Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2019-18987 An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been ma… Abusefilter after 1.34 Fix from $1,6002019-11-15 HIGH 7.5 CVE-2013-3070 An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK… Wndr4700 Firmware Patch available Fix from $1,9502019-11-14 MEDIUM 5.3 CVE-2012-1169 Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are show… Moodle 2.2.2+ Fix from $1,6002019-11-14 HIGH 7.5 CVE-2012-1155 Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from … Moodle 1.9.17 / 2.0.8+ Fix from $1,9502019-11-14 HIGH 7.5 CVE-2011-4972 hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to rea… Ckeditor Patch available Fix from $1,9502019-11-13 HIGH 7.5 CVE-2019-14365 The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the vict… Intercom after 1.2.1 Fix from $1,9502019-11-12 HIGH 7.5 CVE-2019-14366 WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the vict… Wp Slacksync after 1.8.5 Fix from $1,9502019-11-12 HIGH 7.5 CVE-2019-14367 Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, m… Slack Chat after 1.5.5 Fix from $1,9502019-11-12 MEDIUM 5.5 CVE-2019-1436 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure V… Windows 10 Patch available Fix from $1,6002019-11-12 MEDIUM 6.5 CVE-2019-1439EPSS 76% An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor… Windows 10 Patch available Fix from $1,6002019-11-12 MEDIUM 5.5 CVE-2019-1440 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure V… Windows 10 Patch available Fix from $1,6002019-11-12 MEDIUM 5.5 CVE-2019-1446EPSS 8% An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information… Excel Patch available Fix from $1,6002019-11-12 MEDIUM 5.5 CVE-2019-1402 An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Micros… Office Patch available Fix from $1,6002019-11-12 MEDIUM 5.5 CVE-2019-1374EPSS 7% An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Infor… Windows 10 Patch available Fix from $1,6002019-11-12 MEDIUM 5.5 CVE-2019-1381 An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows … Windows 10 Patch available Fix from $1,6002019-11-12 MEDIUM 5.3 CVE-2019-1324 An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP… Windows 10 Patch available Fix from $1,6002019-11-12 MEDIUM 5.5 CVE-2019-1370 An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Inf… Open Enclave Software Development Kit after 0.7.0 Fix from $1,6002019-11-12 HIGH 7.5 CVE-2018-21026 A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information. Device Manager 8.6.5-00 / 8.7.0-00+ Fix from $1,9502019-11-12 MEDIUM 5.3 CVE-2019-4412 IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to … Cognos Controller Patch available Fix from $1,6002019-11-09 MEDIUM 5.3 CVE-2019-13557 In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access … Tasy Emr after 3.02.1757 Fix from $1,6002019-11-08 MEDIUM 6.5 CVE-2008-5083 In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON. Jboss Operations Network 2.1.2+ Fix from $1,6002019-11-08 HIGH 7.5 CVE-2010-2450 The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed … Debian Linux Patch available Fix from $1,9502019-11-07 MEDIUM 6.2 CVE-2019-3422 The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of… Mf910s Firmware No fix yet Fix from $1,6002019-11-07 HIGH 7.5 CVE-2009-5045 Dump Servlet information leak in jetty before 6.1.22. Debian Linux 6.1.22+ Fix from $1,9502019-11-06 MEDIUM 6.5 CVE-2011-4900 TYPO3 before 4.5.4 allows Information Disclosure in the backend. TYPO3 4.5.4+ Fix from $1,6002019-11-06 MEDIUM 6.5 CVE-2011-4901 TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database. TYPO3 4.3.12 / 4.4.9+ Fix from $1,6002019-11-06 MEDIUM 6.5 CVE-2011-4627 TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend. TYPO3 4.3.12 / 4.4.9+ Fix from $1,6002019-11-06 MEDIUM 5.5 CVE-2019-1734 A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local… Firepower Extensible Operating System 2.2.2.91 / 2.3.1.111+ Fix from $1,6002019-11-05 MEDIUM 6.5 CVE-2019-1877 A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through… Enterprise Chat And Email No fix yet Fix from $1,6002019-11-05 MEDIUM 5.3 CVE-2010-3673 TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API. TYPO3 4.2.13 / 4.3.4+ Fix from $1,6002019-11-05