Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
HIGH 8.1 CVE-2016-10680 adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP,… Adamvr Geoip Lite after 1.2.0 Fix from $1,9502018-05-29 HIGH 8.1 CVE-2016-10558 aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the module vuln… Aerospike 2.4.2+ Fix from $1,9502018-05-29 HIGH 8.1 CVE-2016-10559 selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads bina… Selenium Download 2.0.7+ Fix from $1,9502018-05-29 HIGH 8.1 CVE-2016-10566 install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over HTTP, whi… Install Nw 1.1.5+ Fix from $1,9502018-05-29 HIGH 8.1 CVE-2016-10567 product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information about the stat… Product Monitor 2.2.5+ Fix from $1,9502018-05-29 HIGH 8.1 CVE-2016-10568 geoip-lite-country is a stripped down version of geoip-lite, supporting only country lookup. geoip-lite-country before 1.1.4 downloads data resources… Geoip Lite Country 1.1.4+ Fix from $1,9502018-05-29 MEDIUM 5.8 CVE-2018-0281 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of … Secure Firewall Management Center Mitigation only Fix from $1,6002018-05-02 MEDIUM 5.8 CVE-2018-0283 A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of … Secure Firewall Management Center Mitigation only Fix from $1,6002018-05-02 HIGH 7.3 CVE-2013-4035 IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging fa… Sterling Connect No fix yet Fix from $1,9502018-05-01 MEDIUM 5.3 CVE-2013-5391 IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and En… Worklight Mitigation only Fix from $1,6002018-04-27 HIGH 7.5 CVE-2015-9258 In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the fiel… Notary 0.1+ Fix from $1,9502018-03-31 HIGH 7.4 CVE-2015-5039 The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not pro… Rational Clearcase after 8.0.1.10 Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-5458 Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain un… Intellispace Portal Mitigation only Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-5462 Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to… Intellispace Portal Mitigation only Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-5464 Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain una… Intellispace Portal Mitigation only Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-5466 Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain un… Intellispace Portal Mitigation only Fix from $1,9502018-03-26 HIGH 7.5 CVE-2014-10069 Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers… Cve 30360 Firmware Patch available Fix from $1,9502018-01-07 MEDIUM 5.9 CVE-2014-2903 CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate n… Wolfssl after 2.9.4 Fix from $1,6002017-10-06 MEDIUM 5.9 CVE-2014-8878 KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive informatio… Kmail Patch available Fix from $1,6002017-09-28 MEDIUM 5.9 CVE-2015-7256 ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, … Nwa1100 N Firmware Mitigation only Fix from $1,6002017-09-28 MEDIUM 5.9 CVE-2011-4667 The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS… iOS Mitigation only Fix from $1,6002017-09-25 CRITICAL 9.8 CVE-2014-8684EPSS 72% CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and conseque… Codeigniter after 2.2.6 Fix from $2,3002017-09-19 CRITICAL 9.8 CVE-2014-8686EPSS 37% CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when … Codeigniter after 2.1.4 Fix from $2,3002017-09-19 HIGH 7.5 CVE-2014-7808 Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism a… Wicket 1.5.13 / 6.19.0+ Fix from $1,9502017-09-15 HIGH 7.5 CVE-2017-6766 A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.… Firesight System Software Mitigation only Fix from $1,9502017-08-07 CRITICAL 9.8 CVE-2015-9107 Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The im… Manageengine Opmanager Mitigation only Fix from $2,3002017-08-04 HIGH 7.5 CVE-2016-0736EPSS 49% In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either C… HTTP Server No fix yet Fix from $1,9502017-07-27 HIGH 7.5 CVE-2015-8013 s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentica… Openpgpjs after 1.2.0 Fix from $1,9502017-07-25 HIGH 7.5 CVE-2016-4457 CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate. Cloudforms Management Engine No fix yet Fix from $1,9502017-06-08 HIGH 7.8 CVE-2015-9003 In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel. Android Patch available Fix from $1,9502017-05-16