Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Msm8909w Firmware HIGH 7.5
CVE-2015-9169

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400…

Mitigation only
Fix from $1,950 2018-04-18
Mdm9206 Firmware HIGH 7.5
CVE-2015-9119

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MD…

Mitigation only
Fix from $1,950 2018-04-18
Mdm9206 Firmware HIGH 7.5
CVE-2015-9123

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, IPQ4019, MDM…

Mitigation only
Fix from $1,950 2018-04-18
Mdm9206 Firmware HIGH 7.5
CVE-2014-10062

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, MS…

Mitigation only
Fix from $1,950 2018-04-18
Sd 400 Firmware HIGH 7.5
CVE-2014-10047

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, when writing the Full Disk Encryption k…

Mitigation only
Fix from $1,950 2018-04-18
Sd 400 Firmware HIGH 7.5
CVE-2014-10055

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, there could be leakage of protected con…

Mitigation only
Fix from $1,950 2018-04-18
Mautic HIGH 7.5
CVE-2018-10189

An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking th…

Fix: 2.13.0+
Fix from $1,950 2018-04-17
Jasperreports Server HIGH 8.8
CVE-2018-5430 KEVEPSS 50%

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server fo…

Fix: after 6.4.2
Fix from $1,950 2018-04-17
Fromdoctopdf MEDIUM 5.3
CVE-2018-10178

The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisited…

Fix: 13.611.13.2303+
Fix from $1,600 2018-04-17
Dir 815 Firmware CRITICAL 9.8
CVE-2018-10106

D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdo…

Fix: after 2.07.b01
Fix from $2,300 2018-04-16
Jenkins MEDIUM 5.3
CVE-2018-1000169

An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler…

Fix: after 2.107.1
Fix from $1,600 2018-04-16
Mediawiki MEDIUM 5.3
CVE-2014-1686

MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.

No fix yet
Fix from $1,600 2018-04-16
Debian Linux HIGH 7.8
CVE-2017-0361

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.

Fix: 1.27.2 / 1.28.1+
Fix from $1,950 2018-04-13
Cms Made Simple MEDIUM 5.3
CVE-2018-10082

CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact…

Fix: after 2.2.7
Fix from $1,600 2018-04-13
Dir 815 Firmware CRITICAL 9.8
CVE-2015-0152

D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the ad…

Fix: 2.07.b01+
Fix from $2,300 2018-04-12
Debian Linux HIGH 7.5
CVE-2018-1086

pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th…

Mitigation only
Fix from $1,950 2018-04-12
Kaazing Websocket Gateway HIGH 7.5
CVE-2014-6309

The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 a…

Mitigation only
Fix from $1,950 2018-04-12
Kaazing Gateway HIGH 7.5
CVE-2017-6910

The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 …

Fix: 4.4.2 / 4.5.3+
Fix from $1,950 2018-04-12
Password Vault MEDIUM 5.3
CVE-2018-9842EPSS 16%

CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.

Fix: 9.7+
Fix from $1,600 2018-04-12
Junos MEDIUM 5.9
CVE-2018-0018

On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to bypass firewall rules, leading…

Patch available
Fix from $1,600 2018-04-11
Joyplus Cms MEDIUM 5.3
CVE-2018-10028

joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.

Mitigation only
Fix from $1,600 2018-04-11
Mate 9 Firmware MEDIUM 5.7
CVE-2018-7930

The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C567) has an information leak vu…

Mitigation only
Fix from $1,600 2018-04-11
Mdm9206 Firmware HIGH 7.5
CVE-2017-18072

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6…

Mitigation only
Fix from $1,950 2018-04-11
Websphere Mq MEDIUM 5.3
CVE-2015-1957

IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-mid…

Fix: 7.5.0.6 / 8.0.0.3+
Fix from $1,600 2018-04-10
Open Xchange Appsuite MEDIUM 5.3
CVE-2014-2078

The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses …

Mitigation only
Fix from $1,600 2018-04-10
Security Siteprotector System HIGH 7.5
CVE-2015-0172

IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unsp…

No fix yet
Fix from $1,950 2018-04-10
Icms MEDIUM 5.3
CVE-2018-9922

An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weix…

Fix: after 7.0.7
Fix from $1,600 2018-04-10
Gxlcms Qy CRITICAL 9.8
CVE-2018-9852

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embedding a FROM clause in a…

No fix yet
Fix from $2,300 2018-04-08
Etherpad HIGH 7.5
CVE-2018-9325

Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.

Fix: 1.6.4+
Fix from $1,950 2018-04-07
Ft1 Firmware MEDIUM 5.9
CVE-2014-2359

OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or spoof devices by reading clear…

Mitigation only
Fix from $1,600 2018-04-06