Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Foxit Reader MEDIUM 6.5
CVE-2017-14820

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-14821

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20
Foxit Reader MEDIUM 6.5
CVE-2017-14822

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interactio…

Patch available
Fix from $1,600 2017-12-20
Blogotext HIGH 7.5
CVE-2017-17793

Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a fil…

Fix: after 3.7.6
Fix from $1,950 2017-12-20
Paid To Read Script MEDIUM 5.3
CVE-2017-17776

Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.

No fix yet
Fix from $1,600 2017-12-20
Lantime Firmware MEDIUM 6.5
CVE-2017-16786

The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to …

Fix: after 6.24.003
Fix from $1,600 2017-12-19
Sling Authentication Service HIGH 8.8
CVE-2017-15700

A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the…

Mitigation only
Fix from $1,950 2017-12-18
Enterprise Linux HIGH 7.8
CVE-2017-15104

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv…

Mitigation only
Fix from $1,950 2017-12-18
Cms Made Simple CRITICAL 9.8
CVE-2017-17734

CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.

Fix: 2.2.5+
Fix from $2,300 2017-12-18
Cms Made Simple CRITICAL 9.8
CVE-2017-17735

CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.

Fix: 2.2.5+
Fix from $2,300 2017-12-18
Camera Firmware CRITICAL 9.8
CVE-2017-3185

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to proces…

Mitigation only
Fix from $2,300 2017-12-16
Pandora HIGH 8.1
CVE-2017-3194

Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to con…

Fix: 8.3.2+
Fix from $1,950 2017-12-16
Forticlient HIGH 8.8
CVE-2017-14184

An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below version…

Fix: 4.4.2334 / 5.6.0+
Fix from $1,950 2017-12-15
Adaptive Security Appliance 5505 Firmware MEDIUM 5.9
CVE-2017-12373EPSS 13%

A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unau…

Mitigation only
Fix from $1,600 2017-12-15
Synaptics Touchpad Driver MEDIUM 5.1
CVE-2017-17556

A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by…

Mitigation only
Fix from $1,600 2017-12-15
Lantime Firmware MEDIUM 6.5
CVE-2017-16787EPSS 7%

The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging…

Fix: 6.24.004+
Fix from $1,600 2017-12-15
Fortios HIGH 7.2
CVE-2017-7738

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_adm…

Fix: after 5.6.2
Fix from $1,950 2017-12-13
Application Delivery Controller Firmware MEDIUM 5.9
CVE-2017-17549

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.1…

Mitigation only
Fix from $1,600 2017-12-13
Office MEDIUM 6.5
CVE-2017-11939EPSS 6%

Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permi…

Patch available
Fix from $1,600 2017-12-12
Chakracore MEDIUM 5.3
CVE-2017-11919EPSS 6%

ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and…

Fix: 1.7.5+
Fix from $1,600 2017-12-12
Windows 10 MEDIUM 6.5
CVE-2017-11927EPSS 10%

Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi…

Patch available
Fix from $1,600 2017-12-12
Office MEDIUM 5.5
CVE-2017-11934EPSS 13%

Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certa…

Patch available
Fix from $1,600 2017-12-12
Hana Database MEDIUM 5.3
CVE-2017-16687

The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00,…

Mitigation only
Fix from $1,600 2017-12-12
Connections MEDIUM 5.3
CVE-2017-1613

IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center …

Mitigation only
Fix from $1,600 2017-12-11
Stemosaur Firmware MEDIUM 5.9
CVE-2017-8865

Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections against capture-replay attacks, all…

Fix: after 0.0.794
Fix from $1,600 2017-12-11
Puppet Enterprise MEDIUM 6.5
CVE-2015-8470

The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes i…

Fix: after 2015.2.3
Fix from $1,600 2017-12-11
Experience Manager HIGH 7.5
CVE-2017-3111EPSS 7%

An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstance…

Mitigation only
Fix from $1,950 2017-12-09
Acrobat MEDIUM 6.5
CVE-2017-16369EPSS 7%

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and ear…

Fix: after 17.012.20098
Fix from $1,600 2017-12-09
Digital Editions MEDIUM 5.5
CVE-2017-11273

An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. Adobe Digital Editions parses crafted XML files in an unsafe manner, wh…

Fix: after 4.5.6
Fix from $1,600 2017-12-09
Debian Linux MEDIUM 6.5
CVE-2017-16854

In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a custo…

Fix: after 6.0.1
Fix from $1,600 2017-12-08