Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Vikbooking Hotel Booking Engine \& Property Management System Plugin MEDIUM 5.3
CVE-2022-27863

Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking d…

Fix: after 1.5.3
Fix from $1,600 2022-04-19
Be Popia Compliant MEDIUM 5.3
CVE-2022-1186

The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via a…

Fix: after 1.1.5
Fix from $1,600 2022-04-19
Linux Kernel MEDIUM 5.5
CVE-2011-4917

In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.

Fix: after 3.1
Fix from $1,600 2022-04-18
Simple Ajax Chat HIGH 7.5
CVE-2022-27849

Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115

Fix: after 20220115
Fix from $1,950 2022-04-15
Metabase MEDIUM 5.3
CVE-2022-24853

Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our …

Fix: 0.40.8 / 0.41.7+
Fix from $1,600 2022-04-14
Discatsharp MEDIUM 6.5
CVE-2022-24849

DisCatSharp is a Discord API wrapper for .NET. Users of versions 9.8.5, 9.8.6, 9.9.0 and previously published prereleases of 10.0.0 who have used eit…

Fix: 9.9.1+
Fix from $1,600 2022-04-14
Aws Client Vpn MEDIUM 5.0
CVE-2022-25166

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file …

No fix yet
Fix from $1,600 2022-04-14
Junos Os Evolved HIGH 7.5
CVE-2022-22183

An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect …

Mitigation only
Fix from $1,950 2022-04-14
Gocd HIGH 7.5
CVE-2021-43287EPSS 28%

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to t…

Fix: 21.3.0+
Fix from $1,950 2022-04-14
Cloud Foundation MEDIUM 5.3
CVE-2022-22961

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess informa…

Fix: 5.0 / 9.0+
Fix from $1,600 2022-04-13
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2022-27667

Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to ac…

Mitigation only
Fix from $1,950 2022-04-12
Mendix HIGH 7.5
CVE-2022-27241

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions…

Fix: 9.11.0+
Fix from $1,950 2022-04-12
Hedgedoc MEDIUM 5.3
CVE-2022-24837

HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enum…

Fix: 1.9.3+
Fix from $1,600 2022-04-11
Migration\, Backup\, Staging HIGH 7.5
CVE-2022-27844

Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

Fix: 0.9.71+
Fix from $1,950 2022-04-11
Discourse MEDIUM 5.3
CVE-2022-24804

Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expo…

Fix: 2.8.3+
Fix from $1,600 2022-04-11
Parking Lot Management System MEDIUM 5.3
CVE-2022-25594

Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote attacker can input specific URLs…

No fix yet
Fix from $1,600 2022-04-07
Forticlient MEDIUM 5.3
CVE-2021-43205

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and bel…

Fix: after 7.0.2
Fix from $1,600 2022-04-06
Openeyes MEDIUM 6.5
CVE-2021-40375

Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privileg…

No fix yet
Fix from $1,600 2022-04-06
Booking Package HIGH 7.5
CVE-2022-0709

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is…

Fix: 1.5.29+
Fix from $1,950 2022-04-04
Business Central HIGH 7.5
CVE-2019-14839

It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercep…

Fix: after 7.48.0
Fix from $1,950 2022-04-01
Pomerium CRITICAL 9.1
CVE-2022-24797

Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics h…

Fix: 0.17.1+
Fix from $2,300 2022-03-31
Flex 1085 Firmware HIGH 7.5
CVE-2022-1077

A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log …

Mitigation only
Fix from $1,950 2022-03-29
Argo Cd HIGH 8.8
CVE-2022-24768

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an …

Fix: 2.1.14 / 2.2.8+
Fix from $1,950 2022-03-23
Linux Kernel MEDIUM 5.5
CVE-2022-0854

A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read rand…

Fix: after 5.16
Fix from $1,600 2022-03-23
Multilin B30 Firmware HIGH 7.5
CVE-2021-27422

GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure wi…

Fix: 8.10+
Fix from $1,950 2022-03-23
Multilin B30 Firmware MEDIUM 5.3
CVE-2021-27424

GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MO…

Fix: 8.10+
Fix from $1,600 2022-03-23
Responsive Menu HIGH 8.8
CVE-2022-25602

Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugi…

Fix: after 4.1.7
Fix from $1,950 2022-03-18
Axeda Agent MEDIUM 5.3
CVE-2022-25248

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specif…

Fix: 6.9.1 / 6.9.215+
Fix from $1,600 2022-03-16
Httpie MEDIUM 5.3
CVE-2022-0430

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.

Fix: 3.1.0+
Fix from $1,600 2022-03-15
Sysend.js MEDIUM 6.5
CVE-2022-24762

sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication…

Fix: 1.10.0+
Fix from $1,600 2022-03-14