Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Sysaid MEDIUM 5.0
CVE-2015-2997EPSS 57%

SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFi…

Fix: after 15.1
Fix from $1,600 2015-06-08
Unified Meetingplace MEDIUM 5.0
CVE-2015-0764

Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.

Mitigation only
Fix from $1,600 2015-06-04
Unified Meetingplace MEDIUM 5.0
CVE-2015-0763

Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session in…

Mitigation only
Fix from $1,600 2015-06-04
Sendio MEDIUM 5.0
CVE-2014-0999EPSS 7%

Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessi…

Fix: after 7.2.3
Fix from $1,600 2015-06-02
Headend Digital Broadband Delivery System MEDIUM 5.0
CVE-2015-0745

Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, …

Mitigation only
Fix from $1,600 2015-05-30
Arcserve Unified Data Protection HIGH 7.8
CVE-2015-4069

The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP reques…

Fix: after 5.0
Fix from $1,950 2015-05-29
Identity Services Engine Software MEDIUM 5.0
CVE-2015-0757

The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote…

Mitigation only
Fix from $1,600 2015-05-29
Network Virtualization HIGH 7.8
CVE-2015-2121

HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename…

Mitigation only
Fix from $1,950 2015-05-25
Workload Deployer MEDIUM 5.0
CVE-2014-6190

The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL o…

Patch available
Fix from $1,600 2015-05-25
Infosphere Master Data Management Server MEDIUM 5.0
CVE-2015-1909

The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before F…

Patch available
Fix from $1,600 2015-05-25
Webui MEDIUM 5.0
CVE-2015-3912

Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configur…

Fix: after 22.158.01.00.625
Fix from $1,600 2015-05-21
Ycb002 Firmware MEDIUM 5.0
CVE-2014-1900

Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 …

Patch available
Fix from $1,600 2015-05-14
Flash Player MEDIUM 5.0
CVE-2015-3092

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.144
Fix from $1,600 2015-05-13
Flash Player MEDIUM 5.0
CVE-2015-3091

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.144
Fix from $1,600 2015-05-13
Acrobat Reader MEDIUM 5.0
CVE-2015-3058EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to obtain sensitive information from process…

Patch available
Fix from $1,600 2015-05-13
Windows 7 MEDIUM 5.0
CVE-2015-1716EPSS 21%

Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows …

Patch available
Fix from $1,600 2015-05-13
Netweaver Rfc Sdk MEDIUM 5.0
CVE-2015-3981

SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037.

No fix yet
Fix from $1,600 2015-05-12
Curl MEDIUM 5.0
CVE-2015-3153EPSS 7%

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow re…

Fix: after 12.1.3
Fix from $1,600 2015-05-01
Rational Software Architect Design Manager MEDIUM 5.0
CVE-2015-0113

The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through…

Patch available
Fix from $1,600 2015-04-27
Django Markupfield MEDIUM 5.0
CVE-2015-0846

django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and rea…

Fix: after 1.3.1
Fix from $1,600 2015-04-24
Path Breadcrumbs MEDIUM 5.0
CVE-2015-3391

The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and obtain sensitive node titles…

Fix: after 7.x-3.1
Fix from $1,600 2015-04-21
Tomcat Connectors MEDIUM 5.0
CVE-2014-8111EPSS 7%

Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to acce…

Fix: after 1.2.40
Fix from $1,600 2015-04-21
Amazon Aws MEDIUM 5.0
CVE-2015-3373

The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote a…

Fix: after 7.x-1.2
Fix from $1,600 2015-04-21
Chrome MEDIUM 5.0
CVE-2015-1247

The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does …

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Ubuntu Linux MEDIUM 5.0
CVE-2015-1244

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the w…

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Searchblox MEDIUM 5.0
CVE-2015-0969EPSS 13%

SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI.

Fix: after 8.1
Fix from $1,600 2015-04-18
Malware Analysis Appliance MEDIUM 5.0
CVE-2015-0938

search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access …

Fix: after 4.2.3.20150129
Fix from $1,600 2015-04-17
Hotex Billing Manager MEDIUM 5.0
CVE-2015-3319

Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obt…

No fix yet
Fix from $1,600 2015-04-16
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-3044EPSS 9%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Patch available
Fix from $1,600 2015-04-14
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-3040

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly r…

Fix: after 13.0.0.264
Fix from $1,600 2015-04-14