Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2014-7259 SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain… Kaku San Sei Million Aruthur after 1.0.1 Fix from $1,6002014-12-05 MEDIUM 5.0 CVE-2014-7243 LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers… L 04d Mitigation only Fix from $1,6002014-12-05 MEDIUM 5.0 CVE-2014-9018 Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to sh… Icecast after 2.4.0 Fix from $1,6002014-12-03 MEDIUM 5.0 CVE-2014-8775 MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote … Modx Revolution No fix yet Fix from $1,6002014-12-03 MEDIUM 5.0 CVE-2014-9177 The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html… Html5 Mp3 Player With Playlist Free after 2.6 Fix from $1,6002014-12-02 MEDIUM 5.0 CVE-2014-8874 The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remot… Ke Questionnaire after 2.5.2 Fix from $1,6002014-12-02 HIGH 7.8 CVE-2014-8425 The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files. Vap2500 Firmware after 08.41 Fix from $1,9502014-11-28 MEDIUM 5.0 CVE-2014-6075 IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2… Qradar Risk Manager Patch available Fix from $1,6002014-11-28 MEDIUM 5.0 CVE-2014-8552 The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through S… Simatic Pcs 7 Mitigation only Fix from $1,6002014-11-26 HIGH 7.8 CVE-2014-8678 The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related … Oputils after 7.0 Fix from $1,9502014-11-25 MEDIUM 5.0 CVE-2014-7848 lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct re… Moodle after 2.4.11 Fix from $1,6002014-11-24 MEDIUM 5.0 CVE-2014-5325 The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x throu… Direct Web Remoting after 2.0.10 Fix from $1,6002014-11-24 MEDIUM 6.8 CVE-2014-6477 Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote au… Database Server Patch available Fix from $1,6002014-11-23 MEDIUM 5.0 CVE-2014-9025 The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email add… Commerce Mitigation only Fix from $1,6002014-11-20 MEDIUM 6.8 CVE-2014-6624 The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unsp… Clearpass after 6.3.4 Fix from $1,6002014-11-19 MEDIUM 5.0 CVE-2014-6622 Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors. Clearpass after 6.3.4 Fix from $1,6002014-11-19 MEDIUM 5.0 CVE-2014-6621 Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which a… Clearpass after 6.3.4 Fix from $1,6002014-11-19 MEDIUM 5.0 CVE-2014-4458 The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might all… Mac Os X after 10.10.0 Fix from $1,6002014-11-18 MEDIUM 5.0 CVE-2014-4453 Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight o… Iphone Os after 10.10.0 Fix from $1,6002014-11-18 MEDIUM 5.0 CVE-2014-7992EPSS 27% The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information fro… iOS Mitigation only Fix from $1,6002014-11-18 HIGH 7.2 CVE-2013-0347 The Gentoo init script for webfs uses world-readable permissions for /var/log/webfsd.log, which allows local users to have unspecified impact by read… Webfs No fix yet Fix from $1,9502014-11-16 MEDIUM 5.0 CVE-2013-3737 The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (… Request Tracker Patch available Fix from $1,6002014-11-16 MEDIUM 6.4 CVE-2014-8566 The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via… Linux after 0.8.0 Fix from $1,6002014-11-15 MEDIUM 5.0 CVE-2014-8736 The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been… Open Atrium after 7.x-2.21 Fix from $1,6002014-11-12 MEDIUM 5.0 CVE-2014-8437 Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.… Flash Player 11.2.202.418 / 13.0.0.252+ Fix from $1,6002014-11-11 MEDIUM 5.0 CVE-2014-8709 The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allow… Linux Kernel after 3.13.4 Fix from $1,6002014-11-10 MEDIUM 5.0 CVE-2014-8665 The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files. Business Intelligence Development Workbench Mitigation only Fix from $1,6002014-11-06 MEDIUM 5.0 CVE-2014-8666 The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain … Business Intelligence Development Workbench Mitigation only Fix from $1,6002014-11-06 HIGH 7.5 CVE-2014-2374 The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors… Axm Net Patch available Fix from $1,9502014-11-05 MEDIUM 5.0 CVE-2014-6130 The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for … Notes Traveler after 9.0.1.2 Fix from $1,6002014-11-04