Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Atom C MEDIUM 5.6
CVE-2017-5754EPSS 84%

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an at…

Patch available
Fix from $1,600 2018-01-04
Op Tee HIGH 7.5
CVE-2017-1000412

Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in …

Fix: after 2.4.0
Fix from $1,950 2018-01-02
Op Tee MEDIUM 5.9
CVE-2017-1000413

Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE …

Fix: after 2.4.0
Fix from $1,600 2018-01-02
Brickstream 2300 2d Firmware CRITICAL 9.8
CVE-2018-3813

getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USER_ID and …

No fix yet
Fix from $2,300 2018-01-01
Direct Mail HIGH 7.5
CVE-2013-7400

The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checkin…

Fix: 3.1.2+
Fix from $1,950 2017-12-29
Professional Service Script MEDIUM 5.3
CVE-2017-17926

PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invali…

No fix yet
Fix from $1,600 2017-12-27
Dolibarr Erp\/crm HIGH 7.5
CVE-2017-17898

Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.

Patch available
Fix from $1,950 2017-12-27
Websphere Portal MEDIUM 5.3
CVE-2017-1698

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the s…

Mitigation only
Fix from $1,600 2017-12-27
Icloud MEDIUM 5.9
CVE-2017-13864

An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue i…

Fix: 7.2 / 12.7.2+
Fix from $1,600 2017-12-25
Iphone Os MEDIUM 5.5
CVE-2017-13865

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watch…

Fix: 4.2 / 10.13.2+
Fix from $1,600 2017-12-25
Iphone Os MEDIUM 5.5
CVE-2017-13868

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watch…

Fix: 4.2 / 10.13.2+
Fix from $1,600 2017-12-25
Iphone Os MEDIUM 5.5
CVE-2017-13869

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watch…

Fix: 4.2 / 10.13.2+
Fix from $1,600 2017-12-25
Hg8245h Firmware HIGH 7.5
CVE-2017-15328

Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability. An attacker can access a specific URL of the affect…

Mitigation only
Fix from $1,950 2017-12-22
Internet Browser HIGH 7.5
CVE-2017-17692EPSS 79%

Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript co…

No fix yet
Fix from $1,950 2017-12-21
Cnpilot R190v Firmware HIGH 8.0
CVE-2017-5262

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by …

Fix: after 4.3.2-r4
Fix from $1,950 2017-12-20
Gaps CRITICAL 9.8
CVE-2017-6094

CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS instance. A CPE identifies itself …

Fix: 7.2+
Fix from $2,300 2017-12-20
Security Guardium MEDIUM 5.5
CVE-2017-1596

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM…

Mitigation only
Fix from $1,600 2017-12-20
Websphere Portal MEDIUM 5.3
CVE-2017-1423

IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 1…

Mitigation only
Fix from $1,600 2017-12-20
Security Guardium MEDIUM 5.5
CVE-2017-1595

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM…

Mitigation only
Fix from $1,600 2017-12-20
Debian Linux HIGH 8.8
CVE-2017-17476

Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remo…

Fix: 4.0.28 / 5.0.26+
Fix from $1,950 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-16584

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.2.25013. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-16588

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-16589

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-16573

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-16574

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-16579

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.2.25013. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-16580

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.2.25013. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-10956

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-14818

This vulnerability allows remote attackers to disclose sensitive on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is require…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-14819

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20