Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Espace Iad Firmware MEDIUM 5.3
CVE-2016-8271

Huawei eSpace IAD V300R002C01SPC100 and earlier versions have an information leak vulnerability; an attacker can check and download the fault informa…

Mitigation only
Fix from $1,600 2017-04-02
Hisuite MEDIUM 5.3
CVE-2016-8272

Huawei PC client software HiSuite 4.0.5.300_OVE has an information leak vulnerability; an attacker who can log in to the system can copy out the user…

Mitigation only
Fix from $1,600 2017-04-02
Mac Os X MEDIUM 5.5
CVE-2017-2489

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It all…

Fix: after 10.12.3
Fix from $1,600 2017-04-02
Safari MEDIUM 6.5
CVE-2017-2480

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affec…

Fix: after 12.5.5.5
Fix from $1,600 2017-04-02
Iphone Os MEDIUM 5.9
CVE-2017-2448

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. The i…

Fix: after 10.12.3
Fix from $1,600 2017-04-02
Mac Os X MEDIUM 6.5
CVE-2017-2418

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Hypervisor" component. It allows guest O…

Fix: after 10.12.3
Fix from $1,600 2017-04-02
Safari MEDIUM 6.5
CVE-2017-2424

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves mishandling of Ope…

Fix: after 10.2.1
Fix from $1,600 2017-04-02
Mac Os Server HIGH 7.5
CVE-2017-2382

An issue was discovered in certain Apple products. macOS Server before 5.3 is affected. The issue involves the "Wiki Server" component. It allows rem…

Fix: after 5.2
Fix from $1,950 2017-04-02
Safari MEDIUM 5.5
CVE-2017-2385

An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allow…

Fix: after 10.0.3
Fix from $1,600 2017-04-02
Iphone Os MEDIUM 5.3
CVE-2017-2400

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "SafariViewController" component. It allows at…

Fix: after 10.2.1
Fix from $1,600 2017-04-02
Algo One MEDIUM 6.5
CVE-2017-1154

IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not…

Patch available
Fix from $1,600 2017-03-31
Sentinel MEDIUM 5.3
CVE-2017-5184

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).

Fix: 8.0.1+
Fix from $1,600 2017-03-30
Rsa Archer Security Operations Management HIGH 7.0
CVE-2017-4977

EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclos…

Fix: after 1.3.1.51
Fix from $1,950 2017-03-29
Ambari MEDIUM 5.5
CVE-2016-4976

Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive informat…

Mitigation only
Fix from $1,600 2017-03-29
Ruggedcom Rox I MEDIUM 6.5
CVE-2017-2686

Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interfa…

Fix: after 2.9.0
Fix from $1,600 2017-03-29
GitLab MEDIUM 6.3
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15…

Patch available
Fix from $1,600 2017-03-28
Revive Adserver MEDIUM 5.3
CVE-2016-9129

Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was assoc…

Fix: after 3.2.2
Fix from $1,600 2017-03-28
Kenexa Lcms Premier MEDIUM 6.5
CVE-2017-1142

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure …

Mitigation only
Fix from $1,600 2017-03-27
Kenexa Lcms Premier MEDIUM 5.3
CVE-2017-1143

IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable…

Mitigation only
Fix from $1,600 2017-03-27
Big Ip Local Traffic Manager MEDIUM 5.5
CVE-2016-7474

In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporar…

Mitigation only
Fix from $1,600 2017-03-27
Moodle MEDIUM 5.3
CVE-2017-2643

In Moodle 3.2.x, global search displays user names for unauthenticated users.

Patch available
Fix from $1,600 2017-03-26
Nt14u Firmware CRITICAL 9.8
CVE-2015-5729

The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, whi…

No fix yet
Fix from $2,300 2017-03-23
Mediawiki HIGH 7.5
CVE-2015-8625

MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the c…

Fix: after 1.23.11
Fix from $1,950 2017-03-23
Mediawiki MEDIUM 5.3
CVE-2015-8628

The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki befor…

Fix: after 1.23.11
Fix from $1,600 2017-03-23
Qts HIGH 7.5
CVE-2017-5227EPSS 6%

QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR forma…

Fix: after 4.2.4
Fix from $1,950 2017-03-23
Netiq Idm Servicenow Driver MEDIUM 6.5
CVE-2016-1603

An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users.

Fix: after 1.0.0
Fix from $1,600 2017-03-23
Access Manager HIGH 7.5
CVE-2016-5752

The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests inc…

Mitigation only
Fix from $1,950 2017-03-23
Access Manager HIGH 7.5
CVE-2016-5754

Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.

Mitigation only
Fix from $1,950 2017-03-23
Access Manager CRITICAL 9.8
CVE-2016-5757

iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which c…

Mitigation only
Fix from $2,300 2017-03-23
Recoverpoint For Virtual Machines HIGH 7.5
CVE-2016-6650

EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may p…

Fix: after 4.4.1.1
Fix from $1,950 2017-03-21