Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mattermost MEDIUM 6.5
CVE-2022-0708

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members…

Fix: after 6.3.0
Fix from $1,600 2022-02-21
Perfect Brands For Woocommerce HIGH 7.5
CVE-2022-23982

The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.

Fix: after 2.0.4
Fix from $1,950 2022-02-18
Lemminx MEDIUM 5.5
CVE-2022-0672

A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMin…

Fix: 0.19.0+
Fix from $1,600 2022-02-18
Linux Kernel MEDIUM 5.5
CVE-2021-20320

A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special us…

Fix: 5.15+
Fix from $1,600 2022-02-18
Linux Kernel CRITICAL 9.8
CVE-2021-3773EPSS 5%

A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network …

Fix: 5.14 / 5.15.15+
Fix from $2,300 2022-02-16
Sourcegraph MEDIUM 6.5
CVE-2022-23643

Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channel vulnerabilitity i…

Fix: 3.35.2 / 3.36.3+
Fix from $1,600 2022-02-15
Switchvox MEDIUM 5.3
CVE-2021-45310

Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restrictio…

No fix yet
Fix from $1,600 2022-02-14
Dixell Xweb 500 Firmware CRITICAL 9.8
CVE-2021-45420EPSS 18%

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cg…

Mitigation only
Fix from $2,300 2022-02-14
Dixell Xweb 500 Firmware HIGH 7.5
CVE-2021-45421

Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to …

No fix yet
Fix from $1,950 2022-02-14
Puma MEDIUM 5.9
CVE-2022-23634

Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails…

Fix: 4.3.11 / 5.2.6.2+
Fix from $1,600 2022-02-11
Rails MEDIUM 5.9
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event …

Fix: 5.2.6.2 / 6.0.4.6+
Fix from $1,600 2022-02-11
Bixby Vision MEDIUM 5.3
CVE-2022-24003

Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision vi…

Fix: 3.7.50.6+
Fix from $1,600 2022-02-11
Modicon M340 Bmxp342020 Firmware HIGH 7.5
CVE-2021-22785

A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when a…

Fix: 3.40+
Fix from $1,950 2022-02-11
Globalprotect MEDIUM 6.5
CVE-2022-0018

An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the credentials of the local user…

Fix: 5.1.10 / 5.2.9+
Fix from $1,600 2022-02-10
Prime Service Catalog MEDIUM 6.5
CVE-2022-20680

A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitiv…

Fix: after 12.0
Fix from $1,600 2022-02-10
S\/4hana MEDIUM 6.5
CVE-2022-22542

S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for…

Mitigation only
Fix from $1,600 2022-02-09
Amt Ac 8260 Firmware MEDIUM 6.7
CVE-2021-0166

Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some…

Fix: 11.8.90 / 12.0.85+
Fix from $1,600 2022-02-09
Amt Ac 8260 Firmware MEDIUM 5.5
CVE-2021-0170

Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some…

Fix: 11.8.90 / 12.0.85+
Fix from $1,600 2022-02-09
Xwiki HIGH 7.5
CVE-2022-23619

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess …

Fix: 12.10.9+
Fix from $1,950 2022-02-09
Simatic Pcs 7 HIGH 8.8
CVE-2021-40360

A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 …

Fix: 7.4+
Fix from $1,950 2022-02-09
Debian Linux HIGH 7.5
CVE-2022-21712

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following…

Fix: 22.1.0+
Fix from $1,950 2022-02-07
Diskstation Manager HIGH 7.5
CVE-2022-22680

Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 all…

Fix: 6.2.4-25556-3 / 7.0.1-42218-2+
Fix from $1,950 2022-02-07
Gobblin MEDIUM 5.5
CVE-2021-36151

In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.…

Fix: after 0.15.0
Fix from $1,600 2022-02-04
Power System Ac922 \(8335 Gtx\) Firmware HIGH 7.5
CVE-2021-38960

IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.

Mitigation only
Fix from $1,950 2022-02-04
Epyc 7763 Firmware MEDIUM 5.5
CVE-2020-12966

AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure …

Mitigation only
Fix from $1,600 2022-02-04
Debian Linux MEDIUM 6.5
CVE-2022-23607

treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq…

Fix: 22.1.0+
Fix from $1,600 2022-02-01
Download Monitor MEDIUM 6.8
CVE-2021-31567

Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows a…

Fix: after 4.4.6
Fix from $1,600 2022-01-28
Linkone HIGH 7.5
CVE-2021-40340

Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net info…

Mitigation only
Fix from $1,950 2022-01-28
Network Management Card 2 Firmware MEDIUM 5.3
CVE-2021-22815

A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninter…

Fix: after 6.9.8
Fix from $1,600 2022-01-28
Rack Power Distribution Unit With Network Management Card 2 Firmware HIGH 8.0
CVE-2021-22825

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with ele…

Fix: 1.2.0.2 / 7.0.6+
Fix from $1,950 2022-01-28