Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 MEDIUM 5.5
CVE-2018-8271

An information disclosure vulnerability exists in Windows when the Windows bowser.sys kernel-mode driver fails to properly handle objects in memory, …

Patch available
Fix from $1,600 2018-09-13
Monstra MEDIUM 5.3
CVE-2018-16977

Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHandler/Resources/Views/Err…

No fix yet
Fix from $1,600 2018-09-12
B315s 22 Firmware MEDIUM 6.5
CVE-2018-7921EPSS 13%

Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this…

No fix yet
Fix from $1,600 2018-09-12
Debian Linux HIGH 7.5
CVE-2018-16948

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables …

Fix: 1.6.23 / 1.8.2+
Fix from $1,950 2018-09-12
Cloud Foundry Elastic Runtime MEDIUM 5.9
CVE-2016-0715

Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote informatio…

Fix: after 1.6.11
Fix from $1,600 2018-09-11
Felcom 250 Firmware CRITICAL 9.8
CVE-2018-16705

FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords.…

No fix yet
Fix from $2,300 2018-09-10
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2016-7061

An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC…

Fix: 7.0.4+
Fix from $1,600 2018-09-10
Openpages Grc Platform MEDIUM 5.5
CVE-2017-1679

IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 13400…

Patch available
Fix from $1,600 2018-09-10
Octoprint CRITICAL 9.1
CVE-2018-16710

OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: th…

Fix: after 1.3.9
Fix from $2,300 2018-09-07
Linux Kernel MEDIUM 6.1
CVE-2018-16658

An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by …

Fix: 4.18.6+
Fix from $1,600 2018-09-07
Xiaomi Miwifi Xiaomi 55dd Firmware HIGH 7.5
CVE-2018-16307

An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to …

No fix yet
Fix from $1,950 2018-09-05
Xbtit MEDIUM 5.3
CVE-2018-15684

An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictable file names, which can lead…

Fix: after 2.5.4
Fix from $1,600 2018-09-05
Ubuntu Linux MEDIUM 5.5
CVE-2018-16539

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to di…

Patch available
Fix from $1,600 2018-09-05
Debian Linux HIGH 8.1
CVE-2018-10927

A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and exec…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Virtualization Host HIGH 7.5
CVE-2018-10911

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Virtualization Host MEDIUM 6.5
CVE-2018-10913

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine t…

Fix: 3.12.14 / 4.1.8+
Fix from $1,600 2018-09-04
Ubuntu Linux MEDIUM 6.5
CVE-2018-16323EPSS 49%

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If …

Fix: 6.9.10-9 / 7.0.8-9+
Fix from $1,600 2018-09-01
Iprint HIGH 7.5
CVE-2018-14902

The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access. This allows an attacker's application t…

No fix yet
Fix from $1,950 2018-08-30
Phpmyfaq MEDIUM 5.3
CVE-2014-6048EPSS 6%

phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.

Fix: 2.8.13+
Fix from $1,600 2018-08-28
Jira MEDIUM 5.3
CVE-2018-13391

The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7…

Fix: 7.6.8 / 7.7.5+
Fix from $1,600 2018-08-28
Platform Symphony MEDIUM 6.5
CVE-2018-1705

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could…

Mitigation only
Fix from $1,600 2018-08-28
Openssh MEDIUM 5.3
CVE-2018-15919

Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system…

Fix: after 7.8
Fix from $1,600 2018-08-28
Openstack HIGH 7.5
CVE-2017-15139

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configura…

Fix: after 12.0.4-7
Fix from $1,950 2018-08-27
Data Master MEDIUM 6.5
CVE-2018-15697

ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For …

Fix: after 3.1.5
Fix from $1,600 2018-08-27
Data Master MEDIUM 6.5
CVE-2018-15698

ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full …

Fix: after 3.1.5
Fix from $1,600 2018-08-27
Joomanager CRITICAL 9.8
CVE-2017-18345

The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an…

Fix: after 2.0.0
Fix from $2,300 2018-08-26
Ip Camera Firmware CRITICAL 9.8
CVE-2018-11653

Information disclosure in Netwave IP camera at //etc/RT2870STA.dat (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive…

No fix yet
Fix from $2,300 2018-08-24
Ip Camera Firmware HIGH 7.5
CVE-2018-11654

Information disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive info…

No fix yet
Fix from $1,950 2018-08-24
Websphere Application Server MEDIUM 5.9
CVE-2018-1755

IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when…

Patch available
Fix from $1,600 2018-08-24
Ubuntu Linux MEDIUM 6.5
CVE-2018-10919

The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated at…

Fix: 4.6.16 / 4.7.9+
Fix from $1,600 2018-08-22