Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2015-4450 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac… Acrobat 10.1.15 / 11.0.12+ Fix from $1,6002015-07-15 MEDIUM 5.0 CVE-2015-4449 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac… Acrobat 15.006.30060 / 15.008.20082+ Fix from $1,6002015-07-15 MEDIUM 5.0 CVE-2014-8450 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac… Acrobat 10.1.15 / 11.0.12+ Fix from $1,6002015-07-15 MEDIUM 5.0 CVE-2015-1887 IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Co… Websphere Portal Patch available Fix from $1,6002015-07-14 MEDIUM 5.0 CVE-2015-1011 Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecifie… Lifecare Pcainfusion Firmware after 5.0 Fix from $1,6002015-07-06 MEDIUM 5.0 CVE-2015-1914 IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permissio… Java 5.0.16.10 / 6.0.16.4+ Fix from $1,6002015-07-02 MEDIUM 5.0 CVE-2015-2141 The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Willia… Crypto\+\+ Library Patch available Fix from $1,6002015-07-01 HIGH 7.8 CVE-2015-1941EPSS 6% The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an un… Tivoli Storage Manager Fastback Mitigation only Fix from $1,9502015-06-30 MEDIUM 5.0 CVE-2015-4229 The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsm… Unified Communications Domain Manager Mitigation only Fix from $1,6002015-06-30 MEDIUM 5.0 CVE-2015-4216 The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual A… Content Security Management Virtual Appliance Mitigation only Fix from $1,6002015-06-26 MEDIUM 6.8 CVE-2015-1851 OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users t… Ubuntu Linux after 2014.1.4 Fix from $1,6002015-06-25 MEDIUM 5.0 CVE-2015-4218 The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information… Jabber Mitigation only Fix from $1,6002015-06-24 MEDIUM 5.0 CVE-2015-4212 Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credential… Webex Meeting Center No fix yet Fix from $1,6002015-06-24 HIGH 7.5 CVE-2015-4208 Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive informat… Webex Meeting Center Mitigation only Fix from $1,9502015-06-24 MEDIUM 5.0 CVE-2014-4875 CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to dis… Chec after 6.6 Fix from $1,6002015-06-24 MEDIUM 6.4 CVE-2015-4209 Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive i… Webex Meeting Center Mitigation only Fix from $1,6002015-06-23 MEDIUM 5.0 CVE-2015-4207 Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intend… Webex Meeting Center Mitigation only Fix from $1,6002015-06-23 MEDIUM 5.0 CVE-2015-3236EPSS 7% cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset… Curl Patch available Fix from $1,6002015-06-22 MEDIUM 5.0 CVE-2015-4202 Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service,… iOS Mitigation only Fix from $1,6002015-06-20 MEDIUM 5.0 CVE-2015-4194 The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether… Webex Meeting Center Mitigation only Fix from $1,6002015-06-19 MEDIUM 5.0 CVE-2015-4345 The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for auth… Restful Web Services Patch available Fix from $1,6002015-06-15 MEDIUM 5.0 CVE-2015-3951 RLE Nova-Wind Turbine HMI devices store cleartext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors. Nova Wind Turbine Hmi Firmware No fix yet Fix from $1,6002015-06-13 MEDIUM 5.0 CVE-2015-3923 Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php. Coppermine Photo Gallery after 1.5.4 Fix from $1,6002015-06-10 MEDIUM 5.0 CVE-2014-8604EPSS 7% The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which … Xcloner No fix yet Fix from $1,6002015-06-10 MEDIUM 5.0 CVE-2015-3108 Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1… Flash Player after 17.0.0.172 Fix from $1,6002015-06-10 MEDIUM 5.0 CVE-2015-3102 Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1… Air after 17.0.0.172 Fix from $1,6002015-06-10 MEDIUM 5.0 CVE-2015-3099 Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1… Air after 17.0.0.172 Fix from $1,6002015-06-10 MEDIUM 5.0 CVE-2015-3098 Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1… Air after 17.0.0.172 Fix from $1,6002015-06-10 MEDIUM 5.0 CVE-2015-3097EPSS 12% Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe… Air after 17.0.0.172 Fix from $1,6002015-06-10 MEDIUM 5.0 CVE-2015-2998EPSS 26% SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstr… Sysaid after 15.1 Fix from $1,6002015-06-08