Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2018-15668 An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send ar… Airmail 3 Mitigation only Fix from $1,6002018-08-21 HIGH 7.5 CVE-2018-15661 An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with access… Ola Money Mitigation only Fix from $1,9502018-08-21 CRITICAL 9.8 CVE-2018-15534EPSS 32% Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a … Re Porter 16 Firmware 7.8.974.20+ Fix from $2,3002018-08-21 MEDIUM 5.3 CVE-2018-15599 The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validi… Debian Linux after 2018.76 Fix from $1,6002018-08-21 MEDIUM 5.5 CVE-2015-5160 libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen… Virtualization Mitigation only Fix from $1,6002018-08-20 HIGH 7.5 CVE-2018-14079 Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to obtain sensitive information via /Status/SystemStatusRpm.esp. Smart Hp Wmt Mitigation only Fix from $1,9502018-08-20 MEDIUM 6.5 CVE-2018-1000645 LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file dis… Librehealth Ehr 2.0.0+ Fix from $1,6002018-08-20 MEDIUM 6.7 CVE-2018-1000635 The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vulnerability in OMERO.server t… Omero after 5.4.6 Fix from $1,6002018-08-20 HIGH 7.2 CVE-2018-1000633 The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the login form a… Omero 5.4.7+ Fix from $1,9502018-08-20 MEDIUM 5.5 CVE-2018-15594 arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectr… Debian Linux 4.18.1+ Fix from $1,6002018-08-20 MEDIUM 5.3 CVE-2017-1732 IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attacke… Security Access Manager For Enterprise Single Sign On Patch available Fix from $1,6002018-08-17 MEDIUM 6.5 CVE-2018-15357 An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmware version 1.2.0. Esp 200 Firmware Mitigation only Fix from $1,6002018-08-17 MEDIUM 6.5 CVE-2018-8398EPSS 8% An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor… Windows 10 Mitigation only Fix from $1,6002018-08-15 MEDIUM 6.5 CVE-2018-8394EPSS 8% An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor… Windows 10 Mitigation only Fix from $1,6002018-08-15 MEDIUM 5.5 CVE-2018-8382EPSS 12% An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information… Excel Patch available Fix from $1,6002018-08-15 HIGH 7.5 CVE-2018-8360EPSS 9% An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environ… .net Framework Patch available Fix from $1,9502018-08-15 MEDIUM 5.6 CVE-2018-3646EPSS 8% Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in th… Core I3 Mitigation only Fix from $1,6002018-08-14 HIGH 8.1 CVE-2018-14348 libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information. Debian Linux after 0.41 Fix from $1,9502018-08-14 HIGH 7.5 CVE-2018-15125 Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface. Zipabox Firmware No fix yet Fix from $1,9502018-08-13 MEDIUM 5.0 CVE-2017-15138 The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook… Openshift Container Platform Patch available Fix from $1,6002018-08-13 MEDIUM 6.5 CVE-2017-1286 Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has b… Urbancode Deploy after 6.9.6.0 Fix from $1,6002018-08-13 HIGH 7.5 CVE-2018-14782 NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and pr… Nwl 25 Firmware after 2.0.29.11 Fix from $1,9502018-08-10 HIGH 7.5 CVE-2018-14785 NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without a… Nwl 25 Firmware after 2.0.29.11 Fix from $1,9502018-08-10 HIGH 7.5 CVE-2018-7686 Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage. Edirectory after 9.1.1 Fix from $1,9502018-08-09 HIGH 7.5 CVE-2018-10915EPSS 5% A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections… Openstack Patch available Fix from $1,9502018-08-09 HIGH 7.5 CVE-2018-14735 An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of mes… Compute Systems Manager 8.6.0-02 / 8.6.1-02+ Fix from $1,9502018-08-09 MEDIUM 5.5 CVE-2018-5953 The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by re… Linux Kernel after 4.14.14 Fix from $1,6002018-08-07 MEDIUM 5.5 CVE-2018-5995 The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by … Linux Kernel after 4.14.14 Fix from $1,6002018-08-07 HIGH 7.5 CVE-2018-15132EPSS 5% An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The link… PHP 5.6.37 / 7.0.31+ Fix from $1,9502018-08-07 MEDIUM 5.3 CVE-2017-2654 jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically… Email Extension 2.57.1+ Fix from $1,6002018-08-06