Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2017-5529 JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any acces… Jasperreports Library Community Edition after 6.4.0 Fix from $1,6002017-06-29 MEDIUM 5.5 CVE-2017-8575 The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a speci… Windows 10 Patch available Fix from $1,6002017-06-29 HIGH 7.5 CVE-2017-7686 Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality… Ignite Mitigation only Fix from $1,9502017-06-28 HIGH 7.5 CVE-2017-9993EPSS 16% FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filenam… Debian Linux 2.8.12 / 3.1.9+ Fix from $1,9502017-06-28 HIGH 7.5 CVE-2015-5378 Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash serve… Logstash No fix yet Fix from $1,9502017-06-27 MEDIUM 5.3 CVE-2016-6083 IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696. Tivoli Monitoring Patch available Fix from $1,6002017-06-27 HIGH 7.4 CVE-2017-7520 OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-mid… Openvpn after 2.3.16 Fix from $1,9502017-06-27 MEDIUM 5.5 CVE-2015-1870 The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which all… Automatic Bug Reporting Tool after 2.1.11 Fix from $1,6002017-06-26 MEDIUM 5.5 CVE-2017-9868 In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic infor… Debian Linux after 1.4.12 Fix from $1,6002017-06-25 MEDIUM 5.5 CVE-2016-5893 IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force I… Sterling B2b Integrator Patch available Fix from $1,6002017-06-23 MEDIUM 6.5 CVE-2017-1131 IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially cr… Sterling B2b Integrator Patch available Fix from $1,6002017-06-23 MEDIUM 6.5 CVE-2017-1193 IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667. Sterling B2b Integrator Patch available Fix from $1,6002017-06-23 MEDIUM 5.5 CVE-2017-1302 IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID:… Sterling B2b Integrator Patch available Fix from $1,6002017-06-23 MEDIUM 5.5 CVE-2017-1349 IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM … Sterling B2b Integrator Patch available Fix from $1,6002017-06-23 MEDIUM 6.5 CVE-2016-9982 IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to impro… Sterling B2b Integrator Patch available Fix from $1,6002017-06-22 MEDIUM 5.3 CVE-2016-9983 IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have ac… Sterling B2b Integrator Patch available Fix from $1,6002017-06-22 HIGH 7.5 CVE-2017-6045 An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application… Vtscada after 11.2.23 Fix from $1,9502017-06-21 HIGH 7.5 CVE-2017-3087 Adobe Captivate versions 9 and earlier have an information disclosure vulnerability resulting from abuse of the quiz reporting feature in Captivate. Captivate after 9.0 Fix from $1,9502017-06-20 HIGH 7.5 CVE-2017-3743 If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utili… Advanced Settings Utility after 10.2 Fix from $1,9502017-06-20 MEDIUM 5.5 CVE-2017-1000380 sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being ab… Linux Kernel after 4.11.4 Fix from $1,6002017-06-17 HIGH 7.5 CVE-2016-1000221 Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information. Logstash after 2.3.3 Fix from $1,9502017-06-16 MEDIUM 6.5 CVE-2016-10362 Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials. Output Plugin after 5.0.0 Fix from $1,6002017-06-16 MEDIUM 5.9 CVE-2017-8449 X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and excl… X Pack after 5.2.2 Fix from $1,6002017-06-16 HIGH 7.5 CVE-2017-8450 X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document an… X Pack Mitigation only Fix from $1,9502017-06-16 HIGH 7.5 CVE-2017-9731 In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive informat… Yp Core Pyro Patch available Fix from $1,9502017-06-16 HIGH 7.5 CVE-2015-7732 The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext. Avira Mobile Security Mitigation only Fix from $1,9502017-06-15 HIGH 7.5 CVE-2017-1379 IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Porta… Api Connect Patch available Fix from $1,9502017-06-15 MEDIUM 6.5 CVE-2017-8531EPSS 7% Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… Office Patch available Fix from $1,6002017-06-15 MEDIUM 6.5 CVE-2017-8532EPSS 7% Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… Office Patch available Fix from $1,6002017-06-15 MEDIUM 6.5 CVE-2017-8533EPSS 8% Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… Office Patch available Fix from $1,6002017-06-15