Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2018-6239 NVIDIA Jetson TX2 contains a vulnerability by means of speculative execution where local and unprivileged code may access the contents of cached info… Jetson Tx2 Mitigation only Fix from $1,6002019-04-12 CRITICAL 9.1 CVE-2019-0040 On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dro… Junos Mitigation only Fix from $2,3002019-04-10 MEDIUM 5.3 CVE-2018-13366 An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname… Fortios after 5.6.7 Fix from $1,6002019-04-09 MEDIUM 5.3 CVE-2019-10243 In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to … Kura after 4.0.0 Fix from $1,6002019-04-09 MEDIUM 5.3 CVE-2019-4051 Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system uuid, filesystem paths, netw… Api Connect after 2018.4.1.3 Fix from $1,6002019-04-08 MEDIUM 5.3 CVE-2018-1885 IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a spec… Business Automation Workflow after 8.5.0.2 Fix from $1,6002019-04-08 MEDIUM 5.5 CVE-2018-20449 The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information … Linux Kernel Patch available Fix from $1,6002019-04-04 MEDIUM 5.5 CVE-2018-11971 Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in Snapdragon Auto,… Mdm9206 Firmware Mitigation only Fix from $1,6002019-04-04 MEDIUM 5.5 CVE-2018-4431 A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tv… Iphone Os 5.1.2 / 10.14.2+ Fix from $1,6002019-04-03 MEDIUM 5.5 CVE-2018-4403 This issue was addressed by removing additional entitlements. This issue affected versions prior to macOS Mojave 10.14.1. Mac Os X 10.14.1+ Fix from $1,6002019-04-03 MEDIUM 5.5 CVE-2018-4379 A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked devi… Iphone Os 12.0.1+ Fix from $1,6002019-04-03 MEDIUM 5.5 CVE-2018-4380 A lock screen issue allowed access to photos and contacts on a locked device. This issue was addressed by restricting options offered on a locked dev… Iphone Os 12.1+ Fix from $1,6002019-04-03 MEDIUM 5.5 CVE-2018-4355 A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14. Iphone Os 10.14 / 12.0+ Fix from $1,6002019-04-03 MEDIUM 5.9 CVE-2018-4300 The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when th… Cups 2.2.10+ Fix from $1,6002019-04-03 HIGH 8.1 CVE-2018-4311 The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, … Safari 5.0 / 7.7+ Fix from $1,9502019-04-03 MEDIUM 5.5 CVE-2018-4289 An information disclosure issue was addressed by removing the vulnerable code. This issue affected versions prior to macOS High Sierra 10.13.6. Mac Os X 10.13.6+ Fix from $1,6002019-04-03 MEDIUM 5.5 CVE-2018-4052 An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker… Galaxy Mitigation only Fix from $1,6002019-04-02 MEDIUM 6.5 CVE-2018-1917 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM … Infosphere Information Server Mitigation only Fix from $1,6002019-04-02 MEDIUM 5.3 CVE-2018-13288 Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attacker… File Station 1.1.5-0125 / 1.2.2-0250+ Fix from $1,6002019-04-01 MEDIUM 5.3 CVE-2018-13289 Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain … Router Manager 1.1.7-6941-2+ Fix from $1,6002019-04-01 MEDIUM 6.5 CVE-2018-13294 Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to ob… Application Service 1.5.4-0320+ Fix from $1,6002019-04-01 MEDIUM 6.5 CVE-2018-13295 Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated us… Application Service 1.5.4-0320+ Fix from $1,6002019-04-01 MEDIUM 5.3 CVE-2018-13297 Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive syste… Drive Server 1.1.2-10562+ Fix from $1,6002019-04-01 HIGH 7.2 CVE-2019-3869 When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A mal… Ansible Tower 3.3.5 / 3.4.3+ Fix from $1,9502019-03-28 HIGH 7.5 CVE-2018-19643 Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. Solutions Business Manager 11.5+ Fix from $1,9502019-03-27 HIGH 7.5 CVE-2015-1012 Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA … Lifecare Pca Infusion System Firmware after 5.0 Fix from $1,9502019-03-25 HIGH 8.8 CVE-2017-7510 In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface. Ovirt Engine Mitigation only Fix from $1,9502019-03-25 HIGH 7.5 CVE-2015-3952 Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, an… Plum A\+ Infusion System Firmware after 13.6 Fix from $1,9502019-03-25 MEDIUM 6.5 CVE-2019-7429 PHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as the wp-con… Property Rental Software No fix yet Fix from $1,6002019-03-21 MEDIUM 6.5 CVE-2019-7431 PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory. Image Sharing Script No fix yet Fix from $1,6002019-03-21