Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2020-7262 Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view sensitive files via a carefu… Advanced Threat Defense 4.10.0+ Fix from $1,6002020-06-22 MEDIUM 5.3 CVE-2020-13264 Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token GitLab 12.9.8 / 12.10.7+ Fix from $1,6002020-06-19 MEDIUM 5.5 CVE-2020-10750 Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. … Jaeger 1.18.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2016-11075 An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API. Mattermost Server 3.0.0+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2016-11078 An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within … Mattermost Server 3.0.0+ Fix from $1,6002020-06-19 HIGH 7.5 CVE-2016-11066 An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information. Mattermost Server 3.2.0+ Fix from $1,9502020-06-19 MEDIUM 5.3 CVE-2017-18895 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via … Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18901 An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON d… Mattermost Server 3.10.3 / 4.0.4+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18902 An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints. Mattermost Server 3.10.3 / 4.0.4+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18887 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members. Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2020-10782 An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable … Ansible Tower Mitigation only Fix from $1,6002020-06-18 MEDIUM 5.3 CVE-2020-3360 A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sens… Unified Ip Phone 6901 Firmware after 12.8 Fix from $1,6002020-06-18 MEDIUM 5.5 CVE-2020-3347 A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information … Webex Meetings 40.4.12+ Fix from $1,6002020-06-18 MEDIUM 5.7 CVE-2020-7932 OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a … Omero.web 5.6.3+ Fix from $1,6002020-06-17 HIGH 7.5 CVE-2020-7506 A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unpack the … Easergy T300 Firmware after 1.5.2 Fix from $1,9502020-06-16 HIGH 7.5 CVE-2020-7510 A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtain private … Easergy T300 Firmware after 1.5.2 Fix from $1,9502020-06-16 HIGH 7.5 CVE-2020-4045 SSB-DB version 20.0.0 has an information disclosure vulnerability. The get() method is supposed to only decrypt messages when you explicitly ask it t… Ssb Db Patch available Fix from $1,9502020-06-11 CRITICAL 10.0 CVE-2020-13702 The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth… The Rolling Proximity Identifier after 2020-05-29 Fix from $2,3002020-06-11 MEDIUM 5.3 CVE-2020-13268 A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. Thi… GitLab after 13.0.1 Fix from $1,6002020-06-10 MEDIUM 5.3 CVE-2020-12802 LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not t… Fedora 6.4.4+ Fix from $1,6002020-06-08 HIGH 7.5 CVE-2019-20836 An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstrated by Google Drive. Phantompdf 9.5+ Fix from $1,9502020-06-04 CRITICAL 9.8 CVE-2018-21242 An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows Remote Code Execution via a GoToE or GoToR action. Phantompdf 8.3.6+ Fix from $2,3002020-06-04 MEDIUM 5.5 CVE-2020-7030 A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t… Ip Office after 11.0.4.2 Fix from $1,6002020-06-04 MEDIUM 6.5 CVE-2011-2863 Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from p… Chrome 14.0.0.0+ Fix from $1,6002020-06-03 HIGH 7.5 CVE-2020-13764 common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a … Gravityforms 2.4.9+ Fix from $1,9502020-06-02 MEDIUM 5.3 CVE-2014-8940 Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI. Lexiglot after 2014-11-20 Fix from $1,6002020-06-01 HIGH 7.5 CVE-2020-11059 In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from environment variables in the brow… Aegir 21.10.1+ Fix from $1,9502020-05-27 HIGH 7.5 CVE-2020-4226 IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure if unautho… Mobilefirst Platform Foundation Patch available Fix from $1,9502020-05-27 HIGH 7.5 CVE-2020-6830 For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was b… Firefox Mobile 25.0+ Fix from $1,9502020-05-26 HIGH 7.5 CVE-2020-5364 Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by default, with a pre-configured c… Emc Isilon Onefs after 8.2.2 Fix from $1,9502020-05-20