Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2020-17527EPSS 25% While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTT… Tomcat 21.1.2+ Fix from $1,9502020-12-03 HIGH 7.5 CVE-2020-5676 GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors. Growi after 4.1.3 Fix from $1,9502020-12-03 HIGH 7.5 CVE-2020-29043 An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can cr… Bigbluebutton after 2.2.29 Fix from $1,9502020-11-26 CRITICAL 9.8 CVE-2020-28333 Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not u… Wepresent Wipg 1600w Firmware No fix yet Fix from $2,3002020-11-24 MEDIUM 6.5 CVE-2020-12496 Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.… Rsg35 Firmware 2.0.0+ Fix from $1,6002020-11-19 MEDIUM 5.3 CVE-2020-25703 The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affec… Moodle after 3.9.2 Fix from $1,6002020-11-19 HIGH 7.5 CVE-2020-26076 A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on a… Iot Field Network Director 4.6.1+ Fix from $1,9502020-11-18 MEDIUM 5.3 CVE-2020-26230 Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identification and de-anonymization of… Radar Covid Backend Dp3t Server 1.0.7 / 1.0.8+ Fix from $1,6002020-11-13 HIGH 7.5 CVE-2020-2022 An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administ… Pan Os 8.1.17 / 9.0.11+ Fix from $1,9502020-11-12 MEDIUM 6.5 CVE-2020-27403 A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporatio… 32s330 Firmware No fix yet Fix from $1,6002020-11-10 HIGH 7.5 CVE-2020-10291 Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making … Visual Components Network License Server Mitigation only Fix from $1,9502020-11-06 MEDIUM 6.5 CVE-2020-7196 The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos pass… Bluedata Epic after 4.0 Fix from $1,6002020-10-26 HIGH 7.5 CVE-2020-15931 Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administ… Account Lockout Examiner 5.1+ Fix from $1,9502020-10-20 MEDIUM 5.3 CVE-2020-1777 Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as in chat transcriptions inside… Otrs after 8.0.6 Fix from $1,6002020-10-15 MEDIUM 5.5 CVE-2020-15250 In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste… Debian Linux 3.1.1 / 4.13.1+ Fix from $1,6002020-10-12 HIGH 7.5 CVE-2020-26869 ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitima… Pcvue 12.0.17+ Fix from $1,9502020-10-12 HIGH 7.5 CVE-2020-1902 A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from… Whatsapp after 2.20.140 Fix from $1,9502020-10-06 HIGH 7.5 CVE-2020-15235 In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would normally be hidden to everyone ex… Core after 41edf92 Fix from $1,9502020-10-05 MEDIUM 5.3 CVE-2020-5132 SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerab… Sma100 Firmware Mitigation only Fix from $1,6002020-09-30 MEDIUM 6.5 CVE-2019-15963 A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view s… Unified Communications Manager after 12.5 Fix from $1,6002020-09-23 HIGH 7.5 CVE-2020-5975 NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensiti… Geforce Now 2.0.23+ Fix from $1,9502020-09-18 MEDIUM 5.3 CVE-2020-14181EPSS 100% Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili… Data Center 7.13.6 / 8.5.7+ Fix from $1,6002020-09-17 MEDIUM 6.5 CVE-2018-19947 The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sen… Helpdesk 3.0.3+ Fix from $1,6002020-09-11 HIGH 7.5 CVE-2020-9733 An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If e… Experience Manager after 6.5.5.0 Fix from $1,9502020-09-10 MEDIUM 5.3 CVE-2020-15790 A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susc… Spectrum Power 4 4.70+ Fix from $1,6002020-09-09 MEDIUM 5.5 CVE-2020-3643 u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Compute, Snapdragon Co… Apq8009 Firmware Mitigation only Fix from $1,6002020-09-08 MEDIUM 5.5 CVE-2020-3644 u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in Snapdragon Auto, S… Apq8009 Firmware Mitigation only Fix from $1,6002020-09-08 MEDIUM 6.5 CVE-2020-3547 A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Mana… Asyncos after 13.6.1-193 Fix from $1,6002020-09-04 MEDIUM 6.5 CVE-2020-3498 A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is … Jabber 12.1.3 / 12.5.2+ Fix from $1,6002020-09-04 MEDIUM 5.7 CVE-2020-3537 A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulne… Jabber 12.1.3 / 12.5.2+ Fix from $1,6002020-09-04