Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2017-6318 saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet. Leap Mitigation only Fix from $1,9502017-03-20 MEDIUM 6.8 CVE-2016-2981 An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999… Rational Collaborative Lifecycle Management Patch available Fix from $1,6002017-03-20 HIGH 7.5 CVE-2016-9165 The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Sn… Unified Infrastructure Management after 8.47 Fix from $1,9502017-03-20 HIGH 7.5 CVE-2014-8701 Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password. Wondercms No fix yet Fix from $1,9502017-03-17 MEDIUM 5.3 CVE-2014-8702 Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals… Wondercms No fix yet Fix from $1,6002017-03-17 MEDIUM 5.3 CVE-2014-8706 Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to… Pluck No fix yet Fix from $1,6002017-03-17 HIGH 7.5 CVE-2014-8722EPSS 14% GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/… Getsimple Cms No fix yet Fix from $1,9502017-03-17 MEDIUM 5.3 CVE-2014-8723 GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/Inn… Getsimple Cms No fix yet Fix from $1,6002017-03-17 HIGH 7.5 CVE-2015-3881 Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.ym… Qdpm No fix yet Fix from $1,9502017-03-17 MEDIUM 5.3 CVE-2015-3882 qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation… Qdpm No fix yet Fix from $1,6002017-03-17 MEDIUM 5.5 CVE-2017-0105EPSS 30% Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Ser… Office Patch available Fix from $1,6002017-03-17 MEDIUM 5.3 CVE-2017-0043 Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows S… Windows 10 Patch available Fix from $1,6002017-03-17 MEDIUM 5.5 CVE-2017-0060EPSS 16% The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 20… Live Meeting Patch available Fix from $1,6002017-03-17 MEDIUM 6.5 CVE-2017-0063EPSS 35% The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Window… Windows 10 Patch available Fix from $1,6002017-03-17 CRITICAL 9.8 CVE-2017-5496EPSS 6% Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash. Sawmill No fix yet Fix from $2,3002017-03-15 MEDIUM 5.3 CVE-2017-5537 The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an accou… Weblate after 2.10 Fix from $1,6002017-03-15 MEDIUM 6.5 CVE-2017-5583 The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated user… Pan Os after 6.1.15 Fix from $1,6002017-03-15 HIGH 7.5 CVE-2014-8688 An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory an… Messenger Mitigation only Fix from $1,9502017-03-14 HIGH 7.5 CVE-2016-8747EPSS 7% An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11Inpu… Tomcat 8.5.10+ Fix from $1,9502017-03-14 MEDIUM 5.9 CVE-2015-6671 Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent att… Edx Platform after 2015-08-20 Fix from $1,6002017-03-13 CRITICAL 9.8 CVE-2017-5674EPSS 22% A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft … Goahead No fix yet Fix from $2,3002017-03-13 MEDIUM 5.1 CVE-2016-5894 IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local us… Websphere Commerce Patch available Fix from $1,6002017-03-08 MEDIUM 5.5 CVE-2017-0529 An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission le… Android after 7.1.1 Fix from $1,6002017-03-08 MEDIUM 5.5 CVE-2017-0494 An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its p… Android Mitigation only Fix from $1,6002017-03-08 MEDIUM 5.5 CVE-2017-0495 An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. Th… Android Mitigation only Fix from $1,6002017-03-08 MEDIUM 5.5 CVE-2016-8483 An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permiss… Linux Kernel Patch available Fix from $1,6002017-03-08 MEDIUM 5.5 CVE-2017-0334 An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission … Linux Kernel Patch available Fix from $1,6002017-03-08 MEDIUM 5.5 CVE-2017-0336 An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission … Linux Kernel Patch available Fix from $1,6002017-03-08 HIGH 7.8 CVE-2017-0455 An information disclosure vulnerability in the Qualcomm bootloader could help to enable a local malicious application to to execute arbitrary code wi… Linux Kernel Patch available Fix from $1,9502017-03-08 HIGH 8.8 CVE-2016-8940 IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, … Tivoli Storage Manager Patch available Fix from $1,9502017-03-07