Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
P5e Gnss Firmware MEDIUM 5.3
CVE-2022-30625

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A direct…

Mitigation only
Fix from $1,600 2022-07-18
Linux Kernel MEDIUM 5.5
CVE-2021-4135

A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device s…

Fix: 5.16+
Fix from $1,600 2022-07-14
Mattermost Server MEDIUM 6.5
CVE-2022-2401

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by …

Fix: 6.3.9 / 6.5.2+
Fix from $1,600 2022-07-14
Engineering Lifecycle Optimization Publishing MEDIUM 6.5
CVE-2021-39019

IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP…

Patch available
Fix from $1,600 2022-07-14
Convert2rhel MEDIUM 5.5
CVE-2022-1662

In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password via the C…

Patch available
Fix from $1,600 2022-07-14
Businessobjects Business Intelligence Platform MEDIUM 6.0
CVE-2022-35169

SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR …

Mitigation only
Fix from $1,600 2022-07-12
Linux Kernel MEDIUM 5.5
CVE-2011-4916

Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

Fix: after 3.1
Fix from $1,600 2022-07-12
Qradar Network Security HIGH 7.5
CVE-2020-4159

IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to mount further attacks agains…

Patch available
Fix from $1,950 2022-07-12
Fedora MEDIUM 6.5
CVE-2022-29901

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak…

Mitigation only
Fix from $1,600 2022-07-12
HTTP Server CRITICAL 9.8
CVE-2020-35167

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discr…

Fix: 4.1.5 / 4.6+
Fix from $2,300 2022-07-11
Unsafe Accessor HIGH 7.5
CVE-2022-31139

UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data …

Fix: 1.7.0+
Fix from $1,950 2022-07-11
Garoon MEDIUM 6.5
CVE-2022-29512

Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticat…

Fix: after 5.9.1
Fix from $1,600 2022-07-11
Fedora HIGH 7.1
CVE-2022-33741

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond…

Fix: 4.9.322 / 4.14.287+
Fix from $1,950 2022-07-05
Fedora HIGH 7.1
CVE-2022-33742

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond…

Fix: 4.9.322 / 4.14.287+
Fix from $1,950 2022-07-05
Parse Server HIGH 8.2
CVE-2022-31112

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery d…

Fix: 4.10.13 / 5.2.4+
Fix from $1,950 2022-06-30
Teleopti Workforce Management MEDIUM 6.5
CVE-2017-20109

A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the fi…

Fix: after 7.1.0
Fix from $1,600 2022-06-29
Teleopti Workforce Management HIGH 7.5
CVE-2017-20110

A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue is some unknown functionalit…

Fix: after 7.1.0
Fix from $1,950 2022-06-29
Glpi MEDIUM 5.3
CVE-2022-31068

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affec…

Fix: 10.0.2+
Fix from $1,600 2022-06-28
Debian Linux HIGH 7.7
CVE-2022-31090

Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handle…

Fix: 6.5.8 / 7.4.5+
Fix from $1,950 2022-06-27
Debian Linux HIGH 7.7
CVE-2022-31091

Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a r…

Fix: 6.5.8 / 7.4.5+
Fix from $1,950 2022-06-27
Remote Desktop Manager MEDIUM 6.5
CVE-2022-2221

Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access …

Fix: 2022.1.8+
Fix from $1,600 2022-06-27
Projectsend MEDIUM 5.7
CVE-2017-20101

A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_down…

No fix yet
Fix from $1,600 2022-06-27
Parse Url HIGH 7.5
CVE-2022-0722

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.

Fix: 7.0.0+
Fix from $1,950 2022-06-27
Discourse Chat MEDIUM 6.5
CVE-2022-31095

discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an…

Fix: 0.4+
Fix from $1,600 2022-06-21
Robotic Process Automation MEDIUM 6.5
CVE-2022-30607

IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive info…

Patch available
Fix from $1,600 2022-06-17
Fedora MEDIUM 5.5
CVE-2022-30184EPSS 5%

.NET and Visual Studio Information Disclosure Vulnerability

Fix: 6.2.1 / 16.9.22+
Fix from $1,600 2022-06-15
Nestjs Proxy HIGH 7.5
CVE-2022-31069

NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to control when Auth…

Fix: 0.7.0+
Fix from $1,950 2022-06-15
Nestjs Proxy HIGH 7.5
CVE-2022-31070

NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to block sensitive c…

Fix: 0.7.0+
Fix from $1,950 2022-06-15
Email Security Appliance HIGH 7.7
CVE-2022-20664

A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco …

Fix: 13.6.2-090 / 14.0.2-020+
Fix from $1,950 2022-06-15
Discourse MEDIUM 5.3
CVE-2022-31060

Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5` in the `beta` and `tests-pas…

Fix: 2.8.4+
Fix from $1,600 2022-06-14