Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2013-2086 The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an u… Owncloud Server Patch available Fix from $1,6002014-03-14 MEDIUM 6.6 CVE-2014-0323 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2… Windows 7 Patch available Fix from $1,6002014-03-12 HIGH 7.8 CVE-2014-2264 The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remot… Diskstation Manager Mitigation only Fix from $1,9502014-03-02 MEDIUM 5.0 CVE-2013-6656 The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, processe… Chrome after 33.0.1750.116 Fix from $1,6002014-02-24 MEDIUM 5.0 CVE-2014-1962 Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE)… Customer Relationship Management Mitigation only Fix from $1,6002014-02-14 MEDIUM 5.0 CVE-2013-6440 The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expand… Opensaml after 2.6.0 Fix from $1,6002014-02-14 HIGH 7.1 CVE-2014-0266EPSS 19% The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server… Windows 7 Patch available Fix from $1,9502014-02-12 HIGH 7.1 CVE-2013-7130 The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w… Compute Patch available Fix from $1,9502014-02-06 MEDIUM 5.0 CVE-2014-1484 Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitiv… Firefox after 26.0 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2013-2074 kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal… Kdelibs after 4.10.3 Fix from $1,6002014-02-05 MEDIUM 5.5 CVE-2011-4327 ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allow… Openssh after 5.8 Fix from $1,6002014-02-03 MEDIUM 5.0 CVE-2013-4043 The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attacke… Spss Collaboration And Deployment Services Mitigation only Fix from $1,6002014-02-01 MEDIUM 5.0 CVE-2013-7299 framework/common/messageheaderparser.cpp in Tntnet before 2.2.1 allows remote attackers to obtain sensitive information via a header that ends in \n … Tntnet after 2.2 Fix from $1,6002014-01-26 MEDIUM 5.0 CVE-2014-1664 The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain use… Gotomeeting No fix yet Fix from $1,6002014-01-26 MEDIUM 5.0 CVE-2013-6447 Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Re… Jboss Seam 2 Framework after 2.3.1 Fix from $1,6002014-01-23 MEDIUM 5.0 CVE-2014-1637EPSS 7% Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to dow… Command School Student Management System No fix yet Fix from $1,6002014-01-22 MEDIUM 5.0 CVE-2013-6419 Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a reques… Havana Patch available Fix from $1,6002014-01-07 MEDIUM 5.0 CVE-2013-6953 BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file. Blogengine.net after 2.8 Fix from $1,6002014-01-03 MEDIUM 5.0 CVE-2013-7224 Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, … Fat Free Crm after 0.12.0 Fix from $1,6002014-01-02 MEDIUM 5.0 CVE-2013-7249 Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, a… Fat Free Crm after 0.12.0 Fix from $1,6002014-01-02 MEDIUM 5.0 CVE-2013-4069 The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read … Spss Collaboration And Deployment Services Mitigation only Fix from $1,6002013-12-21 MEDIUM 5.0 CVE-2013-4070 The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to disco… Spss Collaboration And Deployment Services Mitigation only Fix from $1,6002013-12-21 HIGH 7.8 CVE-2013-4775EPSS 15% NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, G… Prosafe Firmware after 5.4.1.14 Fix from $1,9502013-12-19 MEDIUM 5.0 CVE-2013-6968 Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows … Webex Training Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.0 CVE-2013-6970 Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information by reading verbose error messages within server responses, aka Bug… Webex Meeting Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.0 CVE-2013-6972 Cisco WebEx Training Center allows remote attackers to discover session numbers, and bypass host approval for audio-conference attendance, by reading… Webex Training Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.0 CVE-2013-6709 The registration component in Cisco WebEx Training Center provides the training-session URL before payment is completed, which allows remote attacker… Webex Training Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.0 CVE-2013-6052 OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read. Openjpeg after 1.3 Fix from $1,6002013-12-12 HIGH 7.8 CVE-2012-0425 LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows contex… Opensuse Mitigation only Fix from $1,9502013-12-02 MEDIUM 5.0 CVE-2013-4617 Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attacker… Jahia Xcm after 6.6.1 Fix from $1,6002013-11-27