Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 MEDIUM 5.5
CVE-2017-0167EPSS 6%

An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the W…

Patch available
Fix from $1,600 2017-04-12
Enterprise Mobile Management MEDIUM 6.5
CVE-2017-5672

Kony Enterprise Mobile Management (EMM) before 4.2.5.2 has the vulnerability of disclosing the private key in clear-text when changing the parameters…

Fix: after 4.2.0
Fix from $1,600 2017-04-11
Log \& Event Manager MEDIUM 6.5
CVE-2017-7646

SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of ar…

Fix: after 6.3.1
Fix from $1,600 2017-04-10
Botan HIGH 7.5
CVE-2015-7824

botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle attack against TLS CBC ciphersui…

Fix: after 1.11.21
Fix from $1,950 2017-04-10
Clustered Data Ontap MEDIUM 5.3
CVE-2017-7345

NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extensio…

Fix: after 7.1
Fix from $1,600 2017-04-10
Keepassx HIGH 7.5
CVE-2015-8378

In KeePassX before 0.4.4, a cleartext copy of password data is created upon a cancel of an XML export action. This allows context-dependent attackers…

Fix: after 0.4.3
Fix from $1,950 2017-04-10
Edoc Libraries MEDIUM 5.5
CVE-2015-8276

LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC files.

Mitigation only
Fix from $1,600 2017-04-10
Lightify Home HIGH 7.5
CVE-2016-5051

OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.

Fix: after 1.6.1
Fix from $1,950 2017-04-10
Lightify Pro MEDIUM 6.5
CVE-2016-5059

OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile…

No fix yet
Fix from $1,600 2017-04-10
Cloudview Nms HIGH 7.5
CVE-2016-5076

CloudView NMS before 2.10a allows remote attackers to obtain sensitive information via a direct request for admin/auto.def.

Fix: after 2.09b
Fix from $1,950 2017-04-10
Vision Critical HIGH 7.5
CVE-2014-2960

Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration …

Fix: after 2014-05-30
Fix from $1,950 2017-04-10
In.sight B120\\37 HIGH 7.5
CVE-2015-2884

Philips In.Sight B120/37 allows remote attackers to obtain sensitive information via a direct request, related to yoics.net URLs, stream.m3u8 URIs, a…

No fix yet
Fix from $1,950 2017-04-10
M6 Baby Monitor Firmware HIGH 7.5
CVE-2015-2886

iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.

Mitigation only
Fix from $1,950 2017-04-10
Openidm MEDIUM 6.5
CVE-2017-7589

In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the "anonymous" user, as demonstrated by re…

Fix: after 4.0.0
Fix from $1,600 2017-04-09
Android MEDIUM 5.5
CVE-2017-0547

An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access data outside of its permissio…

Patch available
Fix from $1,600 2017-04-07
Android MEDIUM 5.5
CVE-2017-0555

An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access data outside of its permission …

Mitigation only
Fix from $1,600 2017-04-07
Android MEDIUM 5.5
CVE-2017-0556

An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permissio…

Patch available
Fix from $1,600 2017-04-07
Android MEDIUM 5.5
CVE-2017-0557

An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permissio…

Patch available
Fix from $1,600 2017-04-07
Android MEDIUM 5.5
CVE-2017-0558

An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. Th…

Patch available
Fix from $1,600 2017-04-07
Android MEDIUM 5.5
CVE-2017-0559

An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of its permission levels. This i…

Mitigation only
Fix from $1,600 2017-04-07
Android MEDIUM 5.5
CVE-2017-0560

An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access data from the previous owner. …

Mitigation only
Fix from $1,600 2017-04-07
Evolved Programmable Network Manager MEDIUM 6.5
CVE-2017-3884

A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated,…

Mitigation only
Fix from $1,600 2017-04-07
Modicon Tm221ce16r Firmware CRITICAL 9.8
CVE-2017-7575

Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection password via a \x00\x01\x00\x00\x…

No fix yet
Fix from $2,300 2017-04-06
Android MEDIUM 5.5
CVE-2016-5349

The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Se…

Fix: after 7.1.1
Fix from $1,600 2017-04-06
Geode HIGH 7.5
CVE-2017-5649

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUST…

Fix: after 1.1.0
Fix from $1,950 2017-04-04
Tc7200 Firmware HIGH 7.5
CVE-2014-1677EPSS 18%

Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.

No fix yet
Fix from $1,950 2017-04-03
Al3g Firmware HIGH 8.8
CVE-2016-10314

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.0…

No fix yet
Fix from $1,950 2017-04-03
S9300 Firmware MEDIUM 5.3
CVE-2014-8570

Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, …

Mitigation only
Fix from $1,600 2017-04-02
Tecal Rh1288 V2 Firmware MEDIUM 6.5
CVE-2014-9691

Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, T…

Mitigation only
Fix from $1,600 2017-04-02
Tecal Rh1288 V2 Firmware HIGH 7.5
CVE-2014-9692

Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, T…

Mitigation only
Fix from $1,950 2017-04-02