Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.9 CVE-2017-0271EPSS 13% Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP… Windows 10 Patch available Fix from $1,6002017-05-12 MEDIUM 5.5 CVE-2017-8360 Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mic… Mictray64 after 1.0.0.46 Fix from $1,6002017-05-12 HIGH 8.1 CVE-2017-8899 Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments… Invision Power Board after 4.1.19.2 Fix from $1,9502017-05-11 HIGH 7.5 CVE-2017-5892 ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map. Rt Ac1750 Firmware Patch available Fix from $1,9502017-05-10 MEDIUM 6.5 CVE-2017-8877 ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID. Rt Ac1750 Firmware Mitigation only Fix from $1,6002017-05-10 MEDIUM 6.5 CVE-2017-8878 ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml. Rt Ac1750 Firmware Mitigation only Fix from $1,6002017-05-10 HIGH 7.5 CVE-2017-3067 Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service… Experience Manager Forms Mitigation only Fix from $1,9502017-05-09 HIGH 8.8 CVE-2017-7923 A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Ser… Ds 2cd2032 I Firmware Patch available Fix from $1,9502017-05-06 MEDIUM 5.5 CVE-2016-8916 IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password com… Tivoli Storage Manager after 6.3 Fix from $1,6002017-05-05 MEDIUM 5.3 CVE-2017-6626 A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unaut… Unified Contact Center Enterprise Mitigation only Fix from $1,6002017-05-03 HIGH 8.8 CVE-2017-5481 Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an … Officescan Patch available Fix from $1,9502017-05-03 MEDIUM 6.5 CVE-2017-7216 The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecif… Pan Os after 7.1.8 Fix from $1,6002017-05-02 MEDIUM 5.3 CVE-2016-4442 The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leve… Rack Mini Profiler after 0.9.9.2 Fix from $1,6002017-05-02 CRITICAL 9.8 CVE-2016-5006 The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user cred… Cloud Foundry after 238.0 Fix from $2,3002017-05-02 MEDIUM 5.5 CVE-2016-10351 Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information vi… Telegram Desktop Patch available Fix from $1,6002017-05-01 MEDIUM 6.5 CVE-2017-7644 The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users … Pan Os after 6.1.15 Fix from $1,6002017-04-29 MEDIUM 5.9 CVE-2017-2103 The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoo… Lala Call after 2.4.7 Fix from $1,6002017-04-28 MEDIUM 5.9 CVE-2017-2104 The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attacker… Business Lala Call after 1.4.7 Fix from $1,6002017-04-28 MEDIUM 5.9 CVE-2017-2105 The TVer App for Android 3.2.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof ser… Tver after 3.2.7 Fix from $1,6002017-04-28 HIGH 7.5 CVE-2017-7415 Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource. Confluence Server No fix yet Fix from $1,9502017-04-27 MEDIUM 5.3 CVE-2017-7983 In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers. Joomla\! Patch available Fix from $1,6002017-04-25 MEDIUM 5.3 CVE-2017-8057 In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting. Joomla\! Patch available Fix from $1,6002017-04-25 HIGH 7.8 CVE-2017-8109 The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, whi… Salt Patch available Fix from $1,9502017-04-25 MEDIUM 5.3 CVE-2017-3556 Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: File Management). Supported versions that … Application Object Library Mitigation only Fix from $1,6002017-04-24 MEDIUM 5.3 CVE-2017-3527 Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core). Supported versions that ar… Peoplesoft Enterprise Peopletools Mitigation only Fix from $1,6002017-04-24 CRITICAL 9.8 CVE-2015-7247EPSS 10% D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super an… Dvg N5402sp Firmware No fix yet Fix from $2,3002017-04-24 HIGH 8.6 CVE-2017-2317 A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthentic… Northstar Controller after 2.1.0 Fix from $1,9502017-04-24 MEDIUM 6.5 CVE-2017-2318 A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user … Northstar Controller after 2.1.0 Fix from $1,6002017-04-24 CRITICAL 10.0 CVE-2017-2320 A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged… Northstar Controller after 2.1.0 Fix from $2,3002017-04-24 MEDIUM 6.5 CVE-2017-2326 An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unpri… Northstar Controller after 2.1.0 Fix from $1,6002017-04-24