Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
CRITICAL 9.8 CVE-2017-9000EPSS 6% ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x pr… Arubaos 6.3.1.25 / 6.4.4.16+ Fix from $2,3002018-08-06 MEDIUM 5.3 CVE-2018-7070 HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue … Centralview Fraud Risk Management 6.1+ Fix from $1,6002018-08-06 MEDIUM 5.3 CVE-2017-1409 IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized users. The information can be … Security Identity Governance And Intelligence Patch available Fix from $1,6002018-08-06 MEDIUM 6.5 CVE-2018-14941 Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for the /webapp.py URI. Nsg 9000 Mitigation only Fix from $1,6002018-08-05 HIGH 7.5 CVE-2018-14928 /contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter. Banco Mitigation only Fix from $1,9502018-08-03 HIGH 8.8 CVE-2018-1999040 An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attacke… Kubernetes after 1.10.1 Fix from $1,9502018-08-01 MEDIUM 5.5 CVE-2018-1999041 An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allow… Tinfoil Security after 1.6.1 Fix from $1,6002018-08-01 HIGH 7.8 CVE-2016-8637 A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio… Dracut 045+ Fix from $1,9502018-08-01 HIGH 8.8 CVE-2018-1999028 An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to ca… Accurev after 0.7.16 Fix from $1,9502018-08-01 MEDIUM 5.4 CVE-2018-1999030 An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in Artifactor… Maven Artifact Choicelistprovider \(nexus\) after 1.3.1 Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-1999031 An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows atta… Meliora Testlab after 1.14 Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-1999033 An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java … Container Image Scanner after 1.0.16 Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-14316 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction… Foxit Reader after 9.1.0.5096 Fix from $1,6002018-07-31 MEDIUM 6.5 CVE-2018-11620 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction… Foxit Reader after 9.1.0.5096 Fix from $1,6002018-07-31 MEDIUM 6.5 CVE-2018-11621 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction… Foxit Reader after 9.1.0.5096 Fix from $1,6002018-07-31 MEDIUM 5.3 CVE-2018-14432 In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may by… Debian Linux 11.0.4+ Fix from $1,6002018-07-31 HIGH 7.5 CVE-2018-5544 When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agent or a confirm box), the BIG-IP APM may disclose … Big Ip Access Policy Manager after 13.1.1 Fix from $1,9502018-07-31 CRITICAL 9.8 CVE-2018-14685 The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index… Gxlcms No fix yet Fix from $2,3002018-07-28 HIGH 7.0 CVE-2017-2624 It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the co… Debian Linux after 1.19.4 Fix from $1,9502018-07-27 HIGH 8.8 CVE-2017-12173 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner… Enterprise Linux Desktop 1.16.0+ Fix from $1,9502018-07-27 MEDIUM 5.5 CVE-2017-2622 An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic… Openstack Mitigation only Fix from $1,6002018-07-27 HIGH 7.5 CVE-2018-14602 An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclos… GitLab 10.8.7 / 11.0.5+ Fix from $1,9502018-07-27 MEDIUM 5.5 CVE-2017-12167 It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma… Jboss Enterprise Application Platform 7.0.9+ Fix from $1,6002018-07-26 MEDIUM 6.5 CVE-2017-2582 It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute … Keycloak 2.5.1+ Fix from $1,6002018-07-26 HIGH 7.1 CVE-2017-12163EPSS 8% An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A ma… Enterprise Linux Desktop 4.4.16 / 4.5.14+ Fix from $1,9502018-07-26 MEDIUM 6.8 CVE-2017-7526 libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right… Ubuntu Linux 1.7.8+ Fix from $1,6002018-07-26 HIGH 7.5 CVE-2018-14083 LICA miniCMTS E8K(u/i/...) devices allow remote attackers to obtain sensitive information via a direct POST request for the inc/user.ini file, leadin… Minicmts E8k Firmware No fix yet Fix from $1,9502018-07-25 CRITICAL 9.8 CVE-2018-10627 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An atta… Smartserver 1 Firmware 4.11.007+ Fix from $2,3002018-07-24 HIGH 7.5 CVE-2018-5386 Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an information leak. Infinity after 2.2 Fix from $1,9502018-07-24 HIGH 7.5 CVE-2016-5638 There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabi… Wndr4500 Firmware No fix yet Fix from $1,9502018-07-24