Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Colord HIGH 7.5
CVE-2021-42523

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. …

Patch available
Fix from $1,950 2022-08-25
Linux Kernel MEDIUM 5.9
CVE-2021-3714

A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local e…

Mitigation only
Fix from $1,600 2022-08-23
Linux Kernel MEDIUM 5.5
CVE-2021-3736

A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Me…

Fix: after 5.14.20
Fix from $1,600 2022-08-23
Opencryptoki MEDIUM 5.5
CVE-2021-3798

A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor …

Fix: 3.17.0+
Fix from $1,600 2022-08-23
Debian Linux MEDIUM 5.5
CVE-2021-3800

A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivil…

Fix: 2.62.5 / 2.63.6+
Fix from $1,600 2022-08-23
Emc Powerscale Onefs MEDIUM 5.5
CVE-2022-31238

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive informat…

Fix: after 9.4.0.2
Fix from $1,600 2022-08-22
Tabit HIGH 7.5
CVE-2022-34776

Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bi…

Fix: 3.27.0+
Fix from $1,950 2022-08-22
Simple Job Board MEDIUM 5.3
CVE-2022-2558

The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certai…

Fix: 2.10.0+
Fix from $1,600 2022-08-22
Satellite HIGH 8.8
CVE-2021-3590

A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output…

Mitigation only
Fix from $1,950 2022-08-22
Office MEDIUM 5.3
CVE-2022-30693

Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to obtain the data of the…

Fix: after 10.8.5
Fix from $1,600 2022-08-18
Doracms CRITICAL 9.8
CVE-2022-35147

DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.

Fix: after 2.1.8
Fix from $2,300 2022-08-17
Authenticator HIGH 7.5
CVE-2022-35290

Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.

Fix: 1.2.17+
Fix from $1,950 2022-08-10
Infosphere Information Server HIGH 7.5
CVE-2022-35715

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…

Mitigation only
Fix from $1,950 2022-08-10
Simcenter Star Ccm\+ Viewer MEDIUM 5.3
CVE-2022-34659

A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applica…

Mitigation only
Fix from $1,600 2022-08-10
Windows 10 MEDIUM 5.5
CVE-2022-34708

Windows Kernel Information Disclosure Vulnerability

Mitigation only
Fix from $1,600 2022-08-09
Windows 10 MEDIUM 5.5
CVE-2022-34710

Windows Defender Credential Guard Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2022-08-09
Windows 10 MEDIUM 5.5
CVE-2022-34712

Windows Defender Credential Guard Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2022-08-09
Exchange Server MEDIUM 5.3
CVE-2022-34692

Microsoft Exchange Server Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2022-08-09
Windows 10 MEDIUM 5.5
CVE-2022-30197

Windows Kernel Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2022-08-09
Simple E Learning System HIGH 7.5
CVE-2022-2704

A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of…

No fix yet
Fix from $1,950 2022-08-08
Linkhub Mesh Wifi Ac1200 HIGH 7.5
CVE-2022-27630

An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-c…

No fix yet
Fix from $1,950 2022-08-05
Linkhub Mesh Wifi Ac1200 HIGH 7.5
CVE-2022-27633

An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-cra…

No fix yet
Fix from $1,950 2022-08-05
Cloudvision Portal MEDIUM 5.5
CVE-2022-29071

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certai…

Fix: after 2022.1.0
Fix from $1,600 2022-08-05
Game Launcher MEDIUM 5.0
CVE-2022-36834

Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interacti…

Fix: 6.0.07+
Fix from $1,600 2022-08-05
Mprweb MEDIUM 5.3
CVE-2022-31185

mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, even if a user had clicked the `…

Fix: after 5.0.0
Fix from $1,600 2022-08-01
Dspace MEDIUM 5.3
CVE-2022-31190

DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace…

Fix: 6.4+
Fix from $1,600 2022-08-01
Media Server HIGH 7.5
CVE-2022-27614

Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attac…

Fix: 1.4-2665 / 1.8.1-2876+
Fix from $1,950 2022-07-28
Wechat HIGH 7.5
CVE-2021-40180

In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContact…

No fix yet
Fix from $1,950 2022-07-26
Slack Morphism HIGH 7.5
CVE-2022-31162

Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug …

Fix: 0.41.0+
Fix from $1,950 2022-07-22
Givewp MEDIUM 5.3
CVE-2022-2117

The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-A…

Fix: after 2.20.2
Fix from $1,600 2022-07-18