver MEDIUM 6.1
CVE-2018-20681

mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applicat…

Fix: 1.20.2+
Fix from $1,600 2019-01-09
Aterm Wf1200cr Firmware MEDIUM 6.5
CVE-2018-16192

Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on t…

Fix: after 1.1.1
Fix from $1,600 2019-01-09