Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Storwize V7000 Firmware MEDIUM 5.3
CVE-2018-1465

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6…

Fix: 7.5.0.14 / 7.7.1.9+
Fix from $1,600 2018-05-17
Windows Stemcells MEDIUM 6.5
CVE-2018-1276

Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push…

Fix: 1200.17+
Fix from $1,600 2018-05-17
Fl Switch 3005 Firmware MEDIUM 5.3
CVE-2018-10729

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unaut…

Fix: after 1.33
Fix from $1,600 2018-05-17
Matrikonopc Explorer MEDIUM 6.1
CVE-2018-8714

Honeywell MatrikonOPC OPC Controller before 5.1.0.0 allows local users to transfer arbitrary files from a host computer and consequently obtain sensi…

Fix: 5.1.0.0+
Fix from $1,600 2018-05-17
Foxit Reader MEDIUM 6.5
CVE-2018-9946

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interactio…

Fix: after 9.0.1.1049
Fix from $1,600 2018-05-17
Foxit Reader MEDIUM 6.5
CVE-2018-9948EPSS 64%

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interactio…

Fix: after 9.0.1.1049
Fix from $1,600 2018-05-17
Foxit Reader MEDIUM 6.5
CVE-2018-1174

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interactio…

Fix: after 9.0.1.1049
Fix from $1,600 2018-05-17
Foxit Reader MEDIUM 6.5
CVE-2018-1175

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interactio…

Fix: after 9.0.1.1049
Fix from $1,600 2018-05-17
Edr 810 Firmware HIGH 7.5
CVE-2017-12128EPSS 43%

An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted…

No fix yet
Fix from $1,950 2018-05-14
Exiv2 MEDIUM 6.5
CVE-2018-11037

In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.

No fix yet
Fix from $1,600 2018-05-14
Linux Kernel MEDIUM 5.5
CVE-2018-1118

Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in t…

Fix: 4.18+
Fix from $1,600 2018-05-10
Android MEDIUM 5.3
CVE-2018-6246

In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data…

Fix: after 8.1
Fix from $1,600 2018-05-10
Zimbra Collaboration Suite MEDIUM 5.3
CVE-2018-10950

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through V…

Fix: 8.7.11 / 8.8.8+
Fix from $1,600 2018-05-10
Vgo Firmware MEDIUM 6.5
CVE-2018-8860

In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker may be able to capture firmware updates through the adjacent network.

Fix: 3.0.3.52164+
Fix from $1,600 2018-05-09
Office MEDIUM 6.5
CVE-2018-8160EPSS 9%

An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." Thi…

Patch available
Fix from $1,600 2018-05-09
Excel MEDIUM 5.5
CVE-2018-8163EPSS 13%

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information…

Patch available
Fix from $1,600 2018-05-09
Windows 10 MEDIUM 5.5
CVE-2018-8127

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu…

Patch available
Fix from $1,600 2018-05-09
Chakracore HIGH 7.5
CVE-2018-8145EPSS 67%

An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with info…

Fix: after 1.8.3
Fix from $1,950 2018-05-09
5 In 1 Xvr Firmware CRITICAL 9.8
CVE-2018-10770

download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a login) to discover the password.

No fix yet
Fix from $2,300 2018-05-09
FreeBSD MEDIUM 5.5
CVE-2018-6920

In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient initialization of memory cop…

Fix: 10.4 / 11.1+
Fix from $1,600 2018-05-08
FreeBSD MEDIUM 5.5
CVE-2018-6921

In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to userland in the network subsystem…

Fix: 11.1+
Fix from $1,600 2018-05-08
Email Extension MEDIUM 6.5
CVE-2018-1000176

An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/email…

Fix: after 2.61
Fix from $1,600 2018-05-08
D303 Firmware CRITICAL 9.8
CVE-2018-10734

KONGTOP DVR devices A303, A403, D303, D305, and D403 contain a backdoor that prints the login password via a Print_Password function call in certain …

No fix yet
Fix from $2,300 2018-05-08
Webex Meetings Online MEDIUM 5.3
CVE-2018-0288

A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access sensitive data about the appli…

Mitigation only
Fix from $1,600 2018-05-02
Wireless Lan Controller Software MEDIUM 5.3
CVE-2018-0245

A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker …

Mitigation only
Fix from $1,600 2018-05-02
Secure Firewall Management Center MEDIUM 6.5
CVE-2018-0278

A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data…

Mitigation only
Fix from $1,600 2018-05-02
Openoffice HIGH 7.5
CVE-2018-10583EPSS 79%

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB co…

No fix yet
Fix from $1,950 2018-05-01
Octopus Deploy MEDIUM 5.4
CVE-2018-10581

In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Envir…

Fix: 2018.4.7+
Fix from $1,600 2018-05-01
Cms Made Simple MEDIUM 6.5
CVE-2018-10516

In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerabilit…

Fix: after 2.2.7
Fix from $1,600 2018-04-27
Cms Made Simple MEDIUM 5.3
CVE-2018-10523

CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modul…

Fix: after 2.2.7
Fix from $1,600 2018-04-27