Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Ex1200t Firmware HIGH 7.5
CVE-2021-42886

TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without author…

No fix yet
Fix from $1,950 2022-06-03
Powerstoreos CRITICAL 9.8
CVE-2022-26869

Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploi…

Fix: 2.1.1.0+
Fix from $2,300 2022-06-02
Curl HIGH 7.5
CVE-2022-27775

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool …

Fix: after 7.82.0
Fix from $1,950 2022-06-02
Bigbluebutton MEDIUM 5.3
CVE-2022-29235

BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able t…

Fix: 2.3.18+
Fix from $1,600 2022-06-02
Bigbluebutton MEDIUM 6.5
CVE-2022-29232

BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circum…

Fix: 2.3.9+
Fix from $1,600 2022-06-01
Cloudlink MEDIUM 6.5
CVE-2022-24414

Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies …

Fix: after 7.1.3
Fix from $1,600 2022-05-26
Ios Xr MEDIUM 6.5
CVE-2022-20821 KEVEPSS 12%

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is…

Mitigation only
Fix from $1,600 2022-05-26
Drupal HIGH 8.1
CVE-2022-29248

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that …

Fix: 6.5.6 / 7.4.3+
Fix from $1,950 2022-05-25
Drawio HIGH 7.5
CVE-2022-1815EPSS 6%

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.

Fix: 18.1.2+
Fix from $1,950 2022-05-25
Vaadin HIGH 7.5
CVE-2022-29567

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through…

Fix: after 23.0.8
Fix from $1,950 2022-05-24
Argo Cd CRITICAL 10.0
CVE-2022-29165

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with versi…

Fix: 2.1.15 / 2.2.9+
Fix from $2,300 2022-05-20
Drawio MEDIUM 6.1
CVE-2022-1774

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.

Fix: 18.0.7+
Fix from $1,600 2022-05-18
Cyber Protect HIGH 7.5
CVE-2022-30990

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before bui…

Fix: 15+
Fix from $1,950 2022-05-18
Tooljet HIGH 8.8
CVE-2022-23067

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite li…

Fix: after 1.2.2
Fix from $1,950 2022-05-18
Security Identity Governance And Intelligence MEDIUM 5.3
CVE-2020-4957

IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks again…

Patch available
Fix from $1,600 2022-05-17
Brave MEDIUM 5.3
CVE-2022-30334

Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers. NOTE: although this was fixe…

Fix: 1.34+
Fix from $1,600 2022-05-07
Access For Android MEDIUM 5.5
CVE-2022-27875

On F5 Access for Android 3.x versions prior to 3.0.8, a Task Hijacking vulnerability exists in the F5 Access for Android application, which may allow…

Fix: 3.0.8+
Fix from $1,600 2022-05-05
F5os A MEDIUM 5.3
CVE-2022-25990

On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have re…

No fix yet
Fix from $1,600 2022-05-05
Guardium Data Encryption MEDIUM 5.3
CVE-2021-39020

IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unaut…

Fix: after 4.0.0.7
Fix from $1,600 2022-05-05
Gatemanager 4250 Firmware MEDIUM 6.7
CVE-2022-25787

Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack conne…

Fix: 9.7.622134021+
Fix from $1,600 2022-05-04
Fuchsia MEDIUM 5.5
CVE-2022-0882

A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It …

Fix: 4.1.1+
Fix from $1,600 2022-05-03
Scada Server CRITICAL 9.8
CVE-2021-43938

Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or auth…

Mitigation only
Fix from $2,300 2022-04-29
Linux Kernel HIGH 7.1
CVE-2022-1353

A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain…

Fix: 5.17+
Fix from $1,950 2022-04-29
Scada Server HIGH 8.8
CVE-2021-43937

Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intenti…

No fix yet
Fix from $1,950 2022-04-29
Tz300p Firmware MEDIUM 5.3
CVE-2022-22276

A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.

Fix: 7.0.1 / 7.0.1.0+
Fix from $1,600 2022-04-27
Tz300p Firmware MEDIUM 5.3
CVE-2022-22277

A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.

Fix: 6.5.4.10 / 7.0.1.0+
Fix from $1,600 2022-04-27
Cc612 Firmware HIGH 7.5
CVE-2021-34589

In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authenticatio…

Fix: 5.11.2 / 5.12.5+
Fix from $1,950 2022-04-27
Kibana MEDIUM 5.3
CVE-2022-23711

A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring …

Fix: 7.17.3 / 8.1.3+
Fix from $1,600 2022-04-21
Glpi HIGH 7.5
CVE-2022-24867

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you …

Fix: 10.0.0+
Fix from $1,950 2022-04-21
Humhub MEDIUM 6.5
CVE-2022-24865

HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrie…

Fix: 1.9.4 / 1.10.4+
Fix from $1,600 2022-04-20