Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2018-8271 An information disclosure vulnerability exists in Windows when the Windows bowser.sys kernel-mode driver fails to properly handle objects in memory, … Windows 10 Patch available Fix from $1,6002018-09-13 MEDIUM 5.3 CVE-2018-16977 Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHandler/Resources/Views/Err… Monstra No fix yet Fix from $1,6002018-09-12 MEDIUM 6.5 CVE-2018-7921EPSS 13% Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this… B315s 22 Firmware No fix yet Fix from $1,6002018-09-12 HIGH 7.5 CVE-2018-16948 An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables … Debian Linux 1.6.23 / 1.8.2+ Fix from $1,9502018-09-12 MEDIUM 5.9 CVE-2016-0715 Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote informatio… Cloud Foundry Elastic Runtime after 1.6.11 Fix from $1,6002018-09-11 CRITICAL 9.8 CVE-2018-16705 FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords.… Felcom 250 Firmware No fix yet Fix from $2,3002018-09-10 MEDIUM 6.5 CVE-2016-7061 An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC… Jboss Enterprise Application Platform 7.0.4+ Fix from $1,6002018-09-10 MEDIUM 5.5 CVE-2017-1679 IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 13400… Openpages Grc Platform Patch available Fix from $1,6002018-09-10 CRITICAL 9.1 CVE-2018-16710 OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: th… Octoprint after 1.3.9 Fix from $2,3002018-09-07 MEDIUM 6.1 CVE-2018-16658 An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by … Linux Kernel 4.18.6+ Fix from $1,6002018-09-07 HIGH 7.5 CVE-2018-16307 An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to … Xiaomi Miwifi Xiaomi 55dd Firmware No fix yet Fix from $1,9502018-09-05 MEDIUM 5.3 CVE-2018-15684 An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictable file names, which can lead… Xbtit after 2.5.4 Fix from $1,6002018-09-05 MEDIUM 5.5 CVE-2018-16539 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to di… Ubuntu Linux Patch available Fix from $1,6002018-09-05 HIGH 8.1 CVE-2018-10927 A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and exec… Debian Linux 3.12.14 / 4.1.8+ Fix from $1,9502018-09-04 HIGH 7.5 CVE-2018-10911 A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read… Virtualization Host 3.12.14 / 4.1.8+ Fix from $1,9502018-09-04 MEDIUM 6.5 CVE-2018-10913 An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine t… Virtualization Host 3.12.14 / 4.1.8+ Fix from $1,6002018-09-04 MEDIUM 6.5 CVE-2018-16323EPSS 49% ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If … Ubuntu Linux 6.9.10-9 / 7.0.8-9+ Fix from $1,6002018-09-01 HIGH 7.5 CVE-2018-14902 The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access. This allows an attacker's application t… Iprint No fix yet Fix from $1,9502018-08-30 MEDIUM 5.3 CVE-2014-6048EPSS 6% phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request. Phpmyfaq 2.8.13+ Fix from $1,6002018-08-28 MEDIUM 5.3 CVE-2018-13391 The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7… Jira 7.6.8 / 7.7.5+ Fix from $1,6002018-08-28 MEDIUM 6.5 CVE-2018-1705 IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could… Platform Symphony Mitigation only Fix from $1,6002018-08-28 MEDIUM 5.3 CVE-2018-15919 Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system… Openssh after 7.8 Fix from $1,6002018-08-28 HIGH 7.5 CVE-2017-15139 A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configura… Openstack after 12.0.4-7 Fix from $1,9502018-08-27 MEDIUM 6.5 CVE-2018-15697 ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For … Data Master after 3.1.5 Fix from $1,6002018-08-27 MEDIUM 6.5 CVE-2018-15698 ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full … Data Master after 3.1.5 Fix from $1,6002018-08-27 CRITICAL 9.8 CVE-2017-18345 The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an… Joomanager after 2.0.0 Fix from $2,3002018-08-26 CRITICAL 9.8 CVE-2018-11653 Information disclosure in Netwave IP camera at //etc/RT2870STA.dat (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive… Ip Camera Firmware No fix yet Fix from $2,3002018-08-24 HIGH 7.5 CVE-2018-11654 Information disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive info… Ip Camera Firmware No fix yet Fix from $1,9502018-08-24 MEDIUM 5.9 CVE-2018-1755 IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when… Websphere Application Server Patch available Fix from $1,6002018-08-24 MEDIUM 6.5 CVE-2018-10919 The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated at… Ubuntu Linux 4.6.16 / 4.7.9+ Fix from $1,6002018-08-22