Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2018-18334 A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to byp… Dr. Safety 3.0.1478+ Fix from $1,9502019-02-05 MEDIUM 5.3 CVE-2017-1177 IBM BigFix Compliance 1.7 through 1.9.91 discloses sensitive information to unauthorized users. The information can be used to mount further attacks … Bigfix Compliance after 1.9.91 Fix from $1,6002019-02-05 MEDIUM 6.5 CVE-2018-15655 An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible. Suremdm 6.35+ Fix from $1,6002019-02-05 HIGH 7.5 CVE-2018-15656 An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/… Suremdm 2018-11-27+ Fix from $1,9502019-02-05 HIGH 7.5 CVE-2018-15658 An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to … Suremdm 2018-11-27+ Fix from $1,9502019-02-05 MEDIUM 6.5 CVE-2018-15659 An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications. Cross-origin access is possi… Suremdm 6.35+ Fix from $1,6002019-02-05 HIGH 7.5 CVE-2019-7388 An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers… Dir 823g Firmware No fix yet Fix from $1,9502019-02-05 HIGH 7.5 CVE-2018-1675 IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are … Tivoli Application Dependency Discovery Manager after 7.3.0.5 Fix from $1,9502019-02-04 MEDIUM 5.3 CVE-2019-7312 Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANSSI qualification submission) … Zed 1.0.195 / 1.0.199+ Fix from $1,6002019-02-03 CRITICAL 9.8 CVE-2018-18941 In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the v… Content Management No fix yet Fix from $2,3002019-01-31 MEDIUM 5.3 CVE-2018-19440 ARM Trusted Firmware-A allows information disclosure. Trusted Firmware A after 2.0 Fix from $1,6002019-01-30 MEDIUM 5.3 CVE-2018-12610 OX App Suite 7.8.4 and earlier allows Information Exposure. Open Xchange Appsuite after 7.8.4 Fix from $1,6002019-01-30 HIGH 7.5 CVE-2018-16889 Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files … Ceph after 13.2.4 Fix from $1,9502019-01-28 MEDIUM 6.5 CVE-2018-0187 A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential info… Identity Services Engine Mitigation only Fix from $1,6002019-01-23 MEDIUM 5.5 CVE-2017-18332 Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in version… Mdm9607 Firmware Mitigation only Fix from $1,6002019-01-18 MEDIUM 5.3 CVE-2018-19718 Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead to exposure of the privilege… Connect after 9.8.1 Fix from $1,6002019-01-18 MEDIUM 6.5 CVE-2019-0647 An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation … Team Foundation Server Patch available Fix from $1,6002019-01-17 HIGH 7.5 CVE-2018-5738EPSS 11% Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are p… Ubuntu Linux Mitigation only Fix from $1,9502019-01-16 MEDIUM 5.2 CVE-2019-3811 A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the… Debian Linux 2.1+ Fix from $1,6002019-01-15 HIGH 7.5 CVE-2019-3803 Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a us… Concourse 4.2.2+ Fix from $1,9502019-01-12 HIGH 7.5 CVE-2018-4217 In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing. Mac Os X 10.13.5+ Fix from $1,9502019-01-11 MEDIUM 5.5 CVE-2018-4179 In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic. Mac Os X 10.13.4+ Fix from $1,6002019-01-11 HIGH 7.5 CVE-2018-4185 In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transi… Iphone Os 4.3 / 10.13.4+ Fix from $1,9502019-01-11 HIGH 7.5 CVE-2018-4186 In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with ad… Safari 11.1+ Fix from $1,9502019-01-11 MEDIUM 6.5 CVE-2016-4643 In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing o… Apple Tv 9.2.2 / 9.3.3+ Fix from $1,6002019-01-11 MEDIUM 6.5 CVE-2016-4644 In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authent… Apple Tv 9.2.2 / 9.3.3+ Fix from $1,6002019-01-11 HIGH 8.8 CVE-2018-0474 A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view d… Unified Communications Manager Mitigation only Fix from $1,9502019-01-10 MEDIUM 5.9 CVE-2019-5884 php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set. Elfinder 2.1.45+ Fix from $1,6002019-01-10 MEDIUM 6.1 CVE-2018-20681 mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applicat… Mate Screensaver 1.20.2+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-16192 Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on t… Aterm Wf1200cr Firmware after 1.1.1 Fix from $1,6002019-01-09