Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Diskstation Manager CRITICAL 9.8
CVE-2018-8919

Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers …

Fix: 6.1.6-15266+
Fix from $2,300 2018-12-24
Photorange Photo Vault CRITICAL 9.8
CVE-2018-20371

PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restr…

No fix yet
Fix from $2,300 2018-12-23
Dcs 936l Firmware HIGH 7.5
CVE-2018-18441

D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, suc…

No fix yet
Fix from $1,950 2018-12-20
Elasticsearch MEDIUM 6.5
CVE-2018-17244

Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, L…

Fix: after 6.4.2
Fix from $1,600 2018-12-20
Sssd MEDIUM 5.5
CVE-2018-16883

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. I…

Fix: 2.0.0+
Fix from $1,600 2018-12-19
Trusted Firmware A HIGH 7.5
CVE-2017-15031

In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world ti…

Fix: after 2.1
Fix from $1,950 2018-12-18
Modicom M340 Firmware HIGH 7.5
CVE-2018-7812

An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR020…

Mitigation only
Fix from $1,950 2018-12-17
Yara MEDIUM 5.5
CVE-2018-19976

In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequenc…

No fix yet
Fix from $1,600 2018-12-17
Security Guardium MEDIUM 5.3
CVE-2017-1272

IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties h…

Fix: after 10.5
Fix from $1,600 2018-12-17
Rendertron HIGH 7.5
CVE-2017-18355

Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "…

Patch available
Fix from $1,950 2018-12-17
Keystone MEDIUM 5.3
CVE-2018-20170

OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POS…

Fix: after 14.0.1
Fix from $1,600 2018-12-17
WordPress HIGH 7.5
CVE-2018-20151EPSS 6%

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration w…

Fix: 4.9.9 / 5.0.1+
Fix from $1,950 2018-12-14
Grafana MEDIUM 6.5
CVE-2018-19039EPSS 7%

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

Fix: 4.6.5 / 5.3.3+
Fix from $1,600 2018-12-13
Security Access Manager MEDIUM 5.3
CVE-2018-1886

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The info…

Fix: after 9.0.5.0
Fix from $1,600 2018-12-13
Simatic Step 7 \(tia Portal\) MEDIUM 5.5
CVE-2018-13811

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort cou…

Fix: 15.1+
Fix from $1,600 2018-12-13
Ofbiz HIGH 7.5
CVE-2018-8033EPSS 26%

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via …

Fix: after 16.11.04
Fix from $1,950 2018-12-13
Opendental HIGH 7.5
CVE-2018-15718

Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command prompt. T…

Fix: 18.4+
Fix from $1,950 2018-12-12
Bigfix Platform MEDIUM 5.3
CVE-2018-1481

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosur…

Fix: after 9.5.9
Fix from $1,600 2018-12-12
Bigfix Platform HIGH 7.5
CVE-2018-1476

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. The information can be used to …

Fix: after 9.5.9
Fix from $1,950 2018-12-12
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-15328

On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and t…

Fix: after 13.1.1
Fix from $1,950 2018-12-12
Debian Linux MEDIUM 6.5
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker …

Fix: 4.8.4+
Fix from $1,600 2018-12-11
Bits Service MEDIUM 6.8
CVE-2018-15800

Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing …

Fix: 2.18.0+
Fix from $1,600 2018-12-10
Websphere Application Server MEDIUM 5.5
CVE-2018-1957

IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an inc…

Fix: after 9.0.0.9
Fix from $1,600 2018-12-10
Debian Linux HIGH 7.8
CVE-2018-19962

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU m…

Fix: after 4.11.1
Fix from $1,950 2018-12-08
Datapower Gateway MEDIUM 5.9
CVE-2018-1663

IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to pro…

Fix: after 7.7.1.3
Fix from $1,600 2018-12-07
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16602

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16603

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16524

Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16527

Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16599

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06