Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2019-7434 PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory. Rental Bike Script No fix yet Fix from $1,6002019-03-21 MEDIUM 6.5 CVE-2019-7436 PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory. Opensource Classified Ads Script No fix yet Fix from $1,6002019-03-21 CRITICAL 9.8 CVE-2018-20555EPSS 10% The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, con… Social Network Tabs No fix yet Fix from $2,3002019-03-21 HIGH 7.5 CVE-2018-19487 The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the adm… Wp Jobhunt 2.4+ Fix from $1,9502019-03-21 MEDIUM 6.5 CVE-2018-18762EPSS 6% SaltOS 3.1 r8126 contains a database download vulnerability. Saltos No fix yet Fix from $1,6002019-03-21 MEDIUM 5.5 CVE-2018-17482 Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the … Lobby Track Mitigation only Fix from $1,6002019-03-21 MEDIUM 5.5 CVE-2018-17483 Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the … Lobby Track Mitigation only Fix from $1,6002019-03-21 HIGH 7.1 CVE-2018-17484 Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk m… Lobby Track Mitigation only Fix from $1,9502019-03-21 HIGH 7.8 CVE-2018-17956 In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samb… Yast2 Samba Provision after 1.0.1 Fix from $1,9502019-03-15 HIGH 7.5 CVE-2018-18205 Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebContent/startup.tar.gz with use… Cc8800ce Firmware Mitigation only Fix from $1,9502019-03-15 CRITICAL 9.1 CVE-2015-2254 Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change patch loading information resu… Oceanstor Uds Firmware 100r002c01spc102+ Fix from $2,3002019-03-13 MEDIUM 6.8 CVE-2019-3615 Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose… Database Security after 4.6.6 Fix from $1,6002019-03-12 MEDIUM 6.5 CVE-2018-2009 IBM API Connect v2018.1 and 2018.4.1 is affected by an information disclosure vulnerability in the consumer API. Any registered user can obtain a lis… Api Connect after 2018.4.1.0 Fix from $1,6002019-03-11 HIGH 7.5 CVE-2018-11783 sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plug… Traffic Server after 8.0.1 Fix from $1,9502019-03-07 HIGH 8.8 CVE-2019-3781 Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remo… Command Line Interface 6.43.0+ Fix from $1,9502019-03-07 CRITICAL 9.8 CVE-2019-6206 An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.… Iphone Os 12.1.3+ Fix from $2,3002019-03-04 MEDIUM 5.3 CVE-2018-12400 In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows informati… Firefox 63.0+ Fix from $1,6002019-02-28 HIGH 7.1 CVE-2018-12397 A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being… Firefox 60.3.0 / 63.0+ Fix from $1,9502019-02-28 MEDIUM 5.3 CVE-2019-4061EPSS 23% IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to … Bigfix Platform after 9.5.11 Fix from $1,6002019-02-27 MEDIUM 6.5 CVE-2018-1775 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated u… Spectrum Virtualize Software after 8.2 Fix from $1,6002019-02-27 MEDIUM 5.5 CVE-2018-11845 Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdragon Auto, Snapdragon Compute,… Mdm9150 Firmware Mitigation only Fix from $1,6002019-02-25 HIGH 7.5 CVE-2019-9126 An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via requests for the router_info.xml d… Dir 825 Rev.b Firmware No fix yet Fix from $1,9502019-02-25 MEDIUM 5.3 CVE-2014-10079EPSS 9% In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML so… Storegrid No fix yet Fix from $1,6002019-02-23 HIGH 7.5 CVE-2019-1681EPSS 6% A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthenticated, remote attacker to retri… Ios Xr 6.5.2+ Fix from $1,9502019-02-21 MEDIUM 5.5 CVE-2019-3610 Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidenti… True Key after 3.1.9211.0 Fix from $1,6002019-02-13 MEDIUM 5.5 CVE-2018-12006 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potenti… Android Patch available Fix from $1,6002019-02-11 HIGH 7.5 CVE-2018-20776 Frog CMS 0.9.5 provides a directory listing for a /public request. Frog Cms No fix yet Fix from $1,9502019-02-11 MEDIUM 5.9 CVE-2019-7628 Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to … Pagure Patch available Fix from $1,6002019-02-08 HIGH 7.5 CVE-2018-1296 In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs,… Hadoop after 2.7.5 Fix from $1,9502019-02-07 MEDIUM 5.3 CVE-2019-7535 index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and… Testrail Mitigation only Fix from $1,6002019-02-07