Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Rbk352 Firmware HIGH 7.5
CVE-2021-45652

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 …

Fix: 4.4.0.10+
Fix from $1,950 2021-12-26
Rbk352 Firmware HIGH 7.5
CVE-2021-45653

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 …

Fix: 4.4.0.10+
Fix from $1,950 2021-12-26
Xr1000 Firmware HIGH 7.5
CVE-2021-45654

NETGEAR XR1000 devices before 1.0.0.58 are affected by disclosure of sensitive information.

Fix: 1.0.0.58+
Fix from $1,950 2021-12-26
R7000 Firmware HIGH 7.5
CVE-2021-45646

NETGEAR R7000 devices before 1.0.11.116 are affected by disclosure of sensitive information.

Fix: 1.0.11.116+
Fix from $1,950 2021-12-26
Eax80 Firmware HIGH 7.5
CVE-2021-45647

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EAX80 before 1.0.1.62, EX7000 before 1.0.1.104, R6120 befor…

Fix: 1.0.0.76 / 1.0.1.62+
Fix from $1,950 2021-12-26
D7800 Firmware MEDIUM 5.5
CVE-2021-45603

Certain NETGEAR devices are affected by disclosure of sensitive information. A UPnP request reveals a device's serial number, which can be used for a…

Fix: 1.0.0.90 / 1.0.1.66+
Fix from $1,600 2021-12-26
Rax35 Firmware HIGH 7.5
CVE-2021-45493

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RA…

Fix: 1.0.4.102+
Fix from $1,950 2021-12-26
Fedora MEDIUM 6.5
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gv…

Fix: 3.4.3+
Fix from $1,600 2021-12-23
Cloud Pak For Security MEDIUM 6.5
CVE-2021-39013

IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses t…

Mitigation only
Fix from $1,600 2021-12-22
Wyse Device Agent MEDIUM 5.5
CVE-2021-36341

Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low privileges cou…

Fix: after 14.5.4.1
Fix from $1,600 2021-12-21
Nifi MEDIUM 6.5
CVE-2021-44145

In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious externa…

Fix: 1.15.1+
Fix from $1,600 2021-12-17
Mediawiki MEDIUM 5.3
CVE-2021-45038

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can …

Fix: 1.35.5 / 1.36.3+
Fix from $1,600 2021-12-17
Linux Kernel MEDIUM 5.5
CVE-2021-45095

pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.

Fix: after 5.15.8
Fix from $1,600 2021-12-16
Android MEDIUM 5.0
CVE-2021-1023

In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, d…

Mitigation only
Fix from $1,600 2021-12-15
Sourcegraph MEDIUM 6.5
CVE-2021-43823

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in priva…

Fix: 3.33.2+
Fix from $1,600 2021-12-13
Spectrum Protect Operations Center MEDIUM 5.5
CVE-2021-38901

IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Forc…

Fix: 7.1.14+
Fix from $1,600 2021-12-13
GitLab MEDIUM 5.3
CVE-2021-39941

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to se…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
Like Button Rating HIGH 8.0
CVE-2021-24945

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX acti…

Fix: 2.6.38+
Fix from $1,950 2021-12-13
Huntflow Enterprise HIGH 7.5
CVE-2021-37935

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get inf…

Fix: after 3.10.4
Fix from $1,950 2021-12-10
Firefox MEDIUM 6.5
CVE-2021-43536

Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thun…

Fix: 91.4.0 / 95.0+
Fix from $1,600 2021-12-08
Agent HIGH 7.5
CVE-2021-41090

Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.…

Fix: 0.20.1 / 0.21.2+
Fix from $1,950 2021-12-08
Fortiauthenticator MEDIUM 6.5
CVE-2021-43067

A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and…

Fix: after 6.0.7
Fix from $1,600 2021-12-08
Sync Gateway HIGH 8.1
CVE-2021-43963

An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were in…

Fix: 2.8.3+
Fix from $1,950 2021-12-07
Harmonyos HIGH 7.5
CVE-2021-37067

There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerabilit…

Fix: 2.0+
Fix from $1,950 2021-12-07
Arcgis Enterprise MEDIUM 5.3
CVE-2021-29115

An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attac…

Fix: after 10.9
Fix from $1,600 2021-12-07
Kantech Entrapass HIGH 7.5
CVE-2021-36198

Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.

Fix: 8.40+
Fix from $1,950 2021-12-06
Mahavitaran MEDIUM 5.9
CVE-2020-27414

Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthori…

Fix: after 7.50
Fix from $1,600 2021-12-02
Mq Appliance MEDIUM 5.5
CVE-2021-38999

IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.

Patch available
Fix from $1,600 2021-11-30
Mq Appliance MEDIUM 5.5
CVE-2021-39000

IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. I…

Patch available
Fix from $1,600 2021-11-30
Harmonyos HIGH 7.5
CVE-2021-37010

There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerabilit…

No fix yet
Fix from $1,950 2021-11-23