Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Netweaver HIGH 7.5
CVE-2017-5372

The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system informati…

No fix yet
Fix from $1,950 2017-01-23
Confluence Server HIGH 7.5
CVE-2016-6668

The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat …

No fix yet
Fix from $1,950 2017-01-23
Open Enterprise Server HIGH 7.5
CVE-2017-5182

Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that …

Mitigation only
Fix from $1,950 2017-01-23
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2016-10143

A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner U…

Patch available
Fix from $1,950 2017-01-20
Moodle MEDIUM 5.3
CVE-2016-5012

In Moodle 3.x, glossary search displays entries without checking user permissions to view them.

Patch available
Fix from $1,600 2017-01-20
Moodle MEDIUM 5.4
CVE-2016-5014

In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.

Patch available
Fix from $1,600 2017-01-20
Chrome MEDIUM 6.5
CVE-2016-5201

A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Ma…

Fix: after 54.0.2840.87
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.5
CVE-2016-5212

Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insufficiently sanitized DevTools URLs, which allowed a …

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.5
CVE-2016-5220

PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, wh…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Provisioning Services HIGH 7.5
CVE-2016-9680

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.

Mitigation only
Fix from $1,950 2017-01-18
Provisioning Services MEDIUM 5.3
CVE-2016-9677

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.

Mitigation only
Fix from $1,600 2017-01-18
Phpmailer MEDIUM 5.5
CVE-2017-5223

An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an em…

Fix: after 5.2.21
Fix from $1,600 2017-01-16
Linux Kernel HIGH 7.1
CVE-2017-2584

arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel memory or cause a denial of s…

Fix: after 4.9.3
Fix from $1,950 2017-01-15
WordPress MEDIUM 5.3
CVE-2017-5487EPSS 87%

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly rest…

Fix: after 4.7
Fix from $1,600 2017-01-15
Android MEDIUM 5.5
CVE-2017-0398

An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. Th…

Mitigation only
Fix from $1,600 2017-01-13
Matrixssl MEDIUM 5.9
CVE-2016-6887

The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to pred…

Fix: after 3.8.6
Fix from $1,600 2017-01-13
Matrixssl MEDIUM 5.9
CVE-2016-8671

The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to pred…

Fix: after 3.8.6
Fix from $1,600 2017-01-13
Gajim Otr HIGH 7.5
CVE-2016-9107

The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecifi…

Patch available
Fix from $1,950 2017-01-13
Lg Mobile MEDIUM 5.5
CVE-2016-10135

An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5…

Mitigation only
Fix from $1,600 2017-01-13
Zoneminder HIGH 7.5
CVE-2016-10140EPSS 7%

Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29…

Patch available
Fix from $1,950 2017-01-13
Enterprise Service HIGH 8.1
CVE-2016-3130

An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote atta…

Mitigation only
Fix from $1,950 2017-01-13
Clickshare Csc 1 Firmware CRITICAL 9.8
CVE-2016-3152

Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the fir…

Fix: after 01.09.02.03
Fix from $2,300 2017-01-12
Android MEDIUM 5.5
CVE-2017-0388

An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD…

Mitigation only
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2017-0396

An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaserver could enable a local malicious application to…

Patch available
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2017-0397

An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data out…

Patch available
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2017-0399

An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a loca…

Fix: after 7.1.1
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2017-0400

An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious applicatio…

Patch available
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2017-0401

An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a loca…

Fix: after 7.1.1
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2017-0402

An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious applicatio…

Fix: after 7.1.1
Fix from $1,600 2017-01-12
Linux Kernel MEDIUM 5.5
CVE-2016-8460

An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permissio…

Mitigation only
Fix from $1,600 2017-01-12