Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Nodemailer Js HIGH 7.5
CVE-2017-16071

nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Nodemailer.js HIGH 7.5
CVE-2017-16072

nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Noderequest HIGH 7.5
CVE-2017-16073

noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-07
Security Access Manager MEDIUM 5.3
CVE-2017-1474

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. …

Fix: after 9.0.3.1
Fix from $1,600 2018-06-06
Security Access Manager MEDIUM 5.9
CVE-2017-1476

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive infor…

Fix: after 9.0.3.1
Fix from $1,600 2018-06-06
Gitlab Hook MEDIUM 6.5
CVE-2018-1000196

A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/g…

Fix: after 1.4.2
Fix from $1,600 2018-06-05
GitHub MEDIUM 6.5
CVE-2018-1000183

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers w…

Fix: after 1.29.0
Fix from $1,600 2018-06-05
Github Pull Request Builder MEDIUM 6.5
CVE-2018-1000186

A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that …

Fix: after 1.41.0
Fix from $1,600 2018-06-05
Kubernetes MEDIUM 6.5
CVE-2018-1000187

A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in …

Fix: after 1.7.0
Fix from $1,600 2018-06-05
Black Duck Hub MEDIUM 6.5
CVE-2018-1000190

A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildScanDescriptor.java that allows…

Fix: after 4.0.0
Fix from $1,600 2018-06-05
Synopsys Detect MEDIUM 6.5
CVE-2018-1000191

A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java th…

Fix: after 1.4.0
Fix from $1,600 2018-06-05
Intellivue Mp2 Firmware MEDIUM 5.3
CVE-2018-10599

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M an…

Mitigation only
Fix from $1,600 2018-06-05
Storm MEDIUM 6.5
CVE-2018-1332

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonat…

Fix: after 1.2.1
Fix from $1,600 2018-06-05
Kitura HIGH 7.5
CVE-2018-1000181

Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a crafted URL resulting in informa…

Fix: after 2.3.0
Fix from $1,950 2018-06-05
Yzmcms CRITICAL 9.8
CVE-2018-11554

The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure…

Fix: after 3.7
Fix from $2,300 2018-06-05
Micrologix 1400 B Firmware HIGH 7.5
CVE-2017-12092

An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A sp…

Fix: after 21.2
Fix from $1,950 2018-06-04
D3.js HIGH 7.5
CVE-2017-16044

`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Jquery.js HIGH 7.5
CVE-2017-16045

`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Node Sqlite HIGH 7.5
CVE-2017-16048

`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Nodesqlite HIGH 7.5
CVE-2017-16049

`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Sqlite.js HIGH 7.5
CVE-2017-16050

`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Sqliter HIGH 7.5
CVE-2017-16051

`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Node Fabric HIGH 7.5
CVE-2017-16052

`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Fabric Js HIGH 7.5
CVE-2017-16053

`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Nodefabric HIGH 7.5
CVE-2017-16054

`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Sqlserver HIGH 7.5
CVE-2017-16055

`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
Node.js MEDIUM 6.5
CVE-2017-16024

The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning…

Fix: 0.11.9+
Fix from $1,600 2018-06-04
Node Jose MEDIUM 5.9
CVE-2017-16007

node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jo…

Fix: 0.9.3+
Fix from $1,600 2018-06-04
Mahara MEDIUM 6.8
CVE-2018-11195

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows ma…

Fix: 17.04.8 / 17.10.5+
Fix from $1,600 2018-06-01
Serve MEDIUM 5.3
CVE-2018-3809

Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.

No fix yet
Fix from $1,600 2018-06-01