Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2013-3982EPSS 13% The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified installation information… Sametime Mitigation only Fix from $1,6002014-05-26 MEDIUM 5.0 CVE-2014-2199 meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and ea… Webex Business Suite after 1.5 Fix from $1,6002014-05-20 MEDIUM 5.0 CVE-2014-3787 SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors. Netweaver after 7.20 Fix from $1,6002014-05-19 MEDIUM 5.0 CVE-2011-2513 The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef… Icedtea Web after 1.8.8 Fix from $1,6002014-05-14 MEDIUM 5.0 CVE-2014-3242 SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an ent… Soappy No fix yet Fix from $1,6002014-05-12 MEDIUM 5.0 CVE-2013-6472 MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) l… Mediawiki after 1.19.9 Fix from $1,6002014-05-12 MEDIUM 5.0 CVE-2014-2301 OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/. Bscw after 5.0.7 Fix from $1,6002014-05-12 MEDIUM 5.0 CVE-2013-0174 The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request. Foreman after 1.0 Fix from $1,6002014-05-08 MEDIUM 5.0 CVE-2013-7060 Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file obj… Plone Mitigation only Fix from $1,6002014-05-02 MEDIUM 5.0 CVE-2014-0786 Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverag… Integraxor after 4.1.4390 Fix from $1,6002014-05-01 MEDIUM 5.0 CVE-2014-3129 The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted … Netweaver Software Lifecycle Manager Mitigation only Fix from $1,6002014-04-30 MEDIUM 5.0 CVE-2014-2545 TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before… Slingshot after 7.2.1 Fix from $1,6002014-04-30 HIGH 7.5 CVE-2013-7373 Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection … Android after 4.3.1 Fix from $1,9502014-04-29 MEDIUM 5.0 CVE-2013-7111 The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on … Basespace Ruby Sdk No fix yet Fix from $1,6002014-04-29 MEDIUM 6.8 CVE-2014-2383EPSS 39% dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitr… Dompdf after 0.6.0 Fix from $1,6002014-04-28 MEDIUM 5.0 CVE-2014-0892 IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier f… Lotus Domino Mitigation only Fix from $1,6002014-04-23 MEDIUM 5.0 CVE-2014-2983 Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous user… Drupal 6.31 / 7.27+ Fix from $1,6002014-04-23 MEDIUM 6.3 CVE-2014-2719 Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remo… Rt Ac66u Firmware Mitigation only Fix from $1,6002014-04-22 MEDIUM 5.0 CVE-2014-0778 TCPUploader module listens on Port 10651/TCP for incoming connections. Exploitation of this vulnerability could allow a remote unauthenticated user… Movicon Mitigation only Fix from $1,6002014-04-19 MEDIUM 5.0 CVE-2013-4279 imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to t… Imapsync after 1.564 Fix from $1,6002014-04-18 HIGH 7.8 CVE-2014-0644EPSS 53% EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external … Cloud Tiering Appliance Software Mitigation only Fix from $1,9502014-04-17 MEDIUM 5.0 CVE-2014-2869 PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as d… Commonspot Content Server after 7.0.1 Fix from $1,6002014-04-15 MEDIUM 5.0 CVE-2014-2871 PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attacke… Commonspot Content Server after 7.0.1 Fix from $1,6002014-04-15 MEDIUM 5.0 CVE-2014-2872 PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing v… Commonspot Content Server after 7.0.1 Fix from $1,6002014-04-15 MEDIUM 5.0 CVE-2014-2873 PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obta… Commonspot Content Server after 7.0.1 Fix from $1,6002014-04-15 MEDIUM 5.0 CVE-2014-0771 The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to t… Advantech Webaccess after 7.1 Fix from $1,6002014-04-12 MEDIUM 5.0 CVE-2014-0772 The BWOCXRUN.BwocxrunCtrl.1 control contains a method named OpenUrlToBufferTimeout. This method takes a URL as a parameter and returns its contents… Advantech Webaccess after 7.1 Fix from $1,6002014-04-12 MEDIUM 5.0 CVE-2014-2749 The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive inf… Hana Mitigation only Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2014-0708 WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sens… Webex Meeting Center Mitigation only Fix from $1,6002014-03-21 HIGH 7.5 CVE-2014-1505 The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows… Firefox 24.4 / 28.0+ Fix from $1,9502014-03-19