Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Leap HIGH 7.5
CVE-2017-6318

saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.

Mitigation only
Fix from $1,950 2017-03-20
Rational Collaborative Lifecycle Management MEDIUM 6.8
CVE-2016-2981

An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999…

Patch available
Fix from $1,600 2017-03-20
Unified Infrastructure Management HIGH 7.5
CVE-2016-9165

The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Sn…

Fix: after 8.47
Fix from $1,950 2017-03-20
Wondercms HIGH 7.5
CVE-2014-8701

Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.

No fix yet
Fix from $1,950 2017-03-17
Wondercms MEDIUM 5.3
CVE-2014-8702

Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals…

No fix yet
Fix from $1,600 2017-03-17
Pluck MEDIUM 5.3
CVE-2014-8706

Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to…

No fix yet
Fix from $1,600 2017-03-17
Getsimple Cms HIGH 7.5
CVE-2014-8722EPSS 14%

GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/…

No fix yet
Fix from $1,950 2017-03-17
Getsimple Cms MEDIUM 5.3
CVE-2014-8723

GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/Inn…

No fix yet
Fix from $1,600 2017-03-17
Qdpm HIGH 7.5
CVE-2015-3881

Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.ym…

No fix yet
Fix from $1,950 2017-03-17
Qdpm MEDIUM 5.3
CVE-2015-3882

qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation…

No fix yet
Fix from $1,600 2017-03-17
Office MEDIUM 5.5
CVE-2017-0105EPSS 30%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Ser…

Patch available
Fix from $1,600 2017-03-17
Windows 10 MEDIUM 5.3
CVE-2017-0043

Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows S…

Patch available
Fix from $1,600 2017-03-17
Live Meeting MEDIUM 5.5
CVE-2017-0060EPSS 16%

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 20…

Patch available
Fix from $1,600 2017-03-17
Windows 10 MEDIUM 6.5
CVE-2017-0063EPSS 35%

The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Window…

Patch available
Fix from $1,600 2017-03-17
Sawmill CRITICAL 9.8
CVE-2017-5496EPSS 6%

Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.

No fix yet
Fix from $2,300 2017-03-15
Weblate MEDIUM 5.3
CVE-2017-5537

The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an accou…

Fix: after 2.10
Fix from $1,600 2017-03-15
Pan Os MEDIUM 6.5
CVE-2017-5583

The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated user…

Fix: after 6.1.15
Fix from $1,600 2017-03-15
Messenger HIGH 7.5
CVE-2014-8688

An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory an…

Mitigation only
Fix from $1,950 2017-03-14
Tomcat HIGH 7.5
CVE-2016-8747EPSS 7%

An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11Inpu…

Fix: 8.5.10+
Fix from $1,950 2017-03-14
Edx Platform MEDIUM 5.9
CVE-2015-6671

Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent att…

Fix: after 2015-08-20
Fix from $1,600 2017-03-13
Goahead CRITICAL 9.8
CVE-2017-5674EPSS 22%

A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft …

No fix yet
Fix from $2,300 2017-03-13
Websphere Commerce MEDIUM 5.1
CVE-2016-5894

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local us…

Patch available
Fix from $1,600 2017-03-08
Android MEDIUM 5.5
CVE-2017-0529

An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission le…

Fix: after 7.1.1
Fix from $1,600 2017-03-08
Android MEDIUM 5.5
CVE-2017-0494

An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its p…

Mitigation only
Fix from $1,600 2017-03-08
Android MEDIUM 5.5
CVE-2017-0495

An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. Th…

Mitigation only
Fix from $1,600 2017-03-08
Linux Kernel MEDIUM 5.5
CVE-2016-8483

An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permiss…

Patch available
Fix from $1,600 2017-03-08
Linux Kernel MEDIUM 5.5
CVE-2017-0334

An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission …

Patch available
Fix from $1,600 2017-03-08
Linux Kernel MEDIUM 5.5
CVE-2017-0336

An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission …

Patch available
Fix from $1,600 2017-03-08
Linux Kernel HIGH 7.8
CVE-2017-0455

An information disclosure vulnerability in the Qualcomm bootloader could help to enable a local malicious application to to execute arbitrary code wi…

Patch available
Fix from $1,950 2017-03-08
Tivoli Storage Manager HIGH 8.8
CVE-2016-8940

IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, …

Patch available
Fix from $1,950 2017-03-07