Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Airmail 3 MEDIUM 5.3
CVE-2018-15668

An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send ar…

Mitigation only
Fix from $1,600 2018-08-21
Ola Money HIGH 7.5
CVE-2018-15661

An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with access…

Mitigation only
Fix from $1,950 2018-08-21
Re Porter 16 Firmware CRITICAL 9.8
CVE-2018-15534EPSS 32%

Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a …

Fix: 7.8.974.20+
Fix from $2,300 2018-08-21
Debian Linux MEDIUM 5.3
CVE-2018-15599

The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validi…

Fix: after 2018.76
Fix from $1,600 2018-08-21
Virtualization MEDIUM 5.5
CVE-2015-5160

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen…

Mitigation only
Fix from $1,600 2018-08-20
Smart Hp Wmt HIGH 7.5
CVE-2018-14079

Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to obtain sensitive information via /Status/SystemStatusRpm.esp.

Mitigation only
Fix from $1,950 2018-08-20
Librehealth Ehr MEDIUM 6.5
CVE-2018-1000645

LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file dis…

Fix: 2.0.0+
Fix from $1,600 2018-08-20
Omero MEDIUM 6.7
CVE-2018-1000635

The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vulnerability in OMERO.server t…

Fix: after 5.4.6
Fix from $1,600 2018-08-20
Omero HIGH 7.2
CVE-2018-1000633

The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the login form a…

Fix: 5.4.7+
Fix from $1,950 2018-08-20
Debian Linux MEDIUM 5.5
CVE-2018-15594

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectr…

Fix: 4.18.1+
Fix from $1,600 2018-08-20
Security Access Manager For Enterprise Single Sign On MEDIUM 5.3
CVE-2017-1732

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attacke…

Patch available
Fix from $1,600 2018-08-17
Esp 200 Firmware MEDIUM 6.5
CVE-2018-15357

An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmware version 1.2.0.

Mitigation only
Fix from $1,600 2018-08-17
Windows 10 MEDIUM 6.5
CVE-2018-8398EPSS 8%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…

Mitigation only
Fix from $1,600 2018-08-15
Windows 10 MEDIUM 6.5
CVE-2018-8394EPSS 8%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…

Mitigation only
Fix from $1,600 2018-08-15
Excel MEDIUM 5.5
CVE-2018-8382EPSS 12%

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information…

Patch available
Fix from $1,600 2018-08-15
.net Framework HIGH 7.5
CVE-2018-8360EPSS 9%

An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environ…

Patch available
Fix from $1,950 2018-08-15
Core I3 MEDIUM 5.6
CVE-2018-3646EPSS 8%

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in th…

Mitigation only
Fix from $1,600 2018-08-14
Debian Linux HIGH 8.1
CVE-2018-14348

libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.

Fix: after 0.41
Fix from $1,950 2018-08-14
Zipabox Firmware HIGH 7.5
CVE-2018-15125

Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface.

No fix yet
Fix from $1,950 2018-08-13
Openshift Container Platform MEDIUM 5.0
CVE-2017-15138

The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook…

Patch available
Fix from $1,600 2018-08-13
Urbancode Deploy MEDIUM 6.5
CVE-2017-1286

Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has b…

Fix: after 6.9.6.0
Fix from $1,600 2018-08-13
Nwl 25 Firmware HIGH 7.5
CVE-2018-14782

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and pr…

Fix: after 2.0.29.11
Fix from $1,950 2018-08-10
Nwl 25 Firmware HIGH 7.5
CVE-2018-14785

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without a…

Fix: after 2.0.29.11
Fix from $1,950 2018-08-10
Edirectory HIGH 7.5
CVE-2018-7686

Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.

Fix: after 9.1.1
Fix from $1,950 2018-08-09
Openstack HIGH 7.5
CVE-2018-10915EPSS 5%

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections…

Patch available
Fix from $1,950 2018-08-09
Compute Systems Manager HIGH 7.5
CVE-2018-14735

An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of mes…

Fix: 8.6.0-02 / 8.6.1-02+
Fix from $1,950 2018-08-09
Linux Kernel MEDIUM 5.5
CVE-2018-5953

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by re…

Fix: after 4.14.14
Fix from $1,600 2018-08-07
Linux Kernel MEDIUM 5.5
CVE-2018-5995

The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by …

Fix: after 4.14.14
Fix from $1,600 2018-08-07
PHP HIGH 7.5
CVE-2018-15132EPSS 5%

An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The link…

Fix: 5.6.37 / 7.0.31+
Fix from $1,950 2018-08-07
Email Extension MEDIUM 5.3
CVE-2017-2654

jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically…

Fix: 2.57.1+
Fix from $1,600 2018-08-06