Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Zktime Web HIGH 7.5
CVE-2017-14680

ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.

No fix yet
Fix from $1,950 2017-09-21
Android MEDIUM 5.5
CVE-2017-10996

In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str…

Fix: after 8.0
Fix from $1,600 2017-09-21
Android MEDIUM 5.5
CVE-2017-11001

In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of b…

Fix: after 8.0
Fix from $1,600 2017-09-21
Android MEDIUM 5.5
CVE-2017-11040

In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it …

Fix: after 8.0
Fix from $1,600 2017-09-21
Freeipa CRITICAL 9.8
CVE-2015-5284

ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.

Fix: after 4.2.1
Fix from $2,300 2017-09-21
Chef HIGH 7.5
CVE-2015-8559

The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.

Fix: 15.4.45+
Fix from $1,950 2017-09-21
Iterm2 HIGH 7.5
CVE-2015-9231

iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature was added to iTerm2 version 3.0…

Patch available
Fix from $1,950 2017-09-20
Simple Ads Manager MEDIUM 5.3
CVE-2015-2826EPSS 13%

WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.

No fix yet
Fix from $1,600 2017-09-20
Wifi Repeater Firmware HIGH 7.5
CVE-2017-8770EPSS 10%

There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a craft…

No fix yet
Fix from $1,950 2017-09-20
Realpresence Resource Manager MEDIUM 6.5
CVE-2015-4682EPSS 5%

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST reques…

Fix: after 8.3.2
Fix from $1,600 2017-09-19
Jboss Enterprise Application Platform MEDIUM 5.9
CVE-2015-1849

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vect…

Fix: after 6.4.0
Fix from $1,600 2017-09-19
Edeploy CRITICAL 9.8
CVE-2014-8174

eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.

Fix: after 1.11.0
Fix from $2,300 2017-09-19
Netsweeper HIGH 7.5
CVE-2014-9616

Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that…

Fix: after 3.1.9
Fix from $1,950 2017-09-19
Tomcat HIGH 7.5
CVE-2017-12616EPSS 71%

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs …

Mitigation only
Fix from $1,950 2017-09-19
Android MEDIUM 6.5
CVE-2017-0783

A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.…

Patch available
Fix from $1,600 2017-09-14
Android MEDIUM 6.5
CVE-2017-0785EPSS 12%

A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.…

Patch available
Fix from $1,600 2017-09-14
Fastly MEDIUM 6.5
CVE-2017-13761

The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtai…

Fix: after 1.2.25
Fix from $1,600 2017-09-14
Jazz Reporting Service MEDIUM 5.3
CVE-2017-1490

An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.

Patch available
Fix from $1,600 2017-09-14
Kubernetes MEDIUM 6.5
CVE-2017-1002100

Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "contain…

Patch available
Fix from $1,600 2017-09-14
Eyesofnetwork HIGH 7.5
CVE-2017-14404

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows local file inclusion via the tool_list parameter (aka the url_tool variable) to module/tool…

No fix yet
Fix from $1,950 2017-09-13
Windows 7 MEDIUM 5.5
CVE-2017-8680

The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

Patch available
Fix from $1,600 2017-09-13
Windows 10 MEDIUM 5.5
CVE-2017-8681

The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT…

Patch available
Fix from $1,600 2017-09-13
Windows 10 MEDIUM 5.5
CVE-2017-8683EPSS 23%

Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Window…

Patch available
Fix from $1,600 2017-09-13
Windows 7 MEDIUM 5.5
CVE-2017-8684

Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1, allows…

Patch available
Fix from $1,600 2017-09-13
Windows 10 MEDIUM 5.5
CVE-2017-8687

The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT…

Patch available
Fix from $1,600 2017-09-13
Windows 10 MEDIUM 5.5
CVE-2017-8688

Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10…

Patch available
Fix from $1,600 2017-09-13
Live Meeting MEDIUM 5.3
CVE-2017-8695EPSS 10%

Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windo…

Patch available
Fix from $1,600 2017-09-13
Windows 10 MEDIUM 5.3
CVE-2017-8706

The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabil…

Patch available
Fix from $1,600 2017-09-13
Windows 10 MEDIUM 5.3
CVE-2017-8707

The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1…

Patch available
Fix from $1,600 2017-09-13
Windows 10 MEDIUM 5.3
CVE-2017-8711

The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to pr…

Patch available
Fix from $1,600 2017-09-13