Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Adamvr Geoip Lite HIGH 8.1
CVE-2016-10680

adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP,…

Fix: after 1.2.0
Fix from $1,950 2018-05-29
Aerospike HIGH 8.1
CVE-2016-10558

aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the module vuln…

Fix: 2.4.2+
Fix from $1,950 2018-05-29
Selenium Download HIGH 8.1
CVE-2016-10559

selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads bina…

Fix: 2.0.7+
Fix from $1,950 2018-05-29
Install Nw HIGH 8.1
CVE-2016-10566

install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over HTTP, whi…

Fix: 1.1.5+
Fix from $1,950 2018-05-29
Product Monitor HIGH 8.1
CVE-2016-10567

product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information about the stat…

Fix: 2.2.5+
Fix from $1,950 2018-05-29
Geoip Lite Country HIGH 8.1
CVE-2016-10568

geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources…

Fix: 1.1.4+
Fix from $1,950 2018-05-29
Secure Firewall Management Center MEDIUM 5.8
CVE-2018-0281

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of …

Mitigation only
Fix from $1,600 2018-05-02
Secure Firewall Management Center MEDIUM 5.8
CVE-2018-0283

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of …

Mitigation only
Fix from $1,600 2018-05-02
Sterling Connect HIGH 7.3
CVE-2013-4035

IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging fa…

No fix yet
Fix from $1,950 2018-05-01
Worklight MEDIUM 5.3
CVE-2013-5391

IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and En…

Mitigation only
Fix from $1,600 2018-04-27
Notary HIGH 7.5
CVE-2015-9258

In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the fiel…

Fix: 0.1+
Fix from $1,950 2018-03-31
Rational Clearcase HIGH 7.4
CVE-2015-5039

The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not pro…

Fix: after 8.0.1.10
Fix from $1,950 2018-03-26
Intellispace Portal HIGH 7.5
CVE-2018-5458

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain un…

Mitigation only
Fix from $1,950 2018-03-26
Intellispace Portal HIGH 7.5
CVE-2018-5462

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to…

Mitigation only
Fix from $1,950 2018-03-26
Intellispace Portal HIGH 7.5
CVE-2018-5464

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain una…

Mitigation only
Fix from $1,950 2018-03-26
Intellispace Portal HIGH 7.5
CVE-2018-5466

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain un…

Mitigation only
Fix from $1,950 2018-03-26
Cve 30360 Firmware HIGH 7.5
CVE-2014-10069

Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers…

Patch available
Fix from $1,950 2018-01-07
Wolfssl MEDIUM 5.9
CVE-2014-2903

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate n…

Fix: after 2.9.4
Fix from $1,600 2017-10-06
Kmail MEDIUM 5.9
CVE-2014-8878

KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive informatio…

Patch available
Fix from $1,600 2017-09-28
Nwa1100 N Firmware MEDIUM 5.9
CVE-2015-7256

ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, …

Mitigation only
Fix from $1,600 2017-09-28
iOS MEDIUM 5.9
CVE-2011-4667

The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS…

Mitigation only
Fix from $1,600 2017-09-25
Codeigniter CRITICAL 9.8
CVE-2014-8684EPSS 72%

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and conseque…

Fix: after 2.2.6
Fix from $2,300 2017-09-19
Codeigniter CRITICAL 9.8
CVE-2014-8686EPSS 37%

CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when …

Fix: after 2.1.4
Fix from $2,300 2017-09-19
Wicket HIGH 7.5
CVE-2014-7808

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism a…

Fix: 1.5.13 / 6.19.0+
Fix from $1,950 2017-09-15
Firesight System Software HIGH 7.5
CVE-2017-6766

A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.…

Mitigation only
Fix from $1,950 2017-08-07
Manageengine Opmanager CRITICAL 9.8
CVE-2015-9107

Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The im…

Mitigation only
Fix from $2,300 2017-08-04
HTTP Server HIGH 7.5
CVE-2016-0736EPSS 49%

In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either C…

No fix yet
Fix from $1,950 2017-07-27
Openpgpjs HIGH 7.5
CVE-2015-8013

s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentica…

Fix: after 1.2.0
Fix from $1,950 2017-07-25
Cloudforms Management Engine HIGH 7.5
CVE-2016-4457

CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.

No fix yet
Fix from $1,950 2017-06-08
Android HIGH 7.8
CVE-2015-9003

In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.

Patch available
Fix from $1,950 2017-05-16