Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2018-16849 A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbit… Openstack Mistral 7.0.1+ Fix from $1,9502018-11-02 MEDIUM 5.3 CVE-2018-1878 IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks aga… Robotic Process Automation With Automation Anywhere Patch available Fix from $1,6002018-11-02 HIGH 7.5 CVE-2018-3928 An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of U… Yi Home Camera Firmware No fix yet Fix from $1,9502018-11-01 HIGH 8.1 CVE-2018-3947 An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D. An attacker can sni… Yi Home Camera Firmware No fix yet Fix from $1,9502018-11-01 MEDIUM 5.3 CVE-2018-16467 A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares. Nextcloud Server 14.0.0+ Fix from $1,6002018-10-30 MEDIUM 6.5 CVE-2018-18778EPSS 71% ACME mini_httpd before 1.30 lets remote users read arbitrary files. Mini Httpd 1.30+ Fix from $1,6002018-10-29 MEDIUM 5.5 CVE-2018-18710 An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by lo… Linux Kernel after 4.19 Fix from $1,6002018-10-29 HIGH 7.5 CVE-2018-18657 An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Informat… Udp Patch available Fix from $1,9502018-10-26 HIGH 7.5 CVE-2018-18658 An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Informat… Udp Patch available Fix from $1,9502018-10-26 MEDIUM 5.3 CVE-2018-18566 The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information… Unified Communications Software after 5.8.0.12848 Fix from $1,6002018-10-24 HIGH 7.5 CVE-2018-18467 An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing opened conversation by sending… Conversations Patch available Fix from $1,9502018-10-23 MEDIUM 5.5 CVE-2017-18300 Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile… Mdm9206 Firmware Mitigation only Fix from $1,6002018-10-23 HIGH 7.5 CVE-2018-18428EPSS 11% TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI. Tl Sc3130 Firmware No fix yet Fix from $1,9502018-10-19 CRITICAL 9.8 CVE-2018-12671 An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can d… H.264 Poe Ip Camera Firmware No fix yet Fix from $2,3002018-10-19 HIGH 7.5 CVE-2018-12673 An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can d… H.264 Poe Ip Camera Firmware No fix yet Fix from $1,9502018-10-19 HIGH 7.5 CVE-2018-18390 User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. Thingspro Mitigation only Fix from $1,9502018-10-19 MEDIUM 5.5 CVE-2018-15765 Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive … Emc Secure Remote Services 3.32.00.08+ Fix from $1,6002018-10-18 HIGH 7.5 CVE-2018-18487 In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable d… Gxlcms No fix yet Fix from $1,9502018-10-18 MEDIUM 6.5 CVE-2018-12373 dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affect… Enterprise Linux 52.9.0+ Fix from $1,6002018-10-18 MEDIUM 6.5 CVE-2018-12372 Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability a… Enterprise Linux 52.9.0+ Fix from $1,6002018-10-18 MEDIUM 6.5 CVE-2018-12365 A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or inter… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-10-18 HIGH 7.5 CVE-2018-0442 A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software… Wireless Lan Controller Software 8.2.170.0 / 8.3.140.0+ Fix from $1,9502018-10-17 MEDIUM 5.3 CVE-2018-14597 CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error mes… Ca Identity Governance after 14.2 Fix from $1,6002018-10-17 HIGH 7.5 CVE-2018-18376 goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnam… Airbox Firmware No fix yet Fix from $1,9502018-10-16 MEDIUM 6.3 CVE-2018-18073 Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack… Debian Linux Patch available Fix from $1,6002018-10-15 MEDIUM 5.3 CVE-2018-18287 On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source … Rt Ac58u Firmware No fix yet Fix from $1,6002018-10-14 HIGH 7.5 CVE-2018-18289 The MESILAT Zabbix plugin before 1.1.15 for Atlassian Confluence allows attackers to read arbitrary files. Zabbix 1.1.15+ Fix from $1,9502018-10-14 HIGH 7.5 CVE-2018-8890 An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user… Unified Endpoint Manager Mitigation only Fix from $1,9502018-10-12 MEDIUM 6.5 CVE-2018-1838 IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling o… Websphere Application Server Mitigation only Fix from $1,6002018-10-12 MEDIUM 6.5 CVE-2018-1708 IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. I… Platform Symphony Patch available Fix from $1,6002018-10-11