Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2019-5601 In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a b… FreeBSD No fix yet Fix from $1,6002019-07-03 MEDIUM 6.5 CVE-2018-14865 Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passin… Odoo Patch available Fix from $1,6002019-07-03 CRITICAL 9.8 CVE-2018-11215 Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors. Data Science Workbench after 1.3.0 Fix from $2,3002019-07-03 MEDIUM 5.9 CVE-2017-11578 It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web m… Wi Fi Blood Pressure Monitor Firmware No fix yet Fix from $1,6002019-07-02 HIGH 8.8 CVE-2019-7259EPSS 13% Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure. Linear Emerge Essential Firmware after 1.00-06 Fix from $1,9502019-07-02 HIGH 7.1 CVE-2019-4140 IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IB… Spectrum Protect 7.1.9.300 / 8.1.8.0+ Fix from $1,9502019-07-02 MEDIUM 5.3 CVE-2019-13075 Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involvin… Tor Browser after 8.5.3 Fix from $1,6002019-06-30 MEDIUM 6.5 CVE-2019-13055 Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency tra… Unifying Receiver Firmware No fix yet Fix from $1,6002019-06-29 MEDIUM 6.5 CVE-2019-10175 A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine wheth… Containerized Data Importer Mitigation only Fix from $1,6002019-06-28 MEDIUM 5.3 CVE-2018-20811 A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12. Connect Secure No fix yet Fix from $1,6002019-06-28 HIGH 7.5 CVE-2018-20812 An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse S… Pulse Secure Desktop Client Mitigation only Fix from $1,9502019-06-28 MEDIUM 6.5 CVE-2018-6150 Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted… Chrome 66.0.3359.117+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-6159 Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive inf… Chrome 68.0.3440.75+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-6168 Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from pr… Chrome 68.0.3440.75+ Fix from $1,6002019-06-27 MEDIUM 5.5 CVE-2018-20073 Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem. Chrome 72.0.3626.81+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-6134 Information leak in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. Chrome 67.0.3396.62+ Fix from $1,6002019-06-27 MEDIUM 5.3 CVE-2018-2011 IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could ai… Api Connect after 2018.4.1.5 Fix from $1,6002019-06-25 MEDIUM 5.3 CVE-2018-2013 IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the … Api Connect after 2018.4.1.5 Fix from $1,6002019-06-25 HIGH 7.5 CVE-2014-9699 The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs, design files (i.e., a histor… Replicator 5th Generation Firmware Mitigation only Fix from $1,9502019-06-24 HIGH 7.5 CVE-2019-11648 An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be… Self Service Password Reset 4.4+ Fix from $1,9502019-06-24 MEDIUM 5.3 CVE-2018-15665 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts. Data Science Workbench after 1.4.0 Fix from $1,6002019-06-21 CRITICAL 9.8 CVE-2016-7404 OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the inst… Magnum Patch available Fix from $2,3002019-06-21 HIGH 7.5 CVE-2019-11233 EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element to the au… Biyan after 2.8 Fix from $1,9502019-06-19 HIGH 8.8 CVE-2017-8337 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of… Almond 2015 Firmware No fix yet Fix from $1,9502019-06-18 MEDIUM 5.3 CVE-2018-18839 An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "is intentional. Netdata Patch available Fix from $1,6002019-06-18 MEDIUM 6.5 CVE-2017-10719 Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-F… Endoscope Camera Firmware No fix yet Fix from $1,6002019-06-17 CRITICAL 9.1 CVE-2019-5016 An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of… R8000 Firmware Mitigation only Fix from $2,3002019-06-17 MEDIUM 5.3 CVE-2019-5017 An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadySHARE Printer functionality of… R8000 Firmware Mitigation only Fix from $1,6002019-06-17 HIGH 7.2 CVE-2019-11407 app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessiv… Fusionpbx Patch available Fix from $1,9502019-06-17 MEDIUM 5.3 CVE-2019-12497 An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x… Debian Linux after 7.0.8 Fix from $1,6002019-06-17