Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2020-15704 The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module loading. A local non-root attacke… Ppp 2.4.5-5ubuntu1.4 / 2.4.5-5.1ubuntu2.3+ Fix from $1,6002020-09-01 MEDIUM 5.3 CVE-2020-4172 IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties … Security Guardium Insights Patch available Fix from $1,6002020-08-27 MEDIUM 5.5 CVE-2020-3520 A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obtain confidential information … Data Center Network Manager 11.4+ Fix from $1,6002020-08-26 HIGH 7.5 CVE-2020-24381 GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensu… Open Eclass Platform 3.11+ Fix from $1,9502020-08-19 MEDIUM 5.5 CVE-2020-1510 An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploit… Windows 10 Patch available Fix from $1,6002020-08-17 MEDIUM 5.0 CVE-2020-3472 A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to acces… Webex Meetings Online 40.7.0+ Fix from $1,6002020-08-17 HIGH 7.5 CVE-2020-3411 A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. Th… Catalyst Center 1.3.1.4+ Fix from $1,9502020-08-17 HIGH 7.5 CVE-2020-8210 Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.… Xenmobile Server after 10.8.0 Fix from $1,9502020-08-17 MEDIUM 6.5 CVE-2020-8232 An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized informati… Edgeswitch Firmware 1.9.0+ Fix from $1,6002020-08-17 MEDIUM 5.5 CVE-2020-13179 Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server me… Graphics Agent 20.04.1+ Fix from $1,6002020-08-11 HIGH 7.4 CVE-2020-15647 A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data dis… Firefox 68.10.1+ Fix from $1,9502020-08-10 HIGH 8.1 CVE-2020-9525 CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to p… P2p after 3.0.3a Fix from $1,9502020-08-10 HIGH 7.5 CVE-2020-12777 A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose syste… Itop 2.7.1+ Fix from $1,9502020-08-10 HIGH 7.5 CVE-2019-7005 A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network acc… Ip Office after 11.0.4.2 Fix from $1,9502020-08-07 MEDIUM 6.5 CVE-2017-18112 Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability i… Fisheye 4.8.3+ Fix from $1,6002020-08-05 MEDIUM 5.7 CVE-2020-5414 VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains… Tanzu Application Service For Virtual Machines 2.7.15 / 2.7.19+ Fix from $1,6002020-07-31 MEDIUM 5.3 CVE-2020-4186 IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the syste… Security Guardium Patch available Fix from $1,6002020-07-30 CRITICAL 9.8 CVE-2020-15086 In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification… Mediace 7.6.5+ Fix from $2,3002020-07-29 HIGH 8.8 CVE-2020-15098 In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered th… TYPO3 9.5.20 / 10.4.6+ Fix from $1,9502020-07-29 HIGH 8.1 CVE-2020-15099 In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attack… TYPO3 9.5.20 / 10.4.6+ Fix from $1,9502020-07-29 MEDIUM 5.5 CVE-2019-4731 IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Forc… Mq Appliance Patch available Fix from $1,6002020-07-28 MEDIUM 6.5 CVE-2020-6514EPSS 8% Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exp… Chrome 13.1.2 / 13.6+ Fix from $1,6002020-07-22 MEDIUM 5.3 CVE-2020-7696 This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization:… React Native Fast Image Patch available Fix from $1,6002020-07-17 HIGH 7.8 CVE-2020-7284 Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to gain unauthorised access to the… Network Security Management 9.2.9.55 / 10.1.7.7+ Fix from $1,9502020-07-03 MEDIUM 5.3 CVE-2020-15080 In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. … Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 MEDIUM 5.3 CVE-2020-15081 In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6… Prestashop 1.7.6.6+ Fix from $1,6002020-07-02 HIGH 7.5 CVE-2020-15502 The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests … Duckduckgo after 7.47.1.0 Fix from $1,9502020-07-02 MEDIUM 6.5 CVE-2020-3391 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in cle… Digital Network Architecture Center 1.2.10+ Fix from $1,6002020-07-02 MEDIUM 5.9 CVE-2020-4565 IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an attacker to obtain sensitive information due to insecure communications being used bet… Spectrum Protect Plus after 10.1.5 Fix from $1,6002020-06-26 HIGH 7.1 CVE-2020-10274 The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control… Mir100 Firmware after 2.8.1.1 Fix from $1,9502020-06-24