Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2017-16071 nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Nodemailer Js Mitigation only Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16072 nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Nodemailer.js Mitigation only Fix from $1,9502018-06-07 HIGH 7.5 CVE-2017-16073 noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Noderequest Mitigation only Fix from $1,9502018-06-07 MEDIUM 5.3 CVE-2017-1474 IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. … Security Access Manager after 9.0.3.1 Fix from $1,6002018-06-06 MEDIUM 5.9 CVE-2017-1476 IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive infor… Security Access Manager after 9.0.3.1 Fix from $1,6002018-06-06 MEDIUM 6.5 CVE-2018-1000196 A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/g… Gitlab Hook after 1.4.2 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000183 A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers w… GitHub after 1.29.0 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000186 A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that … Github Pull Request Builder after 1.41.0 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000187 A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in … Kubernetes after 1.7.0 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000190 A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildScanDescriptor.java that allows… Black Duck Hub after 4.0.0 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000191 A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java th… Synopsys Detect after 1.4.0 Fix from $1,6002018-06-05 MEDIUM 5.3 CVE-2018-10599 IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M an… Intellivue Mp2 Firmware Mitigation only Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1332 Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonat… Storm after 1.2.1 Fix from $1,6002018-06-05 HIGH 7.5 CVE-2018-1000181 Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a crafted URL resulting in informa… Kitura after 2.3.0 Fix from $1,9502018-06-05 CRITICAL 9.8 CVE-2018-11554 The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure… Yzmcms after 3.7 Fix from $2,3002018-06-05 HIGH 7.5 CVE-2017-12092 An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A sp… Micrologix 1400 B Firmware after 21.2 Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16044 `d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. D3.js Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16045 `jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Jquery.js Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16048 `node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Node Sqlite Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16049 `nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Nodesqlite Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16050 `sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Sqlite.js Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16051 `sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Sqliter Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16052 `node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Node Fabric Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16053 `fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Fabric Js Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16054 `nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Nodefabric Mitigation only Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16055 `sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. Sqlserver Mitigation only Fix from $1,9502018-06-04 MEDIUM 6.5 CVE-2017-16024 The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning… Node.js 0.11.9+ Fix from $1,6002018-06-04 MEDIUM 5.9 CVE-2017-16007 node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jo… Node Jose 0.9.3+ Fix from $1,6002018-06-04 MEDIUM 6.8 CVE-2018-11195 Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows ma… Mahara 17.04.8 / 17.10.5+ Fix from $1,6002018-06-01 MEDIUM 5.3 CVE-2018-3809 Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored. Serve No fix yet Fix from $1,6002018-06-01