Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Cloudforms HIGH 7.5
CVE-2018-3760EPSS 27%

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially craft…

Fix: after 3.7.1
Fix from $1,950 2018-06-26
A1001 Firmware HIGH 7.5
CVE-2018-10663

An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.

Fix: 1.65.0 / 1.65.1+
Fix from $1,950 2018-06-26
GitHub HIGH 8.8
CVE-2018-1000600EPSS 91%

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allow…

Fix: after 1.29.1
Fix from $1,950 2018-06-26
Ssh Credentials MEDIUM 6.5
CVE-2018-1000601

A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers wi…

Fix: after 1.13
Fix from $1,600 2018-06-26
Openstack Cloud HIGH 8.8
CVE-2018-1000603

A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier in BootSource.java, InstancesToRun.java, …

Fix: after 2.35
Fix from $1,950 2018-06-26
Configuration As Code MEDIUM 6.5
CVE-2018-1000609

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java th…

Mitigation only
Fix from $1,600 2018-06-26
Wekan MEDIUM 5.3
CVE-2018-1000549

Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages that can result in A remote…

Mitigation only
Fix from $1,600 2018-06-26
Lms HIGH 7.5
CVE-2018-1000535

lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module that can result in Possible to r…

Fix: after 011123
Fix from $1,950 2018-06-26
Debian Linux HIGH 7.5
CVE-2018-10852

The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can s…

Fix: 1.16.3+
Fix from $1,950 2018-06-26
Basercms MEDIUM 5.3
CVE-2018-0575

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail f…

Fix: after 4.1.0.1
Fix from $1,600 2018-06-26
Smartkey HIGH 7.5
CVE-2018-0584

IIJ SmartKey App for Android version 2.1.0 and earlier allows remote attackers to bypass authentication [effect_of_bypassing_authentication] via unsp…

Fix: after 2.1.0
Fix from $1,950 2018-06-26
Saj Solar Inverter HIGH 7.5
CVE-2018-12735

SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inverter_info.htm or english_main…

Mitigation only
Fix from $1,950 2018-06-25
Civetweb HIGH 7.1
CVE-2018-12684

Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information …

Fix: after 1.10
Fix from $1,950 2018-06-22
Oncommand Unified Manager MEDIUM 5.3
CVE-2017-7568

NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated u…

Fix: 5.2.3+
Fix from $1,600 2018-06-22
Aix MEDIUM 5.5
CVE-2018-1655

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.

Mitigation only
Fix from $1,600 2018-06-22
Circarlife Scada CRITICAL 9.8
CVE-2018-12634EPSS 57%

CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.htm…

Fix: 4.3+
Fix from $2,300 2018-06-22
Redatam MEDIUM 5.3
CVE-2018-12632

Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN parameter to the /redbin/rpwebutil…

Fix: 7+
Fix from $1,600 2018-06-21
Xenserver MEDIUM 5.6
CVE-2018-3665

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to …

Mitigation only
Fix from $1,600 2018-06-21
Mach Prowebcom Firmware HIGH 7.5
CVE-2018-12594

Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct request for the data/fileinfo.xml o…

Mitigation only
Fix from $1,950 2018-06-20
Realpresence Web Suite HIGH 7.5
CVE-2018-12592

Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chos…

Fix: 2.2.0+
Fix from $1,950 2018-06-20
Libfsntfs MEDIUM 5.5
CVE-2018-11727

The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an informati…

Fix: after 20180420
Fix from $1,600 2018-06-19
Libfsntfs MEDIUM 5.5
CVE-2018-11728

The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to …

Fix: after 20180420
Fix from $1,600 2018-06-19
Libfsntfs MEDIUM 5.5
CVE-2018-11729

The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information…

Fix: after 20180420
Fix from $1,600 2018-06-19
Libfsntfs MEDIUM 5.5
CVE-2018-11731

The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an informa…

Fix: after 20180420
Fix from $1,600 2018-06-19
Liblnk MEDIUM 5.5
CVE-2018-12097

The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows remote attackers to cause an …

Fix: after 20180419
Fix from $1,600 2018-06-19
Liblnk MEDIUM 5.5
CVE-2018-12098

The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (h…

Fix: after 20180419
Fix from $1,600 2018-06-19
Virtualization MEDIUM 5.3
CVE-2018-1073

The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an a…

Fix: 4.2.3+
Fix from $1,600 2018-06-19
Zuul CRITICAL 9.8
CVE-2018-12557

An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreach…

Fix: 3.1.0+
Fix from $2,300 2018-06-19
Fedora HIGH 7.5
CVE-2018-1090

In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access …

Fix: 2.16.2+
Fix from $1,950 2018-06-18
Monitoring And Debugging Dashboard MEDIUM 5.3
CVE-2018-12522EPSS 7%

An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing.

No fix yet
Fix from $1,600 2018-06-18