Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Pyplate MEDIUM 5.0
CVE-2014-3852

Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potent…

No fix yet
Fix from $1,600 2014-08-07
Pyplate MEDIUM 5.0
CVE-2014-3853

Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this cookie by…

No fix yet
Fix from $1,600 2014-08-07
Mguard Firmware MEDIUM 5.0
CVE-2014-2356

Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain s…

Fix: after 7.5.0
Fix from $1,600 2014-07-30
Websphere Portal MEDIUM 5.0
CVE-2014-3056

The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive…

Mitigation only
Fix from $1,600 2014-07-29
Webex Meetings Server MEDIUM 5.0
CVE-2014-3304

The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the …

Mitigation only
Fix from $1,600 2014-07-28
Concrete5 MEDIUM 5.0
CVE-2014-5107

concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.…

No fix yet
Fix from $1,600 2014-07-28
Webex Meetings Server MEDIUM 5.0
CVE-2014-3301

The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by…

Fix: after 1.5
Fix from $1,600 2014-07-26
Simatic Pcs7 MEDIUM 5.0
CVE-2014-4682

The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive informat…

Fix: after 8.0
Fix from $1,600 2014-07-24
Nessus MEDIUM 5.0
CVE-2014-4980

The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information…

Fix: after 2.3.4
Fix from $1,600 2014-07-23
Jboss Enterprise Application Platform HIGH 7.5
CVE-2014-3530

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform …

Mitigation only
Fix from $1,950 2014-07-22
Recoverpoint Appliance MEDIUM 5.8
CVE-2014-2519

The default configuration of EMC RecoverPoint Appliance (RPA) 4.1 before 4.1.0.1 does not enable a firewall, which allows remote attackers to obtain …

Mitigation only
Fix from $1,600 2014-07-19
Advantech Webaccess MEDIUM 5.0
CVE-2014-2368

The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a craft…

Fix: after 7.1
Fix from $1,600 2014-07-19
Infosphere Master Data Management Collaboration Server MEDIUM 6.3
CVE-2014-3064

The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Managemen…

Mitigation only
Fix from $1,600 2014-07-19
Netscaler Access Gateway Firmware MEDIUM 5.0
CVE-2014-4347

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x be…

No fix yet
Fix from $1,600 2014-07-16
Wp Easycart MEDIUM 5.0
CVE-2014-4942

The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/…

Fix: after 2.0.5
Fix from $1,600 2014-07-11
Centerstage MEDIUM 6.8
CVE-2014-2510

The JAXB XML parser in EMC Documentum Foundation Services (DFS) 6.6 before P39, 6.7 SP1 before P28, and 6.7 SP2 before P15, as used in My Documentum …

Mitigation only
Fix from $1,600 2014-07-08
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2014-3481

org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion…

Fix: after 6.2.3
Fix from $1,600 2014-07-07
Flex System Manager MEDIUM 5.0
CVE-2013-5423

IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors.

Mitigation only
Fix from $1,600 2014-07-07
Tivoli Endpoint Manager MEDIUM 5.0
CVE-2014-3066

IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declarat…

Mitigation only
Fix from $1,600 2014-07-02
Mac Os X MEDIUM 5.0
CVE-2014-1361

Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only …

Fix: after 7.1.1
Fix from $1,600 2014-07-01
Websphere Application Server MEDIUM 5.0
CVE-2014-0891

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensit…

Patch available
Fix from $1,600 2014-06-28
Open Source Security Information Management HIGH 7.8
CVE-2014-4153EPSS 7%

The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.

Fix: after 4.7.0
Fix from $1,950 2014-06-18
Puppet Enterprise MEDIUM 5.0
CVE-2014-3249

Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.

Mitigation only
Fix from $1,600 2014-06-17
Photo Station Firmware MEDIUM 5.0
CVE-2013-5760

QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.

Fix: after 4.0.3
Fix from $1,600 2014-06-09
Cm3 Acora Content Management System MEDIUM 5.0
CVE-2013-4724

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-C…

Mitigation only
Fix from $1,600 2014-06-06
Cm3 Acora Content Management System MEDIUM 5.0
CVE-2013-4725

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecifi…

Mitigation only
Fix from $1,600 2014-06-06
Cm3 Acora Content Management System MEDIUM 5.0
CVE-2013-4727

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive i…

Mitigation only
Fix from $1,600 2014-06-06
Cm3 Acora Content Management System MEDIUM 5.0
CVE-2013-4728

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive i…

Mitigation only
Fix from $1,600 2014-06-06
Mediawiki MEDIUM 5.0
CVE-2013-1818

maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified vectors.

Fix: after 1.20.2
Fix from $1,600 2014-06-02
Sametime MEDIUM 5.0
CVE-2014-3867

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspe…

Mitigation only
Fix from $1,600 2014-05-26