Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Next Unit Of Computing Firmware MEDIUM 6.0
CVE-2018-12158

Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a privileged user to potentially t…

Fix: 2018-05-24+
Fix from $1,600 2018-10-10
Raid Web Console MEDIUM 6.5
CVE-2018-12161

Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated user to potentially disclose …

Fix: after 3.0
Fix from $1,600 2018-10-10
Xmeye P2p Cloud Server MEDIUM 5.3
CVE-2018-17917

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud …

Mitigation only
Fix from $1,600 2018-10-10
Excel Viewer MEDIUM 5.5
CVE-2018-8427

An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Compon…

Patch available
Fix from $1,600 2018-10-10
Windows 10 MEDIUM 5.5
CVE-2018-8472EPSS 19%

An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an att…

Patch available
Fix from $1,600 2018-10-10
Asp.net Core HIGH 7.5
CVE-2018-8292EPSS 15%

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core In…

Patch available
Fix from $1,950 2018-10-10
Windows 10 MEDIUM 5.5
CVE-2018-8330

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…

Patch available
Fix from $1,600 2018-10-10
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2018-1743

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The information can be used to mount furthe…

Fix: after 3.0.0.1
Fix from $1,600 2018-10-08
Gitea MEDIUM 5.3
CVE-2018-1000803

Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appea…

Fix: 1.5.1+
Fix from $1,600 2018-10-08
Hyperflex Hx Data Platform MEDIUM 5.5
CVE-2018-15407

A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. T…

Mitigation only
Fix from $1,600 2018-10-05
Rv110w Firmware CRITICAL 9.8
CVE-2018-0425

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, …

Fix: 1.0.3.44+
Fix from $2,300 2018-10-05
Spectrum Scale MEDIUM 5.5
CVE-2018-1723

IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node…

Fix: after 5.0.1.2
Fix from $1,600 2018-10-05
Wp Db Backup HIGH 7.5
CVE-2014-10076

The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read …

No fix yet
Fix from $1,950 2018-10-05
Mediawiki MEDIUM 5.3
CVE-2018-13258

Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.

Fix: after 1.31.1
Fix from $1,600 2018-10-04
Pony Mail MEDIUM 5.3
CVE-2017-5658

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead…

Fix: after 0.9
Fix from $1,600 2018-10-04
GitLab MEDIUM 6.5
CVE-2018-16051

An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned U…

Fix: 11.0.6 / 11.1.5+
Fix from $1,600 2018-10-03
Emg 12 Firmware CRITICAL 9.8
CVE-2018-14822

Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may a…

Fix: after 2.57
Fix from $2,300 2018-10-02
Wordpress Mobile Pack HIGH 7.5
CVE-2015-9269

The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obt…

Fix: 2.1.3+
Fix from $1,950 2018-10-01
Thingworx Platform MEDIUM 6.5
CVE-2018-17216

An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users.

Fix: after 8.2
Fix from $1,600 2018-10-01
Telegram Desktop MEDIUM 6.5
CVE-2018-17780

Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because o…

No fix yet
Fix from $1,600 2018-09-29
Phantompdf HIGH 7.5
CVE-2018-17781

Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer …

Fix: after 9.2.0.9297
Fix from $1,950 2018-09-29
FreeBSD MEDIUM 5.5
CVE-2018-17155

In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initializa…

Fix: 11.2+
Fix from $1,600 2018-09-28
Advanced Systemcare MEDIUM 6.5
CVE-2018-16712

IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to sen…

Fix: after 1.2.0.5
Fix from $1,600 2018-09-26
Arris Tg2492lg Na Firmware HIGH 7.5
CVE-2018-17555

The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /snmpGet oids parameter.

No fix yet
Fix from $1,950 2018-09-26
E Alert Firmware MEDIUM 5.3
CVE-2018-14803

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that could allow at…

Mitigation only
Fix from $1,600 2018-09-26
Circarlife Scada MEDIUM 6.5
CVE-2018-16672

An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /servi…

Fix: 4.3+
Fix from $1,600 2018-09-26
Agassi L09 Firmware MEDIUM 5.5
CVE-2018-7907

Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, A…

Mitigation only
Fix from $1,600 2018-09-26
Chrome MEDIUM 6.5
CVE-2018-6045

Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file dat…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome MEDIUM 6.5
CVE-2018-6037

Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient …

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome HIGH 8.8
CVE-2018-6035

Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file dat…

Fix: 64.0.3282.119+
Fix from $1,950 2018-09-25