Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Boozt HIGH 7.5
CVE-2017-11706

The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the l…

Fix: after 2.3.3
Fix from $1,950 2017-07-28
Sos MEDIUM 5.5
CVE-2015-3171

sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive informati…

Patch available
Fix from $1,600 2017-07-25
Candlepin MEDIUM 6.5
CVE-2015-5187

Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.

Mitigation only
Fix from $1,600 2017-07-25
Capi Release HIGH 7.5
CVE-2017-8035

An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-releas…

Fix: 1.35.0 / 268+
Fix from $1,950 2017-07-25
Diskstation Manager MEDIUM 5.3
CVE-2017-9554EPSS 77%

An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumer…

Fix: after 6.1.1-15101-4
Fix from $1,600 2017-07-24
Tilde Cms HIGH 7.5
CVE-2017-11325

An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php.

No fix yet
Fix from $1,950 2017-07-24
Tilde Cms MEDIUM 6.5
CVE-2017-11327

An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP …

No fix yet
Fix from $1,600 2017-07-24
Tririga Application Platform MEDIUM 6.5
CVE-2017-1374

Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to t…

Patch available
Fix from $1,600 2017-07-21
Jboss Wildfly Application Server HIGH 7.5
CVE-2015-3198

The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…

Mitigation only
Fix from $1,950 2017-07-21
Dpc3928ad Docsis Wireless Router Firmware CRITICAL 9.8
CVE-2017-11502EPSS 7%

Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.

No fix yet
Fix from $2,300 2017-07-20
Iphone Os MEDIUM 5.5
CVE-2017-7028

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. w…

Fix: 3.2.3 / 10.2.2+
Fix from $1,600 2017-07-20
Iphone Os MEDIUM 5.5
CVE-2017-7029

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. w…

Fix: 3.2.3 / 10.2.2+
Fix from $1,600 2017-07-20
Hg100r Firmware CRITICAL 9.8
CVE-2017-11435EPSS 10%

The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management conso…

Mitigation only
Fix from $2,300 2017-07-19
Imagemagick MEDIUM 6.5
CVE-2017-11448

The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized …

Fix: 6.9.9-0 / 7.0.6-1+
Fix from $1,600 2017-07-19
News And Weather HIGH 7.5
CVE-2017-9245

The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging …

Fix: 3.3.1+
Fix from $1,950 2017-07-19
Clustered Data Ontap MEDIUM 6.5
CVE-2017-7947

NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging …

Mitigation only
Fix from $1,600 2017-07-17
Anti Virus For Linux Server HIGH 7.5
CVE-2017-9812EPSS 11%

The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before M…

Fix: after 8.0.3.297
Fix from $1,950 2017-07-17
Joomla\! HIGH 7.5
CVE-2017-9933

Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.

Mitigation only
Fix from $1,950 2017-07-17
Moodle MEDIUM 6.5
CVE-2017-2642

Moodle 3.x has user fullname disclosure on the user preferences page.

Patch available
Fix from $1,600 2017-07-17
Openmeetings HIGH 7.5
CVE-2017-7683

Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.

Mitigation only
Fix from $1,950 2017-07-17
Jenkins CRITICAL 9.8
CVE-2017-1000362

The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup direct…

Fix: after 1.498
Fix from $2,300 2017-07-17
Txaws MEDIUM 5.9
CVE-2017-1000007

txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.

Mitigation only
Fix from $1,600 2017-07-17
Epiphany HIGH 7.5
CVE-2017-1000025

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password…

Mitigation only
Fix from $1,950 2017-07-17
Glassfish Server HIGH 7.5
CVE-2017-1000029EPSS 8%

Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include …

Mitigation only
Fix from $1,950 2017-07-17
Edge MEDIUM 6.5
CVE-2017-0196EPSS 18%

An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via…

Patch available
Fix from $1,600 2017-07-17
Foreman HIGH 8.1
CVE-2015-5152

Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote atta…

Mitigation only
Fix from $1,950 2017-07-17
HTTP Server CRITICAL 9.1
CVE-2017-9788EPSS 57%

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…

Fix: after 2.4.26
Fix from $2,300 2017-07-13
Bigfix Inventory CRITICAL 9.8
CVE-2016-8964

IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-F…

Fix: 9.2.8+
Fix from $2,300 2017-07-13
Dt80 Dex Firmware CRITICAL 9.8
CVE-2017-11165EPSS 64%

dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /servic…

No fix yet
Fix from $2,300 2017-07-12
Windows 10 MEDIUM 5.5
CVE-2017-8564

Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows …

Patch available
Fix from $1,600 2017-07-11