Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2014-3852 Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potent… Pyplate No fix yet Fix from $1,6002014-08-07 MEDIUM 5.0 CVE-2014-3853 Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this cookie by… Pyplate No fix yet Fix from $1,6002014-08-07 MEDIUM 5.0 CVE-2014-2356 Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain s… Mguard Firmware after 7.5.0 Fix from $1,6002014-07-30 MEDIUM 5.0 CVE-2014-3056 The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive… Websphere Portal Mitigation only Fix from $1,6002014-07-29 MEDIUM 5.0 CVE-2014-3304 The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the … Webex Meetings Server Mitigation only Fix from $1,6002014-07-28 MEDIUM 5.0 CVE-2014-5107 concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.… Concrete5 No fix yet Fix from $1,6002014-07-28 MEDIUM 5.0 CVE-2014-3301 The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by… Webex Meetings Server after 1.5 Fix from $1,6002014-07-26 MEDIUM 5.0 CVE-2014-4682 The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive informat… Simatic Pcs7 after 8.0 Fix from $1,6002014-07-24 MEDIUM 5.0 CVE-2014-4980 The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information… Nessus after 2.3.4 Fix from $1,6002014-07-23 HIGH 7.5 CVE-2014-3530 The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502014-07-22 MEDIUM 5.8 CVE-2014-2519 The default configuration of EMC RecoverPoint Appliance (RPA) 4.1 before 4.1.0.1 does not enable a firewall, which allows remote attackers to obtain … Recoverpoint Appliance Mitigation only Fix from $1,6002014-07-19 MEDIUM 5.0 CVE-2014-2368 The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a craft… Advantech Webaccess after 7.1 Fix from $1,6002014-07-19 MEDIUM 6.3 CVE-2014-3064 The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Managemen… Infosphere Master Data Management Collaboration Server Mitigation only Fix from $1,6002014-07-19 MEDIUM 5.0 CVE-2014-4347 Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x be… Netscaler Access Gateway Firmware No fix yet Fix from $1,6002014-07-16 MEDIUM 5.0 CVE-2014-4942 The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/… Wp Easycart after 2.0.5 Fix from $1,6002014-07-11 MEDIUM 6.8 CVE-2014-2510 The JAXB XML parser in EMC Documentum Foundation Services (DFS) 6.6 before P39, 6.7 SP1 before P28, and 6.7 SP2 before P15, as used in My Documentum … Centerstage Mitigation only Fix from $1,6002014-07-08 MEDIUM 5.0 CVE-2014-3481 org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion… Jboss Enterprise Application Platform after 6.2.3 Fix from $1,6002014-07-07 MEDIUM 5.0 CVE-2013-5423 IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors. Flex System Manager Mitigation only Fix from $1,6002014-07-07 MEDIUM 5.0 CVE-2014-3066 IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declarat… Tivoli Endpoint Manager Mitigation only Fix from $1,6002014-07-02 MEDIUM 5.0 CVE-2014-1361 Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only … Mac Os X after 7.1.1 Fix from $1,6002014-07-01 MEDIUM 5.0 CVE-2014-0891 IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensit… Websphere Application Server Patch available Fix from $1,6002014-06-28 HIGH 7.8 CVE-2014-4153EPSS 7% The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request. Open Source Security Information Management after 4.7.0 Fix from $1,9502014-06-18 MEDIUM 5.0 CVE-2014-3249 Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes. Puppet Enterprise Mitigation only Fix from $1,6002014-06-17 MEDIUM 5.0 CVE-2013-5760 QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php. Photo Station Firmware after 4.0.3 Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2013-4724 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-C… Cm3 Acora Content Management System Mitigation only Fix from $1,6002014-06-06 MEDIUM 5.0 CVE-2013-4725 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecifi… Cm3 Acora Content Management System Mitigation only Fix from $1,6002014-06-06 MEDIUM 5.0 CVE-2013-4727 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive i… Cm3 Acora Content Management System Mitigation only Fix from $1,6002014-06-06 MEDIUM 5.0 CVE-2013-4728 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive i… Cm3 Acora Content Management System Mitigation only Fix from $1,6002014-06-06 MEDIUM 5.0 CVE-2013-1818 maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified vectors. Mediawiki after 1.20.2 Fix from $1,6002014-06-02 MEDIUM 5.0 CVE-2014-3867 The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspe… Sametime Mitigation only Fix from $1,6002014-05-26