Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2019-1293 An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, … Windows 10 Patch available Fix from $1,6002019-09-11 MEDIUM 5.5 CVE-2019-1251 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos… Windows 10 Patch available Fix from $1,6002019-09-11 MEDIUM 6.5 CVE-2019-1252EPSS 61% An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor… Windows 10 Patch available Fix from $1,6002019-09-11 MEDIUM 5.5 CVE-2019-1263EPSS 8% An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information… Excel Patch available Fix from $1,6002019-09-11 MEDIUM 6.5 CVE-2019-1244EPSS 12% An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos… Windows 10 Patch available Fix from $1,6002019-09-11 MEDIUM 6.5 CVE-2019-1245EPSS 13% An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos… Windows 10 Patch available Fix from $1,6002019-09-11 MEDIUM 6.5 CVE-2019-1209EPSS 6% An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'. Lync Patch available Fix from $1,6002019-09-11 MEDIUM 5.5 CVE-2019-1216 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. Windows 10 Patch available Fix from $1,6002019-09-11 MEDIUM 5.5 CVE-2019-1219 An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Ma… Windows 10 Patch available Fix from $1,6002019-09-11 HIGH 7.5 CVE-2019-0352 In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502019-09-10 HIGH 7.5 CVE-2019-16177 In Limesurvey before 3.17.14, the entire database is exposed through browser caching. Limesurvey 3.17.14+ Fix from $1,9502019-09-09 HIGH 7.5 CVE-2019-11605 An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allow… GitLab 11.8.10 / 11.9.11+ Fix from $1,9502019-09-09 MEDIUM 5.3 CVE-2019-5463 An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnera… GitLab 11.11.7 / 12.0.4+ Fix from $1,6002019-09-09 HIGH 7.5 CVE-2018-21011 The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details. Charitable 1.5.14+ Fix from $1,9502019-09-09 MEDIUM 5.3 CVE-2019-10667 An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and … Librenms after 1.47 Fix from $1,6002019-09-09 MEDIUM 5.5 CVE-2019-2103 In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. Thi… Android Patch available Fix from $1,6002019-09-05 CRITICAL 9.8 CVE-2019-1976 A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remo… Industrial Network Director 1.6.0+ Fix from $2,3002019-09-05 MEDIUM 5.6 CVE-2019-15902 A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x … Linux Kernel after 5.2.11 Fix from $1,6002019-09-04 CRITICAL 9.8 CVE-2019-11064 A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration… Vd 1 Firmware after 230 Fix from $2,3002019-08-29 MEDIUM 5.3 CVE-2018-13367 An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as ve… Fortios after 6.2.0 Fix from $1,6002019-08-23 MEDIUM 5.3 CVE-2014-10388 The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure. Wp Support Plus Responsive Ticket System 4.2+ Fix from $1,6002019-08-22 CRITICAL 9.8 CVE-2019-6177 A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standa… Solution Center Mitigation only Fix from $2,3002019-08-21 HIGH 7.5 CVE-2019-1908 A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an… Unified Computing System 2.0 / 3.0+ Fix from $1,9502019-08-21 MEDIUM 5.3 CVE-2019-15045 AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality Manageengine Servicedesk Plus 10509+ Fix from $1,6002019-08-21 MEDIUM 6.5 CVE-2019-12746 An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS… Debian Linux after 6.0.19 Fix from $1,6002019-08-21 MEDIUM 5.3 CVE-2019-4437 IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID… Api Connect after 2018.4.1.6 Fix from $1,6002019-08-20 MEDIUM 5.5 CVE-2017-18550 An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory becaus… Linux Kernel 4.13+ Fix from $1,6002019-08-19 MEDIUM 5.5 CVE-2017-18549 An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory becaus… Linux Kernel 4.13+ Fix from $1,6002019-08-19 HIGH 7.5 CVE-2018-14669 ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arb… Clickhouse 1.1.54390+ Fix from $1,9502019-08-15 MEDIUM 5.3 CVE-2019-14800 The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-ad… Fv Flowplayer Video Player 7.3.15.727+ Fix from $1,6002019-08-15