Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Dgn2200 Firmware CRITICAL 9.8
CVE-2016-5649EPSS 24%

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_…

No fix yet
Fix from $2,300 2018-07-24
Jira MEDIUM 5.9
CVE-2017-18104

The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to ob…

Fix: 7.6.7 / 7.11.0+
Fix from $1,600 2018-07-24
Online Trade CRITICAL 9.8
CVE-2018-14328EPSS 11%

Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct r…

No fix yet
Fix from $2,300 2018-07-23
October HIGH 8.1
CVE-2018-1999009

October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents fun…

Mitigation only
Fix from $1,950 2018-07-23
Sterling File Gateway HIGH 7.8
CVE-2017-1544

IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be…

Fix: after 2.2.6
Fix from $1,950 2018-07-20
Sterling File Gateway MEDIUM 5.3
CVE-2018-1398

IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X…

Fix: after 2.2.6
Fix from $1,600 2018-07-20
Sterling B2b Integrator MEDIUM 6.7
CVE-2018-1564

IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to obtain user passwords found …

Fix: after 5.2.6.3
Fix from $1,600 2018-07-20
Sterling B2b Integrator MEDIUM 5.3
CVE-2018-1679

IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive information that could be used…

Fix: after 5.2.6.3
Fix from $1,600 2018-07-20
Ubuntu Linux CRITICAL 9.8
CVE-2016-10727

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containin…

Fix: 3.21.2+
Fix from $2,300 2018-07-20
Qradar Security Information And Event Manager MEDIUM 5.8
CVE-2018-1612EPSS 57%

IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information.…

Fix: after 7.2.8
Fix from $1,600 2018-07-17
C4 Professional Firmware HIGH 7.5
CVE-2018-13860

MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18 allows unauthorized remote attack…

Mitigation only
Fix from $1,950 2018-07-17
Teamviewer HIGH 8.1
CVE-2018-14333

TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] and "[00 00 00]" delimiters, w…

Fix: after 13.1.1548
Fix from $1,950 2018-07-17
Debian Linux HIGH 7.5
CVE-2018-10857

git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex reposi…

Mitigation only
Fix from $1,950 2018-07-16
Debian Linux HIGH 7.5
CVE-2018-10859

git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypti…

Mitigation only
Fix from $1,950 2018-07-16
Application Policy Infrastructure Controller Enterprise Module HIGH 7.8
CVE-2018-0368

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an…

Mitigation only
Fix from $1,950 2018-07-16
Lotus Notes HIGH 7.0
CVE-2013-0522

The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover pas…

Mitigation only
Fix from $1,950 2018-07-16
Network Operating System MEDIUM 5.3
CVE-2013-0570

The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating …

Mitigation only
Fix from $1,600 2018-07-13
Ftp Server MEDIUM 5.3
CVE-2016-9499EPSS 8%

Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use t…

No fix yet
Fix from $1,600 2018-07-13
Itrackeasy HIGH 7.8
CVE-2016-6546

The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The bas…

No fix yet
Fix from $1,950 2018-07-13
Nut Mobile HIGH 7.8
CVE-2016-6547

The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file.

No fix yet
Fix from $1,950 2018-07-13
Nut Mobile CRITICAL 9.8
CVE-2016-6548

The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. A…

No fix yet
Fix from $2,300 2018-07-13
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2017-1367

IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead…

Fix: after 5.2.3.2
Fix from $1,600 2018-07-13
Security Identity Governance And Intelligence MEDIUM 5.9
CVE-2017-1395

IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information…

Fix: after 5.2.3.2
Fix from $1,600 2018-07-13
Komoot HIGH 7.4
CVE-2017-14709

The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 cert…

Fix: 9.3.2+
Fix from $1,950 2018-07-12
Spark MEDIUM 5.4
CVE-2018-8024EPSS 5%

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's j…

Fix: after 2.2.1
Fix from $1,600 2018-07-12
Cf Release MEDIUM 5.9
CVE-2016-0708

Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limit…

Fix: after 227
Fix from $1,600 2018-07-11
Inotes HIGH 7.5
CVE-2013-0589

IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive i…

Patch available
Fix from $1,950 2018-07-11
Windows Calendar MEDIUM 6.5
CVE-2018-8305EPSS 8%

An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client Information Disclosure Vulne…

Mitigation only
Fix from $1,600 2018-07-11
Xeon E3 HIGH 7.6
CVE-2018-3652

Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable p…

Mitigation only
Fix from $1,950 2018-07-10
Moodle MEDIUM 5.3
CVE-2018-10890

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidd…

Fix: 3.1.13 / 3.3.7+
Fix from $1,600 2018-07-10