Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2018-7668 TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php. Testlink after 1.9.16 Fix from $1,9502018-03-05 MEDIUM 5.3 CVE-2018-7662EPSS 47% Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/php… Couch after 2.0 Fix from $1,6002018-03-04 MEDIUM 5.3 CVE-2018-7661 Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests to TCP ports 8258 and 8257. Wifi Baby Monitor 2.02.2+ Fix from $1,6002018-03-04 HIGH 7.5 CVE-2017-9280 Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of use… Identity Manager 4.5.6.1+ Fix from $1,9502018-03-02 HIGH 7.1 CVE-2017-14461EPSS 17% A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive info… Debian Linux Patch available Fix from $1,9502018-03-02 HIGH 8.1 CVE-2017-6926 In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access t… Drupal 8.4.5+ Fix from $1,9502018-03-01 HIGH 7.5 CVE-2017-5188 The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source director… Open Build Service after 2.7.3 Fix from $1,9502018-03-01 MEDIUM 5.3 CVE-2016-0299 IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive informati… Tririga Application Platform 3.3.2.6 / 3.4.2.3+ Fix from $1,6002018-02-28 CRITICAL 9.1 CVE-2018-7556 LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installatio… Debian Linux 2.6.7 / 2.73.1+ Fix from $2,3002018-02-28 MEDIUM 6.5 CVE-2017-16770 File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.… Surveillance Station 8.1.2-5469+ Fix from $1,6002018-02-27 HIGH 7.5 CVE-2017-11635 An issue was discovered on Wireless IP Camera 360 devices. Attackers can read recordings by navigating to /mnt/idea0 or /mnt/idea1 on the SD memory c… Wireless Ip Camera 360 No fix yet Fix from $1,9502018-02-26 MEDIUM 5.5 CVE-2018-7250 An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped i… Windows 7 Mitigation only Fix from $1,6002018-02-26 MEDIUM 5.3 CVE-2017-1774 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount … Security Guardium Big Data Intelligence Mitigation only Fix from $1,6002018-02-26 HIGH 7.5 CVE-2017-15696 When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration req… Geode after 1.3.0 Fix from $1,9502018-02-26 HIGH 7.8 CVE-2017-15518 All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password.… Oncommand Api Services after 2.0 Fix from $1,9502018-02-23 MEDIUM 5.3 CVE-2017-16769 Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from pa… Photo Station Mitigation only Fix from $1,6002018-02-23 HIGH 7.5 CVE-2018-7317EPSS 8% Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. Proclaim No fix yet Fix from $1,9502018-02-22 HIGH 7.5 CVE-2018-7276 An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain potentially sensitive inform… Quantum Bacnet Integration Firmware No fix yet Fix from $1,9502018-02-21 MEDIUM 6.5 CVE-2018-7272 The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding… Access Management 5.5.0+ Fix from $1,6002018-02-21 MEDIUM 5.5 CVE-2018-7273 In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the fu… Linux Kernel after 4.15.4 Fix from $1,6002018-02-21 HIGH 7.5 CVE-2018-6487 Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, … Universal Cmdb Foundation Software No fix yet Fix from $1,9502018-02-20 MEDIUM 5.8 CVE-2018-5477 An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior,… Netcadops 7.2.10+ Fix from $1,6002018-02-20 MEDIUM 5.3 CVE-2015-9255 Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machine… Alto 3 Firmware Mitigation only Fix from $1,6002018-02-20 MEDIUM 5.3 CVE-2015-9256 Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not… Alto 3 Firmware Mitigation only Fix from $1,6002018-02-20 HIGH 7.5 CVE-2017-18192 smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to ac… Photo\,video Locker Calculator after 18.0 Fix from $1,9502018-02-20 CRITICAL 9.8 CVE-2018-7251EPSS 72% An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQ… Anchor No fix yet Fix from $2,3002018-02-19 MEDIUM 5.3 CVE-2018-6591 Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe p… Converse.js after 3.3 Fix from $1,6002018-02-19 HIGH 7.5 CVE-2018-7209 An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/conf… Idashboards after 9.6b Fix from $1,9502018-02-18 HIGH 7.5 CVE-2018-7210 An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=i… Idashboards after 9.6b Fix from $1,9502018-02-18 MEDIUM 5.3 CVE-2018-1000068 An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to acces… Jenkins after 2.106 Fix from $1,6002018-02-16