Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Jenkins HIGH 7.8
CVE-2018-1000410

An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases,…

Fix: after 2.145
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6179

Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who…

Fix: 68.0.3440.75+
Fix from $1,600 2019-01-09
Chrome MEDIUM 5.5
CVE-2018-6147

Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive i…

Fix: 67.0.3396.62+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6164

Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a …

Fix: 68.0.3440.75+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6117

Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from pro…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6137

CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Fix: 67.0.3396.62+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6109

readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome pri…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6093

Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16078

Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive i…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
.net Framework HIGH 7.5
CVE-2019-0545EPSS 10%

An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurat…

Patch available
Fix from $1,950 2019-01-08
Telegram MEDIUM 5.5
CVE-2018-3986

An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android messaging application version …

No fix yet
Fix from $1,600 2019-01-03
Wolfssl MEDIUM 5.9
CVE-2018-16870

It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This ma…

Fix: 3.15.7+
Fix from $1,600 2019-01-03
Ansible MEDIUM 5.3
CVE-2018-16876

ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of …

Fix: 2.5.14 / 2.6.11+
Fix from $1,600 2019-01-03
Mdm9650 Firmware MEDIUM 5.5
CVE-2017-18321

Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA660.

Mitigation only
Fix from $1,600 2019-01-03
Mdm9206 Firmware MEDIUM 5.5
CVE-2017-18322

Cryptographic key material leaked in WCDMA debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MD…

Mitigation only
Fix from $1,600 2019-01-03
Mdm9206 Firmware MEDIUM 5.5
CVE-2017-18324

Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, …

Mitigation only
Fix from $1,600 2019-01-03
Mdm9607 Firmware MEDIUM 5.5
CVE-2017-18326

Cryptographic keys are printed in modem debug messages in snapdragon mobile and snapdragon wear in versions MDM9607, MDM9615, MDM9625, MDM9635M, MDM9…

Mitigation only
Fix from $1,600 2019-01-03
Hg8010h Firmware MEDIUM 6.5
CVE-2018-7900

There is an information leak vulnerability in some Huawei HG products. An attacker may obtain information about the HG device by exploiting this vuln…

No fix yet
Fix from $1,600 2019-01-02
Lei Feng Tv Cms HIGH 7.5
CVE-2018-20602

Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.

No fix yet
Fix from $1,950 2018-12-30
Imcat HIGH 7.5
CVE-2018-20606

imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.

No fix yet
Fix from $1,950 2018-12-30
Imcat MEDIUM 5.3
CVE-2018-20607

imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI.

No fix yet
Fix from $1,600 2018-12-30
Imcat HIGH 7.5
CVE-2018-20608EPSS 12%

imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.

No fix yet
Fix from $1,950 2018-12-30
Imcat MEDIUM 5.3
CVE-2018-20609

imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.

No fix yet
Fix from $1,600 2018-12-30
Z5c Firmware HIGH 7.5
CVE-2018-14984

The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-…

No fix yet
Fix from $1,950 2018-12-28
Z5c Firmware HIGH 7.5
CVE-2018-14986

The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-…

Mitigation only
Fix from $1,950 2018-12-28
Damicms HIGH 7.5
CVE-2018-20571

DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id…

Mitigation only
Fix from $1,950 2018-12-28
Linux Kernel MEDIUM 5.5
CVE-2018-20511

An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain se…

Fix: 4.18.11+
Fix from $1,600 2018-12-27
Univerge Sv9100 Webpro Firmware CRITICAL 9.8
CVE-2018-11741EPSS 18%

NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GO…

No fix yet
Fix from $2,300 2018-12-26
Wget HIGH 7.8
CVE-2018-20483

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attri…

Fix: 1.20.1+
Fix from $1,950 2018-12-26
S Cms HIGH 7.5
CVE-2018-20478

An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a …

No fix yet
Fix from $1,950 2018-12-26