Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Rational Collaborative Lifecycle Management MEDIUM 6.5
CVE-2018-1423

IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the syst…

Fix: after 6.0.5
Fix from $1,600 2018-07-10
Directory Ldap Api CRITICAL 9.8
CVE-2018-1337EPSS 5%

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before…

Fix: 1.0.2+
Fix from $2,300 2018-07-10
Acrobat Dc HIGH 7.5
CVE-2018-4993EPSS 87%

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft …

Fix: after 18.011.20038
Fix from $1,950 2018-07-09
Acrobat Dc HIGH 7.5
CVE-2018-4965EPSS 10%

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Memory Corruption vul…

Fix: 15.006.30418 / 17.011.30080+
Fix from $1,950 2018-07-09
Trackr Bravo Firmware HIGH 8.8
CVE-2016-6538

The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, versio…

Fix: 2.2.5 / 5.1.6+
Fix from $1,950 2018-07-06
Trackr Bravo Firmware MEDIUM 6.5
CVE-2016-6540

Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by usi…

Fix: 2.2.5 / 5.1.6+
Fix from $1,600 2018-07-06
Android HIGH 7.8
CVE-2017-15851

Lack of copy_from_user and information leak in function "msm_ois_subdev_do_ioctl, file msm_ois.c can lead to a camera crash in all Android releases(A…

Mitigation only
Fix from $1,950 2018-07-06
Mdm9206 Firmware HIGH 7.5
CVE-2018-5892

The Touch Pal application can collect user behavior data without awareness by the user in Snapdragon Mobile and Snapdragon Wear.

No fix yet
Fix from $1,950 2018-07-06
Api Connect MEDIUM 5.9
CVE-2018-1546

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP …

Fix: after 5.0.8.3
Fix from $1,600 2018-07-06
Rational Quality Manager MEDIUM 5.3
CVE-2017-1239

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID:…

Fix: after 6.0.5
Fix from $1,600 2018-07-06
Rational Collaborative Lifecycle Management MEDIUM 5.3
CVE-2017-1488

An undisclosed vulnerability in Jazz common products exists with potential for information disclosure. IBM X-Force ID: 128627.

Fix: after 6.0.5
Fix from $1,600 2018-07-06
Open Xchange Appsuite MEDIUM 6.5
CVE-2018-9998

Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names i…

Fix: after 7.6.3
Fix from $1,600 2018-07-05
Singularity MEDIUM 6.5
CVE-2018-12021

Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, …

Fix: after 2.5.1
Fix from $1,600 2018-07-05
Fortios HIGH 8.1
CVE-2018-9185

An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file…

Fix: after 6.0.0
Fix from $1,950 2018-07-05
Onefilecms CRITICAL 9.8
CVE-2018-13123

onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&…

Fix: after 2017-10-09
Fix from $2,300 2018-07-03
2090 Carelink Programmer Firmware HIGH 7.1
CVE-2018-10596

Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected…

Mitigation only
Fix from $1,950 2018-07-03
Debian Linux CRITICAL 9.9
CVE-2018-12892

An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl…

Fix: after 4.10.1
Fix from $2,300 2018-07-02
Phpwcms MEDIUM 5.3
CVE-2018-12990

phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

No fix yet
Fix from $1,600 2018-06-30
Firewall Analyzer HIGH 7.5
CVE-2018-12997EPSS 7%

Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before bui…

No fix yet
Fix from $1,950 2018-06-29
Brickstream 2300 Firmware HIGH 7.5
CVE-2018-12920

Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or bas…

Mitigation only
Fix from $1,950 2018-06-28
Gaugetech Nexus Firmware HIGH 7.5
CVE-2018-12921

Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_info…

No fix yet
Fix from $1,950 2018-06-28
Ha Bridge HIGH 7.5
CVE-2018-12923

BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request for the #!/system URI.

Mitigation only
Fix from $1,950 2018-06-28
Pharos Firmware HIGH 7.5
CVE-2018-12926

Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/…

Mitigation only
Fix from $1,950 2018-06-28
Northern Electric \& Power Inverter Firmware HIGH 7.5
CVE-2018-12927

Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/…

Mitigation only
Fix from $1,950 2018-06-28
Pluto HIGH 7.5
CVE-2018-1306EPSS 44%

The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive i…

No fix yet
Fix from $1,950 2018-06-27
Websphere Application Server HIGH 7.5
CVE-2018-1553

IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of ex…

Fix: 18.0.0.2+
Fix from $1,950 2018-06-27
Brynamics CRITICAL 9.8
CVE-2018-12908EPSS 11%

Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct r…

No fix yet
Fix from $2,300 2018-06-27
Spotfire Analytics Platform For Aws HIGH 8.8
CVE-2018-5436

The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multi…

Fix: after 7.12.0
Fix from $1,950 2018-06-27
Rclone HIGH 7.5
CVE-2018-12907

In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of an…

Mitigation only
Fix from $1,950 2018-06-27
Websphere Application Server HIGH 7.5
CVE-2018-1614

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker …

Mitigation only
Fix from $1,950 2018-06-26