Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Urbancode Deploy HIGH 7.5
CVE-2016-6068

IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties.

Patch available
Fix from $1,950 2017-02-01
License Metric Tool MEDIUM 5.5
CVE-2016-8963

IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.

Fix: after 9.2
Fix from $1,600 2017-02-01
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2016-6117

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.

Patch available
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.9
CVE-2016-8966

IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport…

Mitigation only
Fix from $1,600 2017-02-01
License Metric Tool MEDIUM 5.5
CVE-2016-8981

IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.

Mitigation only
Fix from $1,600 2017-02-01
Websphere Message Broker MEDIUM 5.3
CVE-2016-6080

The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager HIGH 7.5
CVE-2016-5958

IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag …

Patch available
Fix from $1,950 2017-02-01
Security Privileged Identity Manager MEDIUM 5.9
CVE-2016-5966

IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to pr…

Patch available
Fix from $1,600 2017-02-01
Security Privileged Identity Manager MEDIUM 6.5
CVE-2016-5988

IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available t…

Patch available
Fix from $1,600 2017-02-01
Infosphere Information Server MEDIUM 6.5
CVE-2016-5994

IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine …

Patch available
Fix from $1,600 2017-02-01
Tivoli Storage Manager For Virtual Environments Data Protection For Vmware MEDIUM 6.8
CVE-2016-6034

IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.

Patch available
Fix from $1,600 2017-02-01
Security Access Manager 9.0 Firmware MEDIUM 5.3
CVE-2016-3023

IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

Patch available
Fix from $1,600 2017-02-01
Security Appscan Source MEDIUM 5.3
CVE-2016-3035

IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.

Patch available
Fix from $1,600 2017-02-01
Security Access Manager For Web 7.0 Firmware MEDIUM 5.9
CVE-2016-3043

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stri…

Patch available
Fix from $1,600 2017-02-01
Maximo Asset Management MEDIUM 5.3
CVE-2016-5896

IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.

Patch available
Fix from $1,600 2017-02-01
Merge System HIGH 7.5
CVE-2016-9410

MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to obtain sensitive database information via …

Fix: after 1.8.6
Fix from $1,950 2017-01-31
Merge System MEDIUM 5.3
CVE-2016-9411

The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installat…

Fix: after 1.8.6
Fix from $1,600 2017-01-31
Merge System HIGH 7.5
CVE-2016-9414

MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missi…

Fix: after 1.8.6
Fix from $1,950 2017-01-31
Merge System HIGH 7.5
CVE-2016-9418

MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive inf…

Fix: after 1.8.7
Fix from $1,950 2017-01-31
Openvpn MEDIUM 5.9
CVE-2016-6329EPSS 6%

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duratio…

Fix: after 2.3.14
Fix from $1,600 2017-01-31
Wnr2000v5 Firmware CRITICAL 9.8
CVE-2016-10175EPSS 65%

The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user…

Fix: after 1.0.0.34
Fix from $2,300 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10181

An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.

No fix yet
Fix from $1,950 2017-01-30
WordPress MEDIUM 5.3
CVE-2017-5610EPSS 5%

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user…

Fix: after 4.7.1
Fix from $1,600 2017-01-30
Peoplesoft Enterprise Peopletools MEDIUM 5.7
CVE-2017-3292

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions…

Patch available
Fix from $1,600 2017-01-27
Glassfish Server HIGH 7.3
CVE-2017-3250

Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are…

Patch available
Fix from $1,950 2017-01-27
Jdeveloper MEDIUM 5.8
CVE-2017-3255

Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: ADF Faces). Supported versions that are affected are 11.1…

Patch available
Fix from $1,600 2017-01-27
Knox MEDIUM 5.5
CVE-2016-3996

ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a craft…

No fix yet
Fix from $1,600 2017-01-27
Debian Linux HIGH 7.5
CVE-2016-10002EPSS 7%

Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, an…

Patch available
Fix from $1,950 2017-01-27
Webex Meetings Server MEDIUM 5.3
CVE-2017-3797

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualified domain name of the Cisco W…

Mitigation only
Fix from $1,600 2017-01-26
Iox MEDIUM 5.3
CVE-2017-3805

A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated, remote attacker to view con…

Mitigation only
Fix from $1,600 2017-01-26