Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
macOS MEDIUM 5.5
CVE-2022-32818

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5. An app may be able to leak sensitive kernel state.

Fix: 12.5+
Fix from $1,600 2022-09-23
Rocket.chat MEDIUM 6.5
CVE-2022-32220

An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from pr…

Fix: 5.0+
Fix from $1,600 2022-09-23
En6200 Prime Quad 35 Firmware HIGH 7.5
CVE-2022-40629

This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive),…

Fix: 22.21.2+
Fix from $1,950 2022-09-23
Customer Reviews For Woocommerce HIGH 7.5
CVE-2022-40194

Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress

Fix: after 5.3.5
Fix from $1,950 2022-09-23
Fhir Works On Aws Authz Smart MEDIUM 6.5
CVE-2022-39230

fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Versions 3.1.1 and 3.1.2 are subject…

Fix: 3.1.3+
Fix from $1,600 2022-09-23
System Center Configuration Manager MEDIUM 5.3
CVE-2021-39190

The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is…

Fix: 2.3.0+
Fix from $1,600 2022-09-22
Keylime HIGH 7.5
CVE-2022-23952

In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.

Fix: 6.3.0+
Fix from $1,950 2022-09-21
Keylime HIGH 7.5
CVE-2022-23948

A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously created unprivil…

Fix: 6.3.0+
Fix from $1,950 2022-09-21
Insightvm MEDIUM 5.3
CVE-2019-5641

Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Ins…

Fix: after 6.6.160
Fix from $1,600 2022-09-21
Integrated Lights Out 5 Firmware HIGH 7.8
CVE-2022-28638

An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that could potentially lead to a loss…

Fix: 2.72+
Fix from $1,950 2022-09-20
Nextcloud MEDIUM 5.5
CVE-2022-39210

Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not pr…

Fix: 3.21.0+
Fix from $1,600 2022-09-17
Talk MEDIUM 5.3
CVE-2022-39212

Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last vid…

Fix: 13.0.8 / 14.0.4+
Fix from $1,600 2022-09-17
Nextcloud Enterprise Server HIGH 7.5
CVE-2022-36074

Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to st…

Fix: 22.2.11 / 23.0.7+
Fix from $1,950 2022-09-15
Glpi MEDIUM 5.3
CVE-2022-31143

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk featu…

Fix: 10.0.3+
Fix from $1,600 2022-09-14
Businessobjects Business Intelligence MEDIUM 5.2
CVE-2022-32244

Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data,…

Mitigation only
Fix from $1,600 2022-09-13
Shopware MEDIUM 5.3
CVE-2022-36101

Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained…

Fix: 5.7.15+
Fix from $1,600 2022-09-12
Mailform Pro Cgi MEDIUM 5.9
CVE-2022-38400

Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a s…

Fix: after 4.3.1
Fix from $1,600 2022-09-08
Parse Server HIGH 7.5
CVE-2022-36079

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields (keys used internally by Pars…

Fix: 4.10.14 / 5.2.5+
Fix from $1,950 2022-09-07
Wp Cerber Security\, Anti Spam \& Malware Scan MEDIUM 5.3
CVE-2022-2939

The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumera…

Fix: after 9.0
Fix from $1,600 2022-09-06
Wp Libre Form MEDIUM 6.5
CVE-2022-34867

Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete su…

Fix: after 2.0.8
Fix from $1,600 2022-09-06
Transposh Wordpress Translation MEDIUM 5.3
CVE-2022-2462

The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to…

Fix: after 1.0.8.1
Fix from $1,600 2022-09-06
Grafana Image Renderer HIGH 8.1
CVE-2022-31176

Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). …

Fix: 3.6.1+
Fix from $1,950 2022-09-02
Enterprise Linux Server MEDIUM 5.3
CVE-2022-2739

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t…

Mitigation only
Fix from $1,600 2022-09-01
Sos MEDIUM 5.5
CVE-2022-2806

It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7…

Fix: 4.2-20.el8_6 / 4.4.7-2.el8ev+
Fix from $1,600 2022-09-01
Stop Spam Comments MEDIUM 6.5
CVE-2022-1663

The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment sectio…

Fix: after 0.2.1.2
Fix from $1,600 2022-08-29
Linux Kernel HIGH 7.1
CVE-2022-0850

A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.

Fix: 4.4.276 / 4.9.276+
Fix from $1,950 2022-08-29
Enterprise Linux MEDIUM 5.5
CVE-2022-0851

There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription…

No fix yet
Fix from $1,600 2022-08-29
Tripleo Heat Templates MEDIUM 5.5
CVE-2021-3585

A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.

Fix: 8.4.1+
Fix from $1,600 2022-08-26
Foreman HIGH 7.8
CVE-2021-20260

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host…

Mitigation only
Fix from $1,950 2022-08-26
Anjuta HIGH 7.5
CVE-2021-42522

There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of …

Mitigation only
Fix from $1,950 2022-08-25