Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Jupyter Server HIGH 8.8
CVE-2022-29241

Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter Notebook. Prior to v…

Fix: 1.17.0+
Fix from $1,950 2022-06-14
Aerial X 1200m Firmware HIGH 7.5
CVE-2022-31309

A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to obtain sensitive router information via executio…

No fix yet
Fix from $1,950 2022-06-14
Aerial X 1200m Firmware HIGH 7.5
CVE-2022-31308

A vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.191012 allows attackers to obtain sensitive router information via execution …

No fix yet
Fix from $1,950 2022-06-14
Qcm2290 Firmware MEDIUM 5.5
CVE-2021-35080

Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobi…

Mitigation only
Fix from $1,600 2022-06-14
Qcm6125 Firmware MEDIUM 5.5
CVE-2021-35070

RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial I…

Mitigation only
Fix from $1,600 2022-06-14
Couchbase Server HIGH 7.5
CVE-2022-32192

Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.

Fix: 7.0.4+
Fix from $1,950 2022-06-13
Npm HIGH 7.5
CVE-2022-29244

npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`,…

Fix: 8.11.0+
Fix from $1,950 2022-06-13
Hc Custom Wp Admin Url MEDIUM 5.3
CVE-2022-1595

The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request

Fix: after 1.4
Fix from $1,600 2022-06-13
Otrs MEDIUM 5.3
CVE-2022-32740

A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket customer under certain circumstances.

Fix: 7.0.35 / 8.0.23+
Fix from $1,600 2022-06-13
Otrs MEDIUM 5.3
CVE-2022-32741

Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.

Fix: 7.0.35 / 8.0.23+
Fix from $1,600 2022-06-13
Calendar Resource Planning MEDIUM 5.3
CVE-2022-32739

When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS relea…

Fix: 7.0.31 / 7.0.35+
Fix from $1,600 2022-06-13
Drupal HIGH 7.5
CVE-2022-31042

Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using …

Fix: 6.5.7 / 7.4.4+
Fix from $1,950 2022-06-10
Drupal HIGH 7.5
CVE-2022-31043

Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request usi…

Fix: 6.5.7 / 7.4.4+
Fix from $1,950 2022-06-10
Solar Log 250 Firmware HIGH 7.5
CVE-2017-20022

A vulnerability has been found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as problematic. This vulnerability affects unknown code. The mani…

No fix yet
Fix from $1,950 2022-06-09
Solar Log 250 Firmware HIGH 7.5
CVE-2017-20019

A vulnerability classified as problematic was found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this vulnerability is an unknown functionality…

No fix yet
Fix from $1,950 2022-06-09
Mechanize HIGH 7.5
CVE-2022-31033

The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies, follows redirects, and can …

Fix: 2.8.5+
Fix from $1,950 2022-06-09
Semantic Release HIGH 7.5
CVE-2022-31051

semantic-release is an open source npm package for automated version management and package publishing. In affected versions secrets that would norma…

Fix: 19.0.3+
Fix from $1,950 2022-06-09
HTTP Server MEDIUM 5.3
CVE-2022-28614

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very larg…

Fix: after 2.4.53
Fix from $1,600 2022-06-09
HTTP Server HIGH 7.5
CVE-2022-30556

Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the …

Fix: 2.4.54+
Fix from $1,950 2022-06-09
Registro Elettronico HIGH 7.5
CVE-2019-25069

A vulnerability, which was classified as problematic, has been found in Axios Italia Axios RE 1.7.0/7.0.0. This issue affects some unknown processing…

Mitigation only
Fix from $1,950 2022-06-09
Account MEDIUM 5.3
CVE-2022-30734

Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number wi…

Fix: 13.2.00.6+
Fix from $1,600 2022-06-07
Account HIGH 7.5
CVE-2022-30735

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.

Fix: 13.2.00.6+
Fix from $1,950 2022-06-07
Account MEDIUM 5.3
CVE-2022-30736

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without per…

Fix: 13.2.00.6+
Fix from $1,600 2022-06-07
Account MEDIUM 5.3
CVE-2022-30737

Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.

Fix: 13.2.00.6+
Fix from $1,600 2022-06-07
Account MEDIUM 5.3
CVE-2022-30743

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without per…

Fix: 13.2.00.6+
Fix from $1,600 2022-06-07
Account HIGH 7.5
CVE-2022-30732

Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onA…

Fix: 13.2.00.6+
Fix from $1,950 2022-06-07
Account MEDIUM 5.3
CVE-2022-30733

Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number wit…

Fix: 13.2.00.6+
Fix from $1,600 2022-06-07
App MEDIUM 6.5
CVE-2020-36532

A vulnerability has been found in Klapp App and classified as problematic. This vulnerability affects unknown code of the component Authorization. Th…

No fix yet
Fix from $1,600 2022-06-07
Gradle HIGH 7.2
CVE-2022-30586

Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.

Fix: 1.3.1+
Fix from $1,950 2022-06-06
Calico MEDIUM 5.5
CVE-2022-28224

Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floatin…

Fix: 3.11.4 / 3.20.5+
Fix from $1,600 2022-06-06