Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.0 CVE-2018-12158 Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a privileged user to potentially t… Next Unit Of Computing Firmware 2018-05-24+ Fix from $1,6002018-10-10 MEDIUM 6.5 CVE-2018-12161 Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated user to potentially disclose … Raid Web Console after 3.0 Fix from $1,6002018-10-10 MEDIUM 5.3 CVE-2018-17917 All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud … Xmeye P2p Cloud Server Mitigation only Fix from $1,6002018-10-10 MEDIUM 5.5 CVE-2018-8427 An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Compon… Excel Viewer Patch available Fix from $1,6002018-10-10 MEDIUM 5.5 CVE-2018-8472EPSS 19% An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an att… Windows 10 Patch available Fix from $1,6002018-10-10 HIGH 7.5 CVE-2018-8292EPSS 15% An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core In… Asp.net Core Patch available Fix from $1,9502018-10-10 MEDIUM 5.5 CVE-2018-8330 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosu… Windows 10 Patch available Fix from $1,6002018-10-10 MEDIUM 5.3 CVE-2018-1743 IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The information can be used to mount furthe… Security Key Lifecycle Manager after 3.0.0.1 Fix from $1,6002018-10-08 MEDIUM 5.3 CVE-2018-1000803 Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appea… Gitea 1.5.1+ Fix from $1,6002018-10-08 MEDIUM 5.5 CVE-2018-15407 A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. T… Hyperflex Hx Data Platform Mitigation only Fix from $1,6002018-10-05 CRITICAL 9.8 CVE-2018-0425 A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, … Rv110w Firmware 1.0.3.44+ Fix from $2,3002018-10-05 MEDIUM 5.5 CVE-2018-1723 IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node… Spectrum Scale after 5.0.1.2 Fix from $1,6002018-10-05 HIGH 7.5 CVE-2014-10076 The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read … Wp Db Backup No fix yet Fix from $1,9502018-10-05 MEDIUM 5.3 CVE-2018-13258 Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible. Mediawiki after 1.31.1 Fix from $1,6002018-10-04 MEDIUM 5.3 CVE-2017-5658 The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead… Pony Mail after 0.9 Fix from $1,6002018-10-04 MEDIUM 6.5 CVE-2018-16051 An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned U… GitLab 11.0.6 / 11.1.5+ Fix from $1,6002018-10-03 CRITICAL 9.8 CVE-2018-14822 Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may a… Emg 12 Firmware after 2.57 Fix from $2,3002018-10-02 HIGH 7.5 CVE-2015-9269 The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obt… Wordpress Mobile Pack 2.1.3+ Fix from $1,9502018-10-01 MEDIUM 6.5 CVE-2018-17216 An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users. Thingworx Platform after 8.2 Fix from $1,6002018-10-01 MEDIUM 6.5 CVE-2018-17780 Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because o… Telegram Desktop No fix yet Fix from $1,6002018-09-29 HIGH 7.5 CVE-2018-17781 Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer … Phantompdf after 9.2.0.9297 Fix from $1,9502018-09-29 MEDIUM 5.5 CVE-2018-17155 In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initializa… FreeBSD 11.2+ Fix from $1,6002018-09-28 MEDIUM 6.5 CVE-2018-16712 IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to sen… Advanced Systemcare after 1.2.0.5 Fix from $1,6002018-09-26 HIGH 7.5 CVE-2018-17555 The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /snmpGet oids parameter. Arris Tg2492lg Na Firmware No fix yet Fix from $1,9502018-09-26 MEDIUM 5.3 CVE-2018-14803 Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that could allow at… E Alert Firmware Mitigation only Fix from $1,6002018-09-26 MEDIUM 6.5 CVE-2018-16672 An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /servi… Circarlife Scada 4.3+ Fix from $1,6002018-09-26 MEDIUM 5.5 CVE-2018-7907 Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, A… Agassi L09 Firmware Mitigation only Fix from $1,6002018-09-26 MEDIUM 6.5 CVE-2018-6045 Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file dat… Chrome 64.0.3282.119+ Fix from $1,6002018-09-25 MEDIUM 6.5 CVE-2018-6037 Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient … Chrome 64.0.3282.119+ Fix from $1,6002018-09-25 HIGH 8.8 CVE-2018-6035 Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file dat… Chrome 64.0.3282.119+ Fix from $1,9502018-09-25