Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Testlink HIGH 7.5
CVE-2018-7668

TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.

Fix: after 1.9.16
Fix from $1,950 2018-03-05
Couch MEDIUM 5.3
CVE-2018-7662EPSS 47%

Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/php…

Fix: after 2.0
Fix from $1,600 2018-03-04
Wifi Baby Monitor MEDIUM 5.3
CVE-2018-7661

Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests to TCP ports 8258 and 8257.

Fix: 2.02.2+
Fix from $1,600 2018-03-04
Identity Manager HIGH 7.5
CVE-2017-9280

Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of use…

Fix: 4.5.6.1+
Fix from $1,950 2018-03-02
Debian Linux HIGH 7.1
CVE-2017-14461EPSS 17%

A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive info…

Patch available
Fix from $1,950 2018-03-02
Drupal HIGH 8.1
CVE-2017-6926

In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access t…

Fix: 8.4.5+
Fix from $1,950 2018-03-01
Open Build Service HIGH 7.5
CVE-2017-5188

The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director…

Fix: after 2.7.3
Fix from $1,950 2018-03-01
Tririga Application Platform MEDIUM 5.3
CVE-2016-0299

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive informati…

Fix: 3.3.2.6 / 3.4.2.3+
Fix from $1,600 2018-02-28
Debian Linux CRITICAL 9.1
CVE-2018-7556

LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installatio…

Fix: 2.6.7 / 2.73.1+
Fix from $2,300 2018-02-28
Surveillance Station MEDIUM 6.5
CVE-2017-16770

File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.…

Fix: 8.1.2-5469+
Fix from $1,600 2018-02-27
Wireless Ip Camera 360 HIGH 7.5
CVE-2017-11635

An issue was discovered on Wireless IP Camera 360 devices. Attackers can read recordings by navigating to /mnt/idea0 or /mnt/idea1 on the SD memory c…

No fix yet
Fix from $1,950 2018-02-26
Windows 7 MEDIUM 5.5
CVE-2018-7250

An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped i…

Mitigation only
Fix from $1,600 2018-02-26
Security Guardium Big Data Intelligence MEDIUM 5.3
CVE-2017-1774

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount …

Mitigation only
Fix from $1,600 2018-02-26
Geode HIGH 7.5
CVE-2017-15696

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration req…

Fix: after 1.3.0
Fix from $1,950 2018-02-26
Oncommand Api Services HIGH 7.8
CVE-2017-15518

All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password.…

Fix: after 2.0
Fix from $1,950 2018-02-23
Photo Station MEDIUM 5.3
CVE-2017-16769

Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from pa…

Mitigation only
Fix from $1,600 2018-02-23
Proclaim HIGH 7.5
CVE-2018-7317EPSS 8%

Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.

No fix yet
Fix from $1,950 2018-02-22
Quantum Bacnet Integration Firmware HIGH 7.5
CVE-2018-7276

An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain potentially sensitive inform…

No fix yet
Fix from $1,950 2018-02-21
Access Management MEDIUM 6.5
CVE-2018-7272

The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding…

Fix: 5.5.0+
Fix from $1,600 2018-02-21
Linux Kernel MEDIUM 5.5
CVE-2018-7273

In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the fu…

Fix: after 4.15.4
Fix from $1,600 2018-02-21
Universal Cmdb Foundation Software HIGH 7.5
CVE-2018-6487

Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, …

No fix yet
Fix from $1,950 2018-02-20
Netcadops MEDIUM 5.8
CVE-2018-5477

An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior,…

Fix: 7.2.10+
Fix from $1,600 2018-02-20
Alto 3 Firmware MEDIUM 5.3
CVE-2015-9255

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machine…

Mitigation only
Fix from $1,600 2018-02-20
Alto 3 Firmware MEDIUM 5.3
CVE-2015-9256

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not…

Mitigation only
Fix from $1,600 2018-02-20
Photo\,video Locker Calculator HIGH 7.5
CVE-2017-18192

smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to ac…

Fix: after 18.0
Fix from $1,950 2018-02-20
Anchor CRITICAL 9.8
CVE-2018-7251EPSS 72%

An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQ…

No fix yet
Fix from $2,300 2018-02-19
Converse.js MEDIUM 5.3
CVE-2018-6591

Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe p…

Fix: after 3.3
Fix from $1,600 2018-02-19
Idashboards HIGH 7.5
CVE-2018-7209

An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/conf…

Fix: after 9.6b
Fix from $1,950 2018-02-18
Idashboards HIGH 7.5
CVE-2018-7210

An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=i…

Fix: after 9.6b
Fix from $1,950 2018-02-18
Jenkins MEDIUM 5.3
CVE-2018-1000068

An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to acces…

Fix: after 2.106
Fix from $1,600 2018-02-16