Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Sametime MEDIUM 5.3
CVE-2012-3331

IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID…

Mitigation only
Fix from $1,600 2018-02-08
Z Blogphp MEDIUM 5.3
CVE-2018-6846

Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.

Mitigation only
Fix from $1,600 2018-02-08
Email Security Appliance Firmware MEDIUM 6.5
CVE-2018-0140

A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated…

Mitigation only
Fix from $1,600 2018-02-08
Rv132w Firmware CRITICAL 9.8
CVE-2018-0127EPSS 77%

A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unau…

Mitigation only
Fix from $2,300 2018-02-08
Mobility Services Engine MEDIUM 5.3
CVE-2018-0134

A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subs…

Mitigation only
Fix from $1,600 2018-02-08
Websphere Mq HIGH 7.5
CVE-2018-1388

GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.

Mitigation only
Fix from $1,950 2018-02-07
Marked 2 MEDIUM 6.5
CVE-2018-6806

Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview…

Fix: after 2.5.11
Fix from $1,600 2018-02-07
Plasma Workspace MEDIUM 5.3
CVE-2018-6790

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover …

Fix: 5.12.0+
Fix from $1,600 2018-02-07
Web2py MEDIUM 5.5
CVE-2016-3954

web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: t…

Fix: 2.14.2+
Fix from $1,600 2018-02-06
Sandstorm MEDIUM 6.5
CVE-2017-6200

Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is…

Fix: 0.203+
Fix from $1,600 2018-02-06
Jlike HIGH 7.5
CVE-2018-6610EPSS 8%

Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.

No fix yet
Fix from $1,950 2018-02-05
FreeBSD HIGH 7.8
CVE-2015-1418

The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1…

Mitigation only
Fix from $1,950 2018-02-05
Django HIGH 7.5
CVE-2018-6188

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensiti…

Patch available
Fix from $1,950 2018-02-05
Debian Linux CRITICAL 9.1
CVE-2018-6596

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al…

Fix: 1.2.1+
Fix from $2,300 2018-02-03
Tririga Application Platform HIGH 7.5
CVE-2016-0312

IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated…

Fix: after 3.3.1
Fix from $1,950 2018-02-02
Mantisbt MEDIUM 5.3
CVE-2018-6526

view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parame…

Fix: after 2.10.0
Fix from $1,600 2018-02-02
Cloud Foundry Uaa HIGH 8.8
CVE-2018-1192

In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x version…

Fix: 1.7 / 4.5.5+
Fix from $1,950 2018-02-01
Evergreen MEDIUM 6.5
CVE-2015-2203

Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by l…

Patch available
Fix from $1,600 2018-02-01
Evergreen HIGH 7.5
CVE-2015-2204

Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensit…

Fix: 2.5.9 / 2.6.7+
Fix from $1,950 2018-02-01
Evergreen MEDIUM 6.5
CVE-2013-7435

The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive setting…

Fix: 2.5.9 / 2.6.7+
Fix from $1,600 2018-02-01
Nibbleblog MEDIUM 5.3
CVE-2018-6470

Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.

Mitigation only
Fix from $1,600 2018-02-01
Hotspot Shield HIGH 7.5
CVE-2018-6460EPSS 11%

Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including …

No fix yet
Fix from $1,950 2018-01-31
Linux Kernel HIGH 7.5
CVE-2018-6412

In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary…

Fix: after 4.15
Fix from $1,950 2018-01-31
Cognos Analytics MEDIUM 5.5
CVE-2017-1784

IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-…

Patch available
Fix from $1,600 2018-01-29
Jtag Members Directory HIGH 7.5
CVE-2018-6008EPSS 37%

Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.

No fix yet
Fix from $1,950 2018-01-29
Email Subscribers \& Newsletters HIGH 7.5
CVE-2018-6015

An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=e…

Fix: 3.4.8+
Fix from $1,950 2018-01-26
Linux Kernel MEDIUM 5.5
CVE-2018-5750

The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information…

Fix: after 4.14.15
Fix from $1,600 2018-01-26
Script Security MEDIUM 6.5
CVE-2017-1000505

In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coerc…

Fix: after 1.36
Fix from $1,600 2018-01-25
Telecontrol Server Basic MEDIUM 5.3
CVE-2018-4835

A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/t…

Fix: 3.1+
Fix from $1,600 2018-01-25
Filehub Firmware HIGH 7.5
CVE-2018-5319EPSS 12%

RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request.

No fix yet
Fix from $1,950 2018-01-24