Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Ghostscript MEDIUM 5.3
CVE-2018-11645

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine…

Fix: after 9.20
Fix from $1,600 2018-06-01
Express Restify Mongoose HIGH 8.8
CVE-2016-10533

express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3…

Fix: after 3.0.1
Fix from $1,950 2018-05-31
Hapi MEDIUM 5.3
CVE-2015-9236

Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allo…

Fix: 11.0.0+
Fix from $1,600 2018-05-31
Bittorrent Dht HIGH 7.5
CVE-2016-10519

A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a listening peer and get it to…

Fix: 5.1.3+
Fix from $1,950 2018-05-31
Airbrake MEDIUM 5.9
CVE-2016-10530

The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys …

Fix: after 0.3.8
Fix from $1,600 2018-05-31
Vsz Firmware CRITICAL 9.1
CVE-2018-11036

Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and …

Mitigation only
Fix from $2,300 2018-05-31
Mahara MEDIUM 5.3
CVE-2018-11565

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by pe…

Fix: 17.04.8 / 17.10.5+
Fix from $1,600 2018-05-30
Libmobi MEDIUM 6.5
CVE-2018-11435

The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access vi…

No fix yet
Fix from $1,600 2018-05-30
Libmobi MEDIUM 6.5
CVE-2018-11437

The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) v…

No fix yet
Fix from $1,600 2018-05-30
Mysqljs HIGH 7.5
CVE-2017-16047

mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-05-29
Tkinter HIGH 7.5
CVE-2017-16061

tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-05-29
Node Tkinter HIGH 7.5
CVE-2017-16062

node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-05-29
Data Science Studio MEDIUM 5.3
CVE-2018-10732

The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of …

Fix: 4.2.3+
Fix from $1,600 2018-05-28
Mypro MEDIUM 5.3
CVE-2018-11517

mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t…

No fix yet
Fix from $1,600 2018-05-28
Linux Kernel MEDIUM 5.5
CVE-2018-11508

The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel mem…

Fix: 4.16.9+
Fix from $1,600 2018-05-28
Werewolf Online HIGH 7.5
CVE-2018-11505EPSS 9%

The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.

No fix yet
Fix from $1,950 2018-05-26
Fortios MEDIUM 5.3
CVE-2017-14185

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to ac…

Fix: after 5.6.2
Fix from $1,600 2018-05-25
Antivirus\+ MEDIUM 5.5
CVE-2018-6234

An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose s…

Fix: after 12.0
Fix from $1,600 2018-05-25
Ubuntu Linux MEDIUM 5.9
CVE-2018-11469

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to ac…

Fix: after 1.8.9
Fix from $1,600 2018-05-25
Storwize Unified V7000 Software HIGH 7.5
CVE-2018-1467

The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. IBM X-Force ID: 140398.

Mitigation only
Fix from $1,950 2018-05-25
Moodle MEDIUM 6.5
CVE-2018-1135

An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by chan…

Fix: after 3.4.2
Fix from $1,600 2018-05-25
Tivoli Application Dependency Discovery Manager MEDIUM 5.3
CVE-2013-3018

The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote at…

Fix: after 7.2.1.4
Fix from $1,600 2018-05-24
Tivoli Application Dependency Discovery Manager HIGH 8.1
CVE-2013-3023

IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive informat…

Fix: after 7.2.1.4
Fix from $1,950 2018-05-24
Xenmobile Server HIGH 7.5
CVE-2018-10652

There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.

No fix yet
Fix from $1,950 2018-05-23
Sysinfo MEDIUM 5.5
CVE-2018-7268

MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in whic…

Fix: 10-h81+
Fix from $1,600 2018-05-21
Digital Editions HIGH 7.5
CVE-2018-4925

Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploitation could lead to informati…

Fix: after 4.5.7
Fix from $1,950 2018-05-19
Tectonic HIGH 7.5
CVE-2018-5256

CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ w…

Fix: 1.7.9-tectonic.4 / 1.8.4-tectonic.3+
Fix from $1,950 2018-05-18
Storwize V7000 Firmware HIGH 7.5
CVE-2018-1433

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Storwize V7000 Firmware HIGH 7.5
CVE-2018-1438

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,950 2018-05-17
Storwize V7000 Firmware MEDIUM 6.5
CVE-2018-1464

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17