Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
CRITICAL 9.8 CVE-2018-8919 Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers … Diskstation Manager 6.1.6-15266+ Fix from $2,3002018-12-24 CRITICAL 9.8 CVE-2018-20371 PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restr… Photorange Photo Vault No fix yet Fix from $2,3002018-12-23 HIGH 7.5 CVE-2018-18441 D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, suc… Dcs 936l Firmware No fix yet Fix from $1,9502018-12-20 MEDIUM 6.5 CVE-2018-17244 Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, L… Elasticsearch after 6.4.2 Fix from $1,6002018-12-20 MEDIUM 5.5 CVE-2018-16883 sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. I… Sssd 2.0.0+ Fix from $1,6002018-12-19 HIGH 7.5 CVE-2017-15031 In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world ti… Trusted Firmware A after 2.1 Fix from $1,9502018-12-18 HIGH 7.5 CVE-2018-7812 An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR020… Modicom M340 Firmware Mitigation only Fix from $1,9502018-12-17 MEDIUM 5.5 CVE-2018-19976 In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequenc… Yara No fix yet Fix from $1,6002018-12-17 MEDIUM 5.3 CVE-2017-1272 IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties h… Security Guardium after 10.5 Fix from $1,6002018-12-17 HIGH 7.5 CVE-2017-18355 Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "… Rendertron Patch available Fix from $1,9502018-12-17 MEDIUM 5.3 CVE-2018-20170 OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POS… Keystone after 14.0.1 Fix from $1,6002018-12-17 HIGH 7.5 CVE-2018-20151EPSS 6% In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration w… WordPress 4.9.9 / 5.0.1+ Fix from $1,9502018-12-14 MEDIUM 6.5 CVE-2018-19039EPSS 7% Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions. Grafana 4.6.5 / 5.3.3+ Fix from $1,6002018-12-13 MEDIUM 5.3 CVE-2018-1886 IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The info… Security Access Manager after 9.0.5.0 Fix from $1,6002018-12-13 MEDIUM 5.5 CVE-2018-13811 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort cou… Simatic Step 7 \(tia Portal\) 15.1+ Fix from $1,6002018-12-13 HIGH 7.5 CVE-2018-8033EPSS 26% In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via … Ofbiz after 16.11.04 Fix from $1,9502018-12-13 HIGH 7.5 CVE-2018-15718 Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command prompt. T… Opendental 18.4+ Fix from $1,9502018-12-12 MEDIUM 5.3 CVE-2018-1481 IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosur… Bigfix Platform after 9.5.9 Fix from $1,6002018-12-12 HIGH 7.5 CVE-2018-1476 IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. The information can be used to … Bigfix Platform after 9.5.9 Fix from $1,9502018-12-12 HIGH 7.5 CVE-2018-15328 On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and t… Big Ip Access Policy Manager after 13.1.1 Fix from $1,9502018-12-12 MEDIUM 6.5 CVE-2018-19968 An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker … Debian Linux 4.8.4+ Fix from $1,6002018-12-11 MEDIUM 6.8 CVE-2018-15800 Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing … Bits Service 2.18.0+ Fix from $1,6002018-12-10 MEDIUM 5.5 CVE-2018-1957 IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an inc… Websphere Application Server after 9.0.0.9 Fix from $1,6002018-12-10 HIGH 7.8 CVE-2018-19962 An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU m… Debian Linux after 4.11.1 Fix from $1,9502018-12-08 MEDIUM 5.9 CVE-2018-1663 IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to pro… Datapower Gateway after 7.7.1.3 Fix from $1,6002018-12-07 MEDIUM 5.9 CVE-2018-16602 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect… Amazon Web Services Freertos after 10.0.1 Fix from $1,6002018-12-06 MEDIUM 5.9 CVE-2018-16603 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect… Amazon Web Services Freertos after 10.0.1 Fix from $1,6002018-12-06 MEDIUM 5.9 CVE-2018-16524 Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen… Amazon Web Services Freertos after 10.0.1 Fix from $1,6002018-12-06 MEDIUM 5.9 CVE-2018-16527 Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen… Amazon Web Services Freertos after 10.0.1 Fix from $1,6002018-12-06 MEDIUM 5.9 CVE-2018-16599 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect… Amazon Web Services Freertos after 10.0.1 Fix from $1,6002018-12-06