Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Sylius MEDIUM 5.5
CVE-2022-24742

Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains u…

Fix: 1.9.10 / 1.10.11+
Fix from $1,600 2022-03-14
G90 Firmware MEDIUM 5.5
CVE-2021-41849

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext usin…

No fix yet
Fix from $1,600 2022-03-11
G90 Firmware HIGH 7.8
CVE-2021-41850

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three I…

No fix yet
Fix from $1,950 2022-03-11
Moodle MEDIUM 5.3
CVE-2021-32473

It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.…

Fix: 3.5.18 / 3.8.9+
Fix from $1,600 2022-03-11
Freetakserver Ui HIGH 7.5
CVE-2022-25512

FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.

No fix yet
Fix from $1,950 2022-03-11
Debian Linux MEDIUM 5.3
CVE-2022-26847

SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

Fix: 3.2.14 / 4.0.5+
Fix from $1,600 2022-03-10
Business Objects Business Intelligence Platform MEDIUM 6.5
CVE-2022-24398

Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access informat…

No fix yet
Fix from $1,600 2022-03-10
Simple Diagnostics Agent HIGH 7.5
CVE-2022-22547

Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a ran…

Fix: 1.58+
Fix from $1,950 2022-03-10
phpMyAdmin HIGH 7.5
CVE-2022-0813

PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang para…

Fix: after 5.1.1
Fix from $1,950 2022-03-10
Linux Kernel HIGH 7.8
CVE-2022-0516

A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a …

Fix: 5.17+
Fix from $1,950 2022-03-10
Fedora HIGH 7.5
CVE-2022-0725

A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vuln…

Mitigation only
Fix from $1,950 2022-03-10
Linux Kernel MEDIUM 5.5
CVE-2021-4023

A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellatio…

Fix: after 5.14
Fix from $1,600 2022-03-10
Linux Kernel MEDIUM 5.5
CVE-2021-3732

A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local u…

Fix: 5.14+
Fix from $1,600 2022-03-10
Ax6000 Firmware MEDIUM 5.3
CVE-2020-14112

Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing configuration. Attackers can expl…

Fix: 1.0.56+
Fix from $1,600 2022-03-10
Shopware MEDIUM 5.3
CVE-2022-24747

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no proper…

Fix: 6.4.8.2+
Fix from $1,600 2022-03-09
Ritto Wiser Door HIGH 7.6
CVE-2021-22783

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected …

Mitigation only
Fix from $1,950 2022-03-09
Nextcloud Server MEDIUM 5.3
CVE-2021-41239

Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user…

Fix: 20.0.14 / 21.0.6+
Fix from $1,600 2022-03-08
Fedora MEDIUM 6.5
CVE-2022-24737

HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that bel…

Fix: 3.1.0+
Fix from $1,600 2022-03-07
Shescape MEDIUM 5.5
CVE-2022-24725

Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when…

Fix: 1.5.1+
Fix from $1,600 2022-03-03
Enterprise Linux MEDIUM 5.5
CVE-2021-3602

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Doc…

Fix: 1.16.8 / 1.17.2+
Fix from $1,600 2022-03-03
Debian Linux HIGH 7.5
CVE-2022-23648EPSS 27%

containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.1…

Fix: 1.4.13 / 1.5.10+
Fix from $1,950 2022-03-03
Tang HIGH 7.5
CVE-2021-4076

A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.

Fix: 11+
Fix from $1,950 2022-03-02
PostgreSQL MEDIUM 6.5
CVE-2021-3677

A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated da…

Fix: 11.13 / 12.8+
Fix from $1,600 2022-03-02
Manageengine Desktop Central MEDIUM 5.3
CVE-2022-23779EPSS 15%

Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading …

Fix: 10.1.2137.8+
Fix from $1,600 2022-03-02
Fortimanager MEDIUM 5.5
CVE-2022-22303

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 …

Fix: after 7.0.2
Fix from $1,600 2022-03-02
Debian Linux MEDIUM 6.5
CVE-2022-0577

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.

Fix: 2.6.1+
Fix from $1,600 2022-03-02
Yoast Seo MEDIUM 5.3
CVE-2021-25118EPSS 6%

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST …

Fix: 17.3+
Fix from $1,600 2022-02-28
Filecloud MEDIUM 5.3
CVE-2022-24633

All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<userna…

Fix: 21.3.0.18447+
Fix from $1,600 2022-02-24
Node Request Retry HIGH 7.5
CVE-2022-0654

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0.

Fix: 7.0.0+
Fix from $1,950 2022-02-23
Wpdiscuz HIGH 7.5
CVE-2022-23984

Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).

Fix: after 7.3.11
Fix from $1,950 2022-02-21