Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16600

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Android MEDIUM 5.5
CVE-2018-9554

In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permissions bypass. This could lead…

Mitigation only
Fix from $1,600 2018-12-06
Integrated Performance Primitives MEDIUM 5.5
CVE-2018-12155

Data leakage in cryptographic libraries for Intel IPP before 2019 update1 release may allow an authenticated user to potentially enable information d…

Fix: 2019+
Fix from $1,600 2018-12-05
Qradar Advisor With Watson HIGH 7.5
CVE-2018-1732

IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on …

Fix: after 1.14.0
Fix from $1,950 2018-12-05
GitLab HIGH 7.5
CVE-2018-17939

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Inf…

Fix: 11.1.8 / 11.2.5+
Fix from $1,950 2018-12-04
GitLab MEDIUM 5.3
CVE-2018-17975

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure…

Fix: 11.1.8 / 11.2.5+
Fix from $1,600 2018-12-04
GitLab MEDIUM 6.5
CVE-2018-17976

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure…

Fix: 11.1.8 / 11.2.5+
Fix from $1,600 2018-12-04
GitLab MEDIUM 6.5
CVE-2018-18640

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information …

Fix: 11.2.7 / 11.3.8+
Fix from $1,600 2018-12-04
GitLab MEDIUM 6.5
CVE-2018-18644

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Info…

Fix: 11.2.7 / 11.3.8+
Fix from $1,600 2018-12-04
GitLab HIGH 7.5
CVE-2018-18648

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information …

Fix: 11.2.7 / 11.3.8+
Fix from $1,950 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6095

Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local fi…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6099

A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Data Master MEDIUM 6.5
CVE-2018-12308

Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key" URL parameter.

No fix yet
Fix from $1,600 2018-12-04
Data Master HIGH 8.8
CVE-2018-12318

Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.

No fix yet
Fix from $1,950 2018-12-04
5n2 Firmware HIGH 7.5
CVE-2018-14695

Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve…

No fix yet
Fix from $1,950 2018-12-03
5n2 Firmware HIGH 7.5
CVE-2018-14696

Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve…

No fix yet
Fix from $1,950 2018-12-03
5n2 Firmware HIGH 7.5
CVE-2018-14702

Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retri…

No fix yet
Fix from $1,950 2018-12-03
Quicken 2018 HIGH 7.1
CVE-2018-3854

An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A s…

No fix yet
Fix from $1,950 2018-12-03
Rails MEDIUM 6.5
CVE-2018-16477

A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` an…

Fix: 5.2.1.1+
Fix from $1,600 2018-11-30
Kde Applications HIGH 7.5
CVE-2018-19120

The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leadin…

Fix: 18.12.0+
Fix from $1,950 2018-11-29
Acrobat Dc HIGH 7.5
CVE-2018-15979EPSS 10%

Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier have a ntlm sso hash theft v…

Fix: after 19.008.20080
Fix from $1,950 2018-11-29
Emily Al00a Firmware MEDIUM 6.5
CVE-2018-7961

There is a smart SMS verification code vulnerability in some Huawei smart phones. An attacker should trick a user to access malicious Website or mali…

Mitigation only
Fix from $1,600 2018-11-27
Fusionsphere Openstack HIGH 7.5
CVE-2018-7977

There is an information leakage vulnerability on several Huawei products. Due to insufficient communication protection for specific services, a remot…

Mitigation only
Fix from $1,950 2018-11-27
Terramaster Operating System HIGH 7.5
CVE-2018-13352

Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directo…

No fix yet
Fix from $1,950 2018-11-27
Expedition HIGH 7.5
CVE-2018-10142

The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.

Mitigation only
Fix from $1,950 2018-11-27
Geforce Experience MEDIUM 5.5
CVE-2018-6266

NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration par…

Fix: 3.16+
Fix from $1,600 2018-11-27
Showdoc MEDIUM 6.5
CVE-2018-19609

ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content,…

No fix yet
Fix from $1,600 2018-11-27
Ts5600d1206 Firmware HIGH 7.5
CVE-2018-13319

Incorrect access control in get_portal_info in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to determine sensitive device information via a…

No fix yet
Fix from $1,950 2018-11-26
Linux Kernel MEDIUM 5.5
CVE-2018-16862

A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The n…

Fix: after 4.14
Fix from $1,600 2018-11-26
Royal Ts HIGH 8.1
CVE-2018-18865EPSS 8%

The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosur…

Fix: after 4.3.60728
Fix from $1,950 2018-11-20