Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Enterprise Linux Desktop HIGH 7.5
CVE-2018-15967EPSS 8%

Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information discl…

Fix: after 31.0.0.108
Fix from $1,950 2018-09-25
Coldfusion MEDIUM 5.3
CVE-2018-15962EPSS 6%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. …

Mitigation only
Fix from $1,600 2018-09-25
Coldfusion HIGH 7.5
CVE-2018-15964EPSS 8%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known v…

Mitigation only
Fix from $1,950 2018-09-25
Samsung Email MEDIUM 5.5
CVE-2018-10498

This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. …

Fix: 5.0.02.16+
Fix from $1,600 2018-09-24
Phonepe MEDIUM 5.3
CVE-2018-17402

The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover the Credit/Debit card number,…

Fix: after 3.3.26
Fix from $1,600 2018-09-23
Sbi Buddy MEDIUM 5.3
CVE-2018-17404

The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow an attacker to sniff private information such as mobile number, P…

No fix yet
Fix from $1,600 2018-09-23
Parcel HIGH 7.5
CVE-2018-14731

An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because the origin of requests is not …

Patch available
Fix from $1,950 2018-09-21
Browserify Hot Module Replacement HIGH 7.5
CVE-2018-14730

An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocke…

No fix yet
Fix from $1,950 2018-09-21
Gitolite MEDIUM 5.5
CVE-2013-7203

gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running git…

Fix: after 3.5.3
Fix from $1,600 2018-09-21
Mesos MEDIUM 5.9
CVE-2018-8023

Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2…

Fix: 1.4.2+
Fix from $1,600 2018-09-21
Db2 MEDIUM 5.5
CVE-2018-1685

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a l…

Mitigation only
Fix from $1,600 2018-09-21
Elasticsearch HIGH 8.8
CVE-2018-3831

Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API…

Fix: 5.6.12 / 6.4.1+
Fix from $1,950 2018-09-19
Elasticsearch MEDIUM 6.5
CVE-2018-3826

In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are …

Fix: after 6.2.4
Fix from $1,600 2018-09-19
Circarlife Scada MEDIUM 5.3
CVE-2018-16671EPSS 9%

An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/…

Fix: 4.3+
Fix from $1,600 2018-09-18
Android MEDIUM 5.5
CVE-2018-11275

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when flashing image using FastbootLib if …

Patch available
Fix from $1,600 2018-09-18
Undertow MEDIUM 5.3
CVE-2018-14642

An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flus…

Patch available
Fix from $1,600 2018-09-18
Webcenter Interaction MEDIUM 5.3
CVE-2018-16959

An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile commun…

Mitigation only
Fix from $1,600 2018-09-18
Hub 2245 222 Firmware MEDIUM 6.5
CVE-2017-14443

An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks …

No fix yet
Fix from $1,600 2018-09-17
Donlinkage MEDIUM 5.4
CVE-2018-17091

An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via a direct request for files/te…

No fix yet
Fix from $1,600 2018-09-16
Supersign Cms HIGH 8.6
CVE-2018-16288EPSS 36%

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

No fix yet
Fix from $1,950 2018-09-14
Maximo Asset Management MEDIUM 5.3
CVE-2018-1698

IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Forc…

Fix: after 7.6.3
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 5.5
CVE-2018-8446

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…

Patch available
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 5.5
CVE-2018-8442

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…

Patch available
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 5.5
CVE-2018-8443

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…

Patch available
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 5.9
CVE-2018-8444EPSS 6%

An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka "W…

Patch available
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 5.5
CVE-2018-8445

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…

Patch available
Fix from $1,600 2018-09-13
Excel MEDIUM 5.5
CVE-2018-8429EPSS 12%

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information…

Patch available
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 5.4
CVE-2018-8434

An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated…

Patch available
Fix from $1,600 2018-09-13
Windows 7 MEDIUM 6.5
CVE-2018-8422EPSS 6%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…

Patch available
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 6.5
CVE-2018-8424EPSS 13%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…

Patch available
Fix from $1,600 2018-09-13