Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 MEDIUM 5.5
CVE-2017-8666

Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold,…

Patch available
Fix from $1,600 2017-08-08
Windows 7 MEDIUM 5.5
CVE-2017-8668

The Volume Manager Extension Driver in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 20…

Patch available
Fix from $1,600 2017-08-08
Apache Authenhook CRITICAL 9.8
CVE-2010-3845

libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.

Patch available
Fix from $2,300 2017-08-08
Myfaces HIGH 7.5
CVE-2011-4343EPSS 5%

Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL express…

Patch available
Fix from $1,950 2017-08-08
Sql Server HIGH 7.5
CVE-2017-8516EPSS 8%

Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information d…

Patch available
Fix from $1,950 2017-08-08
Photo Station HIGH 7.5
CVE-2017-11155EPSS 47%

An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensiti…

Fix: after 6.7.2-3429
Fix from $1,950 2017-08-08
Flexcube Universal Banking MEDIUM 6.5
CVE-2017-10084

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Report Generator). Supporte…

Patch available
Fix from $1,600 2017-08-08
Agile Product Lifecycle Management MEDIUM 5.3
CVE-2017-10093

Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected …

Patch available
Fix from $1,600 2017-08-08
Control Manager HIGH 7.5
CVE-2016-6220

Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.

Patch available
Fix from $1,950 2017-08-07
Leap HIGH 7.5
CVE-2014-3462

The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and addin…

Fix: 1.7.5+
Fix from $1,950 2017-08-07
Adaptive Security Appliance Software HIGH 7.5
CVE-2017-6752

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remote attacker…

Mitigation only
Fix from $1,950 2017-08-07
Sunny Boy 3600 Firmware HIGH 7.5
CVE-2017-9858

An issue was discovered in SMA Solar Technology products. By sending crafted packets to an inverter and observing the response, active and inactive u…

Mitigation only
Fix from $1,950 2017-08-05
Sunny Explorer HIGH 7.5
CVE-2017-9862

An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is possible to create a debug rep…

Mitigation only
Fix from $1,950 2017-08-05
Control Manager HIGH 7.5
CVE-2017-11387EPSS 15%

Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality t…

Patch available
Fix from $1,950 2017-08-02
Netscaler Application Delivery Controller MEDIUM 5.9
CVE-2015-3642

The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x b…

Mitigation only
Fix from $1,600 2017-08-02
Pega Platform MEDIUM 6.5
CVE-2017-11356

The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to o…

Fix: after 7.2_ml0
Fix from $1,600 2017-08-02
PHP MEDIUM 6.5
CVE-2017-7890

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before …

Fix: after 5.6.30
Fix from $1,600 2017-08-02
Outlook MEDIUM 5.5
CVE-2017-8572EPSS 13%

Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an infor…

Patch available
Fix from $1,600 2017-08-01
Vcenter Server MEDIUM 6.5
CVE-2017-4922

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directori…

Patch available
Fix from $1,600 2017-08-01
Vcenter Server CRITICAL 9.8
CVE-2017-4923

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtain…

Patch available
Fix from $2,300 2017-08-01
Mantisbt MEDIUM 5.3
CVE-2015-5059

The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc_threshold) is set to ANYBODY…

Fix: after 1.2.19
Fix from $1,600 2017-08-01
Dpc3939 Firmware MEDIUM 6.5
CVE-2017-9476

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v…

No fix yet
Fix from $1,600 2017-07-31
Dpc3939 Firmware MEDIUM 6.5
CVE-2017-9477

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303…

No fix yet
Fix from $1,600 2017-07-31
Dpc3939 Firmware HIGH 7.5
CVE-2017-9478

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303…

No fix yet
Fix from $1,950 2017-07-31
Dpc3939 Firmware MEDIUM 5.5
CVE-2017-9480

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows local users (e.g., users who have …

No fix yet
Fix from $1,600 2017-07-31
Dpc3939 Firmware HIGH 7.5
CVE-2017-9484

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303…

No fix yet
Fix from $1,950 2017-07-31
Dpc3939 Firmware HIGH 7.5
CVE-2017-9486

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to compute passwo…

No fix yet
Fix from $1,950 2017-07-31
Dpc3939 Firmware MEDIUM 5.9
CVE-2017-9487

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD…

No fix yet
Fix from $1,600 2017-07-31
Dpc3939 Firmware MEDIUM 5.3
CVE-2017-9491

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v…

Mitigation only
Fix from $1,600 2017-07-31
Dpc3939 Firmware HIGH 7.5
CVE-2017-9492

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v…

Mitigation only
Fix from $1,950 2017-07-31