Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2017-16741 An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32.… Fl Switch 3005 Firmware after 1.32 Fix from $1,6002018-01-12 CRITICAL 9.8 CVE-2014-6437EPSS 16% Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors i… Adsl Dsl5018en \(1t1r\) Firmware No fix yet Fix from $2,3002018-01-12 HIGH 7.5 CVE-2015-2298 node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper su… Etherpad Patch available Fix from $1,9502018-01-12 MEDIUM 6.5 CVE-2018-0013 A local file inclusion vulnerability in Juniper Networks Junos Space Network Management Platform may allow an authenticated user to retrieve files fr… Junos Space Patch available Fix from $1,6002018-01-10 MEDIUM 6.5 CVE-2018-0014 Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from p… Screenos Mitigation only Fix from $1,6002018-01-10 HIGH 7.5 CVE-2017-11066 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing ubi image an uninitial… Android Patch available Fix from $1,9502018-01-10 CRITICAL 9.8 CVE-2017-11079 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing sparse image, uninit… Android Patch available Fix from $2,3002018-01-10 HIGH 7.5 CVE-2017-14869 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FOTA parti… Android Patch available Fix from $1,9502018-01-10 HIGH 7.5 CVE-2017-14870 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while updating the recovery message f… Android Patch available Fix from $1,9502018-01-10 HIGH 7.5 CVE-2017-15850 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, userspace can read values from audio … Android Patch available Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-4991 (1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mys… Codders Dataset No fix yet Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-4992 lib/cap-strap/helpers.rb in the cap-strap gem 0.1.5 for Ruby places credentials on the useradd command line, which allows local users to obtain sensi… Cap Strap No fix yet Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-4993 (1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place cr… Backup Agoddard No fix yet Fix from $1,9502018-01-10 HIGH 7.0 CVE-2014-4995 Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the… Vladtheenterprising Mitigation only Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-4997 lib/commands/setup.rb in the point-cli gem 0.0.1 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive i… Point Cli No fix yet Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-4998 test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to o… Lean Ruport No fix yet Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-4999 vendor/plugins/dataset/lib/dataset/database/mysql.rb in the kajam gem 1.0.3.rc2 for Ruby places the mysql user password on the (1) mysqldump command … Kajam No fix yet Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-5000 The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtai… Lawn Login No fix yet Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-5001 lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (3) mysql, and (4) psql comman… Kcapifony No fix yet Fix from $1,9502018-01-10 HIGH 7.8 CVE-2014-5004 lib/brbackup.rb in the brbackup gem 0.1.1 for Ruby places the database password on the mysql command line, which allows local users to obtain sensiti… Brbackup Mitigation only Fix from $1,9502018-01-10 HIGH 7.5 CVE-2017-12169 It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authent… Freeipa Mitigation only Fix from $1,9502018-01-10 HIGH 7.1 CVE-2017-12622 When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with… Geode 1.3.0+ Fix from $1,9502018-01-10 HIGH 7.5 CVE-2017-9795 When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut… Geode 1.3.0+ Fix from $1,9502018-01-10 MEDIUM 5.3 CVE-2017-9796 When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut… Geode 1.3.0+ Fix from $1,6002018-01-10 MEDIUM 5.9 CVE-2017-12697 A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnera… Shanghai Onstar Mitigation only Fix from $1,6002018-01-09 HIGH 7.5 CVE-2012-3353 The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con… Sling Jcr Contentloader Mitigation only Fix from $1,9502018-01-09 MEDIUM 5.9 CVE-2014-5394 Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal. S9300 Firmware Mitigation only Fix from $1,6002018-01-08 HIGH 7.5 CVE-2018-5266 Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the login… Sea Tel 121 Firmware No fix yet Fix from $1,9502018-01-08 HIGH 7.1 CVE-2017-4948 VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll… Workstation 4.7+ Fix from $1,9502018-01-05 MEDIUM 5.3 CVE-2018-0800EPSS 7% Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scriptin… Chakracore after 1.7.6 Fix from $1,6002018-01-04