Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 MEDIUM 5.9
CVE-2017-0271EPSS 13%

Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP…

Patch available
Fix from $1,600 2017-05-12
Mictray64 MEDIUM 5.5
CVE-2017-8360

Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mic…

Fix: after 1.0.0.46
Fix from $1,600 2017-05-12
Invision Power Board HIGH 8.1
CVE-2017-8899

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments…

Fix: after 4.1.19.2
Fix from $1,950 2017-05-11
Rt Ac1750 Firmware HIGH 7.5
CVE-2017-5892

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

Patch available
Fix from $1,950 2017-05-10
Rt Ac1750 Firmware MEDIUM 6.5
CVE-2017-8877

ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.

Mitigation only
Fix from $1,600 2017-05-10
Rt Ac1750 Firmware MEDIUM 6.5
CVE-2017-8878

ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.

Mitigation only
Fix from $1,600 2017-05-10
Experience Manager Forms HIGH 7.5
CVE-2017-3067

Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service…

Mitigation only
Fix from $1,950 2017-05-09
Ds 2cd2032 I Firmware HIGH 8.8
CVE-2017-7923

A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Ser…

Patch available
Fix from $1,950 2017-05-06
Tivoli Storage Manager MEDIUM 5.5
CVE-2016-8916

IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password com…

Fix: after 6.3
Fix from $1,600 2017-05-05
Unified Contact Center Enterprise MEDIUM 5.3
CVE-2017-6626

A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unaut…

Mitigation only
Fix from $1,600 2017-05-03
Officescan HIGH 8.8
CVE-2017-5481

Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an …

Patch available
Fix from $1,950 2017-05-03
Pan Os MEDIUM 6.5
CVE-2017-7216

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecif…

Fix: after 7.1.8
Fix from $1,600 2017-05-02
Rack Mini Profiler MEDIUM 5.3
CVE-2016-4442

The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leve…

Fix: after 0.9.9.2
Fix from $1,600 2017-05-02
Cloud Foundry CRITICAL 9.8
CVE-2016-5006

The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user cred…

Fix: after 238.0
Fix from $2,300 2017-05-02
Telegram Desktop MEDIUM 5.5
CVE-2016-10351

Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information vi…

Patch available
Fix from $1,600 2017-05-01
Pan Os MEDIUM 6.5
CVE-2017-7644

The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users …

Fix: after 6.1.15
Fix from $1,600 2017-04-29
Lala Call MEDIUM 5.9
CVE-2017-2103

The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoo…

Fix: after 2.4.7
Fix from $1,600 2017-04-28
Business Lala Call MEDIUM 5.9
CVE-2017-2104

The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attacker…

Fix: after 1.4.7
Fix from $1,600 2017-04-28
Tver MEDIUM 5.9
CVE-2017-2105

The TVer App for Android 3.2.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof ser…

Fix: after 3.2.7
Fix from $1,600 2017-04-28
Confluence Server HIGH 7.5
CVE-2017-7415

Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.

No fix yet
Fix from $1,950 2017-04-27
Joomla\! MEDIUM 5.3
CVE-2017-7983

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.

Patch available
Fix from $1,600 2017-04-25
Joomla\! MEDIUM 5.3
CVE-2017-8057

In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.

Patch available
Fix from $1,600 2017-04-25
Salt HIGH 7.8
CVE-2017-8109

The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, whi…

Patch available
Fix from $1,950 2017-04-25
Application Object Library MEDIUM 5.3
CVE-2017-3556

Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: File Management). Supported versions that …

Mitigation only
Fix from $1,600 2017-04-24
Peoplesoft Enterprise Peopletools MEDIUM 5.3
CVE-2017-3527

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core). Supported versions that ar…

Mitigation only
Fix from $1,600 2017-04-24
Dvg N5402sp Firmware CRITICAL 9.8
CVE-2015-7247EPSS 10%

D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super an…

No fix yet
Fix from $2,300 2017-04-24
Northstar Controller HIGH 8.6
CVE-2017-2317

A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthentic…

Fix: after 2.1.0
Fix from $1,950 2017-04-24
Northstar Controller MEDIUM 6.5
CVE-2017-2318

A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user …

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Northstar Controller CRITICAL 10.0
CVE-2017-2320

A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged…

Fix: after 2.1.0
Fix from $2,300 2017-04-24
Northstar Controller MEDIUM 6.5
CVE-2017-2326

An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unpri…

Fix: after 2.1.0
Fix from $1,600 2017-04-24