Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2017-11706 The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the l… Boozt after 2.3.3 Fix from $1,9502017-07-28 MEDIUM 5.5 CVE-2015-3171 sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive informati… Sos Patch available Fix from $1,6002017-07-25 MEDIUM 6.5 CVE-2015-5187 Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic. Candlepin Mitigation only Fix from $1,6002017-07-25 HIGH 7.5 CVE-2017-8035 An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-releas… Capi Release 1.35.0 / 268+ Fix from $1,9502017-07-25 MEDIUM 5.3 CVE-2017-9554EPSS 77% An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumer… Diskstation Manager after 6.1.1-15101-4 Fix from $1,6002017-07-24 HIGH 7.5 CVE-2017-11325 An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php. Tilde Cms No fix yet Fix from $1,9502017-07-24 MEDIUM 6.5 CVE-2017-11327 An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP … Tilde Cms No fix yet Fix from $1,6002017-07-24 MEDIUM 6.5 CVE-2017-1374 Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to t… Tririga Application Platform Patch available Fix from $1,6002017-07-21 HIGH 7.5 CVE-2015-3198 The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via… Jboss Wildfly Application Server Mitigation only Fix from $1,9502017-07-21 CRITICAL 9.8 CVE-2017-11502EPSS 7% Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321. Dpc3928ad Docsis Wireless Router Firmware No fix yet Fix from $2,3002017-07-20 MEDIUM 5.5 CVE-2017-7028 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. w… Iphone Os 3.2.3 / 10.2.2+ Fix from $1,6002017-07-20 MEDIUM 5.5 CVE-2017-7029 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. w… Iphone Os 3.2.3 / 10.2.2+ Fix from $1,6002017-07-20 CRITICAL 9.8 CVE-2017-11435EPSS 10% The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management conso… Hg100r Firmware Mitigation only Fix from $2,3002017-07-19 MEDIUM 6.5 CVE-2017-11448 The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized … Imagemagick 6.9.9-0 / 7.0.6-1+ Fix from $1,6002017-07-19 HIGH 7.5 CVE-2017-9245 The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging … News And Weather 3.3.1+ Fix from $1,9502017-07-19 MEDIUM 6.5 CVE-2017-7947 NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging … Clustered Data Ontap Mitigation only Fix from $1,6002017-07-17 HIGH 7.5 CVE-2017-9812EPSS 11% The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before M… Anti Virus For Linux Server after 8.0.3.297 Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-9933 Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents. Joomla\! Mitigation only Fix from $1,9502017-07-17 MEDIUM 6.5 CVE-2017-2642 Moodle 3.x has user fullname disclosure on the user preferences page. Moodle Patch available Fix from $1,6002017-07-17 HIGH 7.5 CVE-2017-7683 Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure. Openmeetings Mitigation only Fix from $1,9502017-07-17 CRITICAL 9.8 CVE-2017-1000362 The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup direct… Jenkins after 1.498 Fix from $2,3002017-07-17 MEDIUM 5.9 CVE-2017-1000007 txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure. Txaws Mitigation only Fix from $1,6002017-07-17 HIGH 7.5 CVE-2017-1000025 GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password… Epiphany Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-1000029EPSS 8% Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include … Glassfish Server Mitigation only Fix from $1,9502017-07-17 MEDIUM 6.5 CVE-2017-0196EPSS 18% An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via… Edge Patch available Fix from $1,6002017-07-17 HIGH 8.1 CVE-2015-5152 Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote atta… Foreman Mitigation only Fix from $1,9502017-07-17 CRITICAL 9.1 CVE-2017-9788EPSS 57% In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or… HTTP Server after 2.4.26 Fix from $2,3002017-07-13 CRITICAL 9.8 CVE-2016-8964 IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-F… Bigfix Inventory 9.2.8+ Fix from $2,3002017-07-13 CRITICAL 9.8 CVE-2017-11165EPSS 64% dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /servic… Dt80 Dex Firmware No fix yet Fix from $2,3002017-07-12 MEDIUM 5.5 CVE-2017-8564 Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows … Windows 10 Patch available Fix from $1,6002017-07-11