Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Hilink MEDIUM 5.5
CVE-2017-2732

Huawei Hilink APP Versions earlier before 5.0.25.306 has an information leak vulnerability. An attacker may trick a user into installing a malicious …

Fix: 5.0.25.306+
Fix from $1,600 2017-11-22
Honor 6x Firmware MEDIUM 5.5
CVE-2017-2733

Honor 6X smartphones with software versions earlier than BLN-AL10C00B357 and versions earlier than BLN-AL20C00B357 have an information leak vulnerabi…

Mitigation only
Fix from $1,600 2017-11-22
Smarthome HIGH 7.5
CVE-2017-2704

Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.…

Fix: after 8.1.2.300
Fix from $1,950 2017-11-22
PostgreSQL MEDIUM 6.5
CVE-2017-15099EPSS 6%

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that th…

Mitigation only
Fix from $1,600 2017-11-22
PostgreSQL HIGH 8.1
CVE-2017-15098

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9…

Mitigation only
Fix from $1,950 2017-11-22
3960hd Firmware MEDIUM 6.5
CVE-2017-8860

Information disclosure through directory listing on the Cohu 3960HD allows an attacker to view and download source code, log files, and other sensiti…

Mitigation only
Fix from $1,600 2017-11-22
3960hd Firmware HIGH 7.5
CVE-2017-8863

Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple …

Mitigation only
Fix from $1,950 2017-11-22
Openoffice MEDIUM 5.5
CVE-2017-3157

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from …

Fix: after 4.1.3
Fix from $1,600 2017-11-20
Laravel HIGH 7.5
CVE-2017-16894EPSS 87%

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for…

Fix: after 5.5.21
Fix from $1,950 2017-11-20
Eds G512e Firmware MEDIUM 5.3
CVE-2017-13702

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipulated, and reused.

Mitigation only
Fix from $1,600 2017-11-17
Book Walker MEDIUM 5.5
CVE-2017-10888

BOOK WALKER for Windows Ver.1.2.9 and earlier, BOOK WALKER for Mac Ver.1.2.5 and earlier allow an attacker to access local files via unspecified vect…

Fix: after 1.2.9
Fix from $1,600 2017-11-17
Stop User Enumeration MEDIUM 5.3
CVE-2017-1000226

Stop User Enumeration 1.3.8 allows user enumeration via the REST API

No fix yet
Fix from $1,600 2017-11-17
I\, Librarian MEDIUM 5.3
CVE-2017-1000234

I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker enumerating directories simpl…

Fix: after 4.6
Fix from $1,600 2017-11-17
Tcmu Runner HIGH 7.5
CVE-2017-1000199

tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check …

Mitigation only
Fix from $1,950 2017-11-17
Altavault Ost Plug In MEDIUM 5.5
CVE-2017-15517

AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to mov…

Fix: 1.2.2+
Fix from $1,600 2017-11-17
Android MEDIUM 5.3
CVE-2017-0850

An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A…

Patch available
Fix from $1,600 2017-11-16
Android MEDIUM 5.3
CVE-2017-0851

An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7…

Patch available
Fix from $1,600 2017-11-16
Android HIGH 7.5
CVE-2017-0839

An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.5
CVE-2017-0840

An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7…

Patch available
Fix from $1,950 2017-11-16
Android MEDIUM 5.3
CVE-2017-0848

An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1…

Patch available
Fix from $1,600 2017-11-16
Android MEDIUM 5.3
CVE-2017-0849

An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Andr…

Patch available
Fix from $1,600 2017-11-16
Android HIGH 7.5
CVE-2017-9701

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing OEM unlock/unlock-go…

Patch available
Fix from $1,950 2017-11-16
Android MEDIUM 5.3
CVE-2017-11022

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the probe requests originated from us…

Patch available
Fix from $1,600 2017-11-16
Android HIGH 7.5
CVE-2017-11028

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the ISP Camera driver, the content…

Patch available
Fix from $1,950 2017-11-16
Nport 5110 Firmware HIGH 8.6
CVE-2017-16715

An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, …

Fix: after 3.7
Fix from $1,950 2017-11-16
Unite CRITICAL 9.1
CVE-2017-5738

Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network…

Patch available
Fix from $2,300 2017-11-16
Hyperflex Hx Data Platform MEDIUM 6.0
CVE-2017-12315

A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker t…

Mitigation only
Fix from $1,600 2017-11-16
Sm 2556 Firmware MEDIUM 5.3
CVE-2017-12737

An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The in…

Mitigation only
Fix from $1,600 2017-11-15
Debian Linux HIGH 7.5
CVE-2017-8810

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for fai…

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Windows 10 MEDIUM 5.5
CVE-2017-11853EPSS 11%

Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, a…

Patch available
Fix from $1,600 2017-11-15