Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Openstack Mistral HIGH 7.5
CVE-2018-16849

A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbit…

Fix: 7.0.1+
Fix from $1,950 2018-11-02
Robotic Process Automation With Automation Anywhere MEDIUM 5.3
CVE-2018-1878

IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks aga…

Patch available
Fix from $1,600 2018-11-02
Yi Home Camera Firmware HIGH 7.5
CVE-2018-3928

An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of U…

No fix yet
Fix from $1,950 2018-11-01
Yi Home Camera Firmware HIGH 8.1
CVE-2018-3947

An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D. An attacker can sni…

No fix yet
Fix from $1,950 2018-11-01
Nextcloud Server MEDIUM 5.3
CVE-2018-16467

A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.

Fix: 14.0.0+
Fix from $1,600 2018-10-30
Mini Httpd MEDIUM 6.5
CVE-2018-18778EPSS 71%

ACME mini_httpd before 1.30 lets remote users read arbitrary files.

Fix: 1.30+
Fix from $1,600 2018-10-29
Linux Kernel MEDIUM 5.5
CVE-2018-18710

An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by lo…

Fix: after 4.19
Fix from $1,600 2018-10-29
Udp HIGH 7.5
CVE-2018-18657

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Informat…

Patch available
Fix from $1,950 2018-10-26
Udp HIGH 7.5
CVE-2018-18658

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Informat…

Patch available
Fix from $1,950 2018-10-26
Unified Communications Software MEDIUM 5.3
CVE-2018-18566

The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information…

Fix: after 5.8.0.12848
Fix from $1,600 2018-10-24
Conversations HIGH 7.5
CVE-2018-18467

An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing opened conversation by sending…

Patch available
Fix from $1,950 2018-10-23
Mdm9206 Firmware MEDIUM 5.5
CVE-2017-18300

Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile…

Mitigation only
Fix from $1,600 2018-10-23
Tl Sc3130 Firmware HIGH 7.5
CVE-2018-18428EPSS 11%

TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI.

No fix yet
Fix from $1,950 2018-10-19
H.264 Poe Ip Camera Firmware CRITICAL 9.8
CVE-2018-12671

An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can d…

No fix yet
Fix from $2,300 2018-10-19
H.264 Poe Ip Camera Firmware HIGH 7.5
CVE-2018-12673

An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can d…

No fix yet
Fix from $1,950 2018-10-19
Thingspro HIGH 7.5
CVE-2018-18390

User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Mitigation only
Fix from $1,950 2018-10-19
Emc Secure Remote Services MEDIUM 5.5
CVE-2018-15765

Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive …

Fix: 3.32.00.08+
Fix from $1,600 2018-10-18
Gxlcms HIGH 7.5
CVE-2018-18487

In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable d…

No fix yet
Fix from $1,950 2018-10-18
Enterprise Linux MEDIUM 6.5
CVE-2018-12373

dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affect…

Fix: 52.9.0+
Fix from $1,600 2018-10-18
Enterprise Linux MEDIUM 6.5
CVE-2018-12372

Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability a…

Fix: 52.9.0+
Fix from $1,600 2018-10-18
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-12365

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or inter…

Mitigation only
Fix from $1,600 2018-10-18
Wireless Lan Controller Software HIGH 7.5
CVE-2018-0442

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software…

Fix: 8.2.170.0 / 8.3.140.0+
Fix from $1,950 2018-10-17
Ca Identity Governance MEDIUM 5.3
CVE-2018-14597

CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error mes…

Fix: after 14.2
Fix from $1,600 2018-10-17
Airbox Firmware HIGH 7.5
CVE-2018-18376

goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnam…

No fix yet
Fix from $1,950 2018-10-16
Debian Linux MEDIUM 6.3
CVE-2018-18073

Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack…

Patch available
Fix from $1,600 2018-10-15
Rt Ac58u Firmware MEDIUM 5.3
CVE-2018-18287

On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source …

No fix yet
Fix from $1,600 2018-10-14
Zabbix HIGH 7.5
CVE-2018-18289

The MESILAT Zabbix plugin before 1.1.15 for Atlassian Confluence allows attackers to read arbitrary files.

Fix: 1.1.15+
Fix from $1,950 2018-10-14
Unified Endpoint Manager HIGH 7.5
CVE-2018-8890

An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user…

Mitigation only
Fix from $1,950 2018-10-12
Websphere Application Server MEDIUM 6.5
CVE-2018-1838

IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling o…

Mitigation only
Fix from $1,600 2018-10-12
Platform Symphony MEDIUM 6.5
CVE-2018-1708

IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. I…

Patch available
Fix from $1,600 2018-10-11