Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2011-3269 Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Sca… X950 Firmware Mitigation only Fix from $1,9502020-03-09 MEDIUM 5.3 CVE-2011-4538 Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings. X860 Firmware Mitigation only Fix from $1,6002020-03-09 MEDIUM 6.5 CVE-2016-1159 In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry… Manageengine Password Manager Pro Mitigation only Fix from $1,6002020-03-09 MEDIUM 6.5 CVE-2020-9282 In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network respo… Mahara 18.10.5 / 19.04.4+ Fix from $1,6002020-03-09 HIGH 7.5 CVE-2020-10096 An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either rem… Zammad after 3.2.0 Fix from $1,9502020-03-05 HIGH 7.5 CVE-2020-7130 HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of… Oneview Global Dashboard Mitigation only Fix from $1,9502020-03-04 MEDIUM 5.3 CVE-2020-3193 A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to ob… Prime Collaboration Provisioning 12.6+ Fix from $1,6002020-03-04 CRITICAL 9.8 CVE-2019-14893 A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of ma… Jackson Databind 2.8.11.5 / 2.9.10+ Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2019-14892EPSS 6% A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal… Decision Manager 2.6.7.3 / 2.8.11.5+ Fix from $2,3002020-03-02 MEDIUM 5.3 CVE-2018-8877 Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows rem… Asus Firmware 3.0.0.4.382.50470 / 384.4+ Fix from $1,6002020-02-27 MEDIUM 5.3 CVE-2018-8878 Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows rem… Asuswrt Merlin 3.0.0.4.382.50470 / 384.4+ Fix from $1,6002020-02-27 MEDIUM 6.5 CVE-2020-9337 In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request. Course Manager Mitigation only Fix from $1,6002020-02-26 HIGH 7.5 CVE-2020-5244 In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. Th… Buddypress 5.1.2+ Fix from $1,9502020-02-24 MEDIUM 5.5 CVE-2012-0844 Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar. Debian Linux after 2.8 Fix from $1,6002020-02-21 MEDIUM 5.9 CVE-2013-3587EPSS 6% The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted d… Big Ip Access Policy Manager after 12.1.2 Fix from $1,6002020-02-21 MEDIUM 6.5 CVE-2013-3551 Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS IT… Otrs 3.0.8 / 3.0.20+ Fix from $1,6002020-02-21 MEDIUM 6.5 CVE-2013-4088 Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not p… Otrs 3.0.21 / 3.1.17+ Fix from $1,6002020-02-21 MEDIUM 5.5 CVE-2011-4915 fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts. Linux Kernel after 3.1 Fix from $1,6002020-02-20 HIGH 7.5 CVE-2014-4019EPSS 13% ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows… Zxv10 W300 Firmware No fix yet Fix from $1,9502020-02-20 MEDIUM 5.5 CVE-2014-4658 The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtai… Ansible 1.5.5+ Fix from $1,6002020-02-20 HIGH 8.8 CVE-2020-9043EPSS 8% The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key. Wpcentral 1.5.1+ Fix from $1,9502020-02-17 HIGH 7.5 CVE-2019-6193 An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated… Xclarity Administrator 2.6.6+ Fix from $1,9502020-02-14 HIGH 7.5 CVE-2013-5687 RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure. Risknet Acquirer No fix yet Fix from $1,9502020-02-14 HIGH 7.5 CVE-2012-6091 Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability. Magento 1.7.0.2+ Fix from $1,9502020-02-13 MEDIUM 5.5 CVE-2018-3987 An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats… Viber No fix yet Fix from $1,6002020-02-13 MEDIUM 5.8 CVE-2020-6190 Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about th… Netweaver Application Server Java Mitigation only Fix from $1,6002020-02-12 HIGH 7.5 CVE-2011-3901 Android SQLite Journal before 4.0.1 has an information disclosure vulnerability. Android No fix yet Fix from $1,9502020-02-12 MEDIUM 5.9 CVE-2013-6681 Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability Tube Map 3.0.22+ Fix from $1,6002020-02-12 MEDIUM 6.5 CVE-2017-18642 Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to sniffing, reverse engineerin… Smartlight Rainbow Led Smart Bulb Firmware after 2017-08-06 Fix from $1,6002020-02-10 MEDIUM 5.7 CVE-2012-1994 HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information Systems Insight Manager 7.0+ Fix from $1,6002020-02-10