Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Security Guardium Insights MEDIUM 5.9
CVE-2021-29838

IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric…

Patch available
Fix from $1,600 2022-01-26
Buddyboss MEDIUM 5.3
CVE-2021-44692

BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID…

Fix: after 1.8.0
Fix from $1,600 2022-01-26
Advance Steel HIGH 7.8
CVE-2021-40159

An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead t…

Fix: 2022.1.2+
Fix from $1,950 2022-01-25
Agilia Connect Firmware MEDIUM 5.3
CVE-2021-23195

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. Whe…

Fix: 3.0+
Fix from $1,600 2022-01-21
Microweber HIGH 7.5
CVE-2022-0281EPSS 12%

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

Fix: after 1.2.10
Fix from $1,950 2022-01-20
Shardingsphere Elasticjob Ui MEDIUM 6.5
CVE-2022-22733EPSS 38%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest acco…

Mitigation only
Fix from $1,600 2022-01-20
Debian Linux MEDIUM 5.3
CVE-2022-21296

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 6.1
CVE-2022-0235

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Fix: 1.0 / 2.6.7+
Fix from $1,600 2022-01-16
Discourse MEDIUM 5.3
CVE-2022-21677

Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for the group as well as the group…

Fix: after 2.7.12
Fix from $1,600 2022-01-14
Qca6390 Firmware MEDIUM 5.5
CVE-2021-30314

Lack of validation for third party application accessing the service can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapd…

Mitigation only
Fix from $1,600 2022-01-13
Cortex Xdr Agent MEDIUM 5.5
CVE-2022-0013

A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arb…

Fix: 5.0.12 / 6.1.9+
Fix from $1,600 2022-01-12
Guacamole MEDIUM 6.5
CVE-2021-41767

Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allo…

Fix: after 1.3.0
Fix from $1,600 2022-01-11
Crosis MEDIUM 6.5
CVE-2022-21671

@replit/crosis is a JavaScript client that speaks Replit's container protocol. A vulnerability that involves exposure of sensitive information exists…

Fix: 7.3.1+
Fix from $1,600 2022-01-11
The Plus Addons For Elementor HIGH 7.5
CVE-2021-24948

The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action…

Fix: 5.0.7+
Fix from $1,950 2022-01-10
Partkeepr MEDIUM 6.5
CVE-2022-22701

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an auth…

Fix: after 1.4.0
Fix from $1,600 2022-01-10
Manageengine Desktop Central MEDIUM 6.5
CVE-2021-46166

Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Report…

Fix: 10.0.662+
Fix from $1,600 2022-01-10
Mediawiki MEDIUM 6.5
CVE-2021-46148

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged users can view confidential inf…

Fix: 1.35.5 / 1.36.3+
Fix from $1,600 2022-01-10
Security Verify Access MEDIUM 5.3
CVE-2021-38956

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further at…

Patch available
Fix from $1,600 2022-01-10
Fortimail MEDIUM 5.3
CVE-2020-15933

A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below Forti…

Fix: after 6.0.9
Fix from $1,600 2022-01-05
Bizhub C750i Firmware MEDIUM 6.5
CVE-2021-20869

Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C65…

Mitigation only
Fix from $1,600 2022-01-04
Bizhub C750i Firmware MEDIUM 6.5
CVE-2021-20871

Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C65…

Mitigation only
Fix from $1,600 2022-01-04
Harmonyos HIGH 7.5
CVE-2021-39972

MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could compr…

Fix: 2.0+
Fix from $1,950 2022-01-03
Harmonyos MEDIUM 5.3
CVE-2021-39980

Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability co…

No fix yet
Fix from $1,600 2022-01-03
Harmonyos HIGH 7.5
CVE-2021-37125

Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may caus…

Fix: 2.0+
Fix from $1,950 2022-01-03
Emuse Eservices \/ Envoice HIGH 7.5
CVE-2021-36723

Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scr…

Mitigation only
Fix from $1,950 2021-12-29
Brave HIGH 7.5
CVE-2021-45884

In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additiona…

Fix: after 1.33.106
Fix from $1,950 2021-12-27
Ex6100v2 Firmware HIGH 7.5
CVE-2021-45648

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EX6100v2 before 1.0.1.106, EX6150v2 before 1.0.1.106, EX625…

Fix: 1.0.0.146 / 1.0.1.106+
Fix from $1,950 2021-12-26
R6400v2 Firmware MEDIUM 5.5
CVE-2021-45649

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R7000 bef…

Fix: 1.0.4.84 / 1.0.11.126+
Fix from $1,600 2021-12-26
R7000 Firmware HIGH 7.5
CVE-2021-45650

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 befor…

Fix: 1.0.4.30 / 1.0.4.62+
Fix from $1,950 2021-12-26
Rbk50 Firmware HIGH 7.5
CVE-2021-45651

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK50 before 2.7.3.22, RBR50 before 2.7.3.22, and RBS50 bef…

Fix: 2.7.3.22+
Fix from $1,950 2021-12-26