Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2012-3331 IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID… Sametime Mitigation only Fix from $1,6002018-02-08 MEDIUM 5.3 CVE-2018-6846 Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php. Z Blogphp Mitigation only Fix from $1,6002018-02-08 MEDIUM 6.5 CVE-2018-0140 A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated… Email Security Appliance Firmware Mitigation only Fix from $1,6002018-02-08 CRITICAL 9.8 CVE-2018-0127EPSS 77% A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unau… Rv132w Firmware Mitigation only Fix from $2,3002018-02-08 MEDIUM 5.3 CVE-2018-0134 A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subs… Mobility Services Engine Mitigation only Fix from $1,6002018-02-08 HIGH 7.5 CVE-2018-1388 GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212. Websphere Mq Mitigation only Fix from $1,9502018-02-07 MEDIUM 6.5 CVE-2018-6806 Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview… Marked 2 after 2.5.11 Fix from $1,6002018-02-07 MEDIUM 5.3 CVE-2018-6790 An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover … Plasma Workspace 5.12.0+ Fix from $1,6002018-02-07 MEDIUM 5.5 CVE-2016-3954 web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: t… Web2py 2.14.2+ Fix from $1,6002018-02-06 MEDIUM 6.5 CVE-2017-6200 Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is… Sandstorm 0.203+ Fix from $1,6002018-02-06 HIGH 7.5 CVE-2018-6610EPSS 8% Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request. Jlike No fix yet Fix from $1,9502018-02-05 HIGH 7.8 CVE-2015-1418 The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1… FreeBSD Mitigation only Fix from $1,9502018-02-05 HIGH 7.5 CVE-2018-6188 django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensiti… Django Patch available Fix from $1,9502018-02-05 CRITICAL 9.1 CVE-2018-6596 webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which al… Debian Linux 1.2.1+ Fix from $2,3002018-02-03 HIGH 7.5 CVE-2016-0312 IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated… Tririga Application Platform after 3.3.1 Fix from $1,9502018-02-02 MEDIUM 5.3 CVE-2018-6526 view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parame… Mantisbt after 2.10.0 Fix from $1,6002018-02-02 HIGH 8.8 CVE-2018-1192 In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x version… Cloud Foundry Uaa 1.7 / 4.5.5+ Fix from $1,9502018-02-01 MEDIUM 6.5 CVE-2015-2203 Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by l… Evergreen Patch available Fix from $1,6002018-02-01 HIGH 7.5 CVE-2015-2204 Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensit… Evergreen 2.5.9 / 2.6.7+ Fix from $1,9502018-02-01 MEDIUM 6.5 CVE-2013-7435 The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive setting… Evergreen 2.5.9 / 2.6.7+ Fix from $1,6002018-02-01 MEDIUM 5.3 CVE-2018-6470 Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak. Nibbleblog Mitigation only Fix from $1,6002018-02-01 HIGH 7.5 CVE-2018-6460EPSS 11% Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including … Hotspot Shield No fix yet Fix from $1,9502018-01-31 HIGH 7.5 CVE-2018-6412 In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary… Linux Kernel after 4.15 Fix from $1,9502018-01-31 MEDIUM 5.5 CVE-2017-1784 IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-… Cognos Analytics Patch available Fix from $1,6002018-01-29 HIGH 7.5 CVE-2018-6008EPSS 37% Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter. Jtag Members Directory No fix yet Fix from $1,9502018-01-29 HIGH 7.5 CVE-2018-6015 An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=e… Email Subscribers \& Newsletters 3.4.8+ Fix from $1,9502018-01-26 MEDIUM 5.5 CVE-2018-5750 The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information… Linux Kernel after 4.14.15 Fix from $1,6002018-01-26 MEDIUM 6.5 CVE-2017-1000505 In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coerc… Script Security after 1.36 Fix from $1,6002018-01-25 MEDIUM 5.3 CVE-2018-4835 A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/t… Telecontrol Server Basic 3.1+ Fix from $1,6002018-01-25 HIGH 7.5 CVE-2018-5319EPSS 12% RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request. Filehub Firmware No fix yet Fix from $1,9502018-01-24