Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2016-6068 IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties. Urbancode Deploy Patch available Fix from $1,9502017-02-01 MEDIUM 5.5 CVE-2016-8963 IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user. License Metric Tool after 9.2 Fix from $1,6002017-02-01 MEDIUM 5.3 CVE-2016-6117 IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information. Security Key Lifecycle Manager Patch available Fix from $1,6002017-02-01 MEDIUM 5.9 CVE-2016-8966 IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport… License Metric Tool Mitigation only Fix from $1,6002017-02-01 MEDIUM 5.5 CVE-2016-8981 IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system. License Metric Tool Mitigation only Fix from $1,6002017-02-01 MEDIUM 5.3 CVE-2016-6080 The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker. Websphere Message Broker Patch available Fix from $1,6002017-02-01 HIGH 7.5 CVE-2016-5958 IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag … Security Privileged Identity Manager Patch available Fix from $1,9502017-02-01 MEDIUM 5.9 CVE-2016-5966 IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to pr… Security Privileged Identity Manager Patch available Fix from $1,6002017-02-01 MEDIUM 6.5 CVE-2016-5988 IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available t… Security Privileged Identity Manager Patch available Fix from $1,6002017-02-01 MEDIUM 6.5 CVE-2016-5994 IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine … Infosphere Information Server Patch available Fix from $1,6002017-02-01 MEDIUM 6.8 CVE-2016-6034 IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges. Tivoli Storage Manager For Virtual Environments Data Protection For Vmware Patch available Fix from $1,6002017-02-01 MEDIUM 5.3 CVE-2016-3023 IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names. Security Access Manager 9.0 Firmware Patch available Fix from $1,6002017-02-01 MEDIUM 5.3 CVE-2016-3035 IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server. Security Appscan Source Patch available Fix from $1,6002017-02-01 MEDIUM 5.9 CVE-2016-3043 IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stri… Security Access Manager For Web 7.0 Firmware Patch available Fix from $1,6002017-02-01 MEDIUM 5.3 CVE-2016-5896 IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser. Maximo Asset Management Patch available Fix from $1,6002017-02-01 HIGH 7.5 CVE-2016-9410 MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to obtain sensitive database information via … Merge System after 1.8.6 Fix from $1,9502017-01-31 MEDIUM 5.3 CVE-2016-9411 The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installat… Merge System after 1.8.6 Fix from $1,6002017-01-31 HIGH 7.5 CVE-2016-9414 MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missi… Merge System after 1.8.6 Fix from $1,9502017-01-31 HIGH 7.5 CVE-2016-9418 MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive inf… Merge System after 1.8.7 Fix from $1,9502017-01-31 MEDIUM 5.9 CVE-2016-6329EPSS 6% OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duratio… Openvpn after 2.3.14 Fix from $1,6002017-01-31 CRITICAL 9.8 CVE-2016-10175EPSS 65% The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user… Wnr2000v5 Firmware after 1.0.0.34 Fix from $2,3002017-01-30 HIGH 7.5 CVE-2016-10181 An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 MEDIUM 5.3 CVE-2017-5610EPSS 5% wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user… WordPress after 4.7.1 Fix from $1,6002017-01-30 MEDIUM 5.7 CVE-2017-3292 Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions… Peoplesoft Enterprise Peopletools Patch available Fix from $1,6002017-01-27 HIGH 7.3 CVE-2017-3250 Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are… Glassfish Server Patch available Fix from $1,9502017-01-27 MEDIUM 5.8 CVE-2017-3255 Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: ADF Faces). Supported versions that are affected are 11.1… Jdeveloper Patch available Fix from $1,6002017-01-27 MEDIUM 5.5 CVE-2016-3996 ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a craft… Knox No fix yet Fix from $1,6002017-01-27 HIGH 7.5 CVE-2016-10002EPSS 7% Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, an… Debian Linux Patch available Fix from $1,9502017-01-27 MEDIUM 5.3 CVE-2017-3797 A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualified domain name of the Cisco W… Webex Meetings Server Mitigation only Fix from $1,6002017-01-26 MEDIUM 5.3 CVE-2017-3805 A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated, remote attacker to view con… Iox Mitigation only Fix from $1,6002017-01-26