Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Northstar Controller MEDIUM 5.5
CVE-2017-2328

An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivilege…

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Northstar Controller HIGH 7.5
CVE-2017-2334

An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-base…

Fix: after 2.1.0
Fix from $1,950 2017-04-24
Kunai MEDIUM 6.8
CVE-2016-1187

Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.

Mitigation only
Fix from $1,600 2017-04-21
Ex3000 Firmware HIGH 7.5
CVE-2016-1561EPSS 74%

ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to …

No fix yet
Fix from $1,950 2017-04-21
Cloudforms Management Engine MEDIUM 5.3
CVE-2016-3702

Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.

Mitigation only
Fix from $1,600 2017-04-21
Wnap320 Firmware HIGH 7.5
CVE-2016-1556

Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote…

Fix: after 3.3.2
Fix from $1,950 2017-04-21
Wnap320 Firmware CRITICAL 9.8
CVE-2016-1557

Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP.

Fix: after 3.0.5.0
Fix from $2,300 2017-04-21
Dap 1353 H\/w B1 Firmware HIGH 8.1
CVE-2016-1559

D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver. A1 1.16 and earlier reveal …

Patch available
Fix from $1,950 2017-04-21
Findit Network Probe MEDIUM 6.5
CVE-2017-6614

A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authenticated, re…

Mitigation only
Fix from $1,600 2017-04-20
Moodle MEDIUM 5.3
CVE-2016-3731

Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussion…

Mitigation only
Fix from $1,600 2017-04-20
Wonderware Intouch Access Anywhere CRITICAL 9.8
CVE-2017-5158

An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be e…

Fix: after 11.5.2
Fix from $2,300 2017-04-20
Mailwise MEDIUM 6.5
CVE-2016-4843

Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information.

Mitigation only
Fix from $1,600 2017-04-20
Openshift HIGH 7.5
CVE-2016-5409

Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta…

Mitigation only
Fix from $1,950 2017-04-20
Mediawiki HIGH 7.5
CVE-2016-6332

MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain …

Fix: after 1.23.14
Fix from $1,950 2017-04-20
Mediawiki HIGH 7.5
CVE-2016-6335

MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows r…

Fix: after 1.23.14
Fix from $1,950 2017-04-20
Ovirt MEDIUM 5.5
CVE-2016-6341

oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive pas…

Fix: after 4.0.2
Fix from $1,600 2017-04-20
Enterprise Backup MEDIUM 5.5
CVE-2017-7282

An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filena…

Fix: after 9.1
Fix from $1,600 2017-04-20
Samsung Mobile HIGH 7.5
CVE-2017-7978

Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log …

Mitigation only
Fix from $1,950 2017-04-19
Cognos Business Intelligence MEDIUM 5.7
CVE-2016-3037

IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interac…

Patch available
Fix from $1,600 2017-04-17
Tomcat HIGH 7.5
CVE-2017-5647EPSS 17%

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.…

Mitigation only
Fix from $1,950 2017-04-17
Office MEDIUM 6.5
CVE-2016-4869

Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.

Mitigation only
Fix from $1,600 2017-04-17
Tivoli Application Dependency Discovery Manager MEDIUM 6.5
CVE-2016-8925

IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the atta…

Patch available
Fix from $1,600 2017-04-14
Mxview HIGH 7.5
CVE-2017-7455EPSS 16%

Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

No fix yet
Fix from $1,950 2017-04-14
Awk 3131a Firmware MEDIUM 5.3
CVE-2016-8722

An exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/…

No fix yet
Fix from $1,600 2017-04-13
Awk 3131a Firmware MEDIUM 5.3
CVE-2016-8724

An exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa AWK-3131A Wireless Access Point running firmware…

No fix yet
Fix from $1,600 2017-04-13
Awk 3131a Firmware MEDIUM 5.3
CVE-2016-8725

An exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wireless access point running f…

No fix yet
Fix from $1,600 2017-04-13
Awk 3131a Firmware HIGH 7.5
CVE-2016-8727

An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a…

No fix yet
Fix from $1,950 2017-04-13
Snc Series Firmware HIGH 8.8
CVE-2016-7834

SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520,…

Fix: after 2.7.0
Fix from $1,950 2017-04-13
Acrobat MEDIUM 5.5
CVE-2017-3043

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the…

Fix: after 15.023.20070
Fix from $1,600 2017-04-12
Excel MEDIUM 5.5
CVE-2017-0194EPSS 26%

Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from pro…

Patch available
Fix from $1,600 2017-04-12