Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Scrapy Splash HIGH 7.5
CVE-2021-41124

Scrapy-splash is a library which provides Scrapy and JavaScript integration. In affected versions users who use [`HttpAuthMiddleware`](http://doc.scr…

Fix: 0.8.0+
Fix from $1,950 2021-10-05
Survey Solutions MEDIUM 5.3
CVE-2021-41123

Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application publishes /metrics endpoint ava…

Fix: 21.09.1+
Fix from $1,600 2021-10-04
Command Line Interface HIGH 7.5
CVE-2021-41092

Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-r…

Fix: 20.10.9+
Fix from $1,950 2021-10-04
Rexroth Indramotion Xlc Firmware HIGH 7.5
CVE-2021-23855

The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore al…

Mitigation only
Fix from $1,950 2021-10-04
Rexroth Indramotion Mlc L20 Firmware HIGH 7.5
CVE-2021-23858

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can …

Fix: after 12
Fix from $1,950 2021-10-04
Parse Server HIGH 7.5
CVE-2021-41109

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.4, for regular (non-Liv…

Fix: 4.10.4+
Fix from $1,950 2021-09-30
Ecs Router Controller Ecs Firmware CRITICAL 9.8
CVE-2021-41301

ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. T…

Mitigation only
Fix from $2,300 2021-09-30
Acrobat MEDIUM 6.5
CVE-2021-39855

Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected b…

Fix: after 21.005.20060
Fix from $1,600 2021-09-29
Acrobat MEDIUM 6.5
CVE-2021-39856

Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected b…

Fix: after 21.005.20060
Fix from $1,600 2021-09-29
Mybuildings CRITICAL 9.4
CVE-2021-22272

The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer …

Fix: 2021-05-03+
Fix from $2,300 2021-09-27
System Access Point 2.0 Firmware MEDIUM 5.5
CVE-2021-22276

The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.

Fix: 2.6.4+
Fix from $1,600 2021-09-23
Chipset Driver MEDIUM 5.5
CVE-2021-26333

An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) …

Fix: 3.08.17.735 / 5.17.0.0+
Fix from $1,600 2021-09-21
Discourse HIGH 7.5
CVE-2021-41082

Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user…

Fix: 2021-09-14+
Fix from $1,950 2021-09-20
Timetable And Event Schedule MEDIUM 6.5
CVE-2021-24585

The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive da…

Fix: 2.4.0+
Fix from $1,600 2021-09-20
Santuario Xml Security For Java HIGH 7.5
CVE-2021-40690EPSS 7%

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is…

Fix: 2.1.7 / 2.2.3+
Fix from $1,950 2021-09-19
Bulletproof Security MEDIUM 5.3
CVE-2021-39327EPSS 72%

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible …

Fix: after 5.1
Fix from $1,600 2021-09-17
Terraform Enterprise HIGH 8.8
CVE-2021-40862

HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which c…

Fix: after 202108-1
Fix from $1,950 2021-09-15
Glpi MEDIUM 5.3
CVE-2021-39211

GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI an…

Fix: 9.5.6+
Fix from $1,600 2021-09-15
Security Secret Server MEDIUM 5.3
CVE-2021-20582

IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties…

Fix: 11.0+
Fix from $1,600 2021-09-14
Access Manager HIGH 7.5
CVE-2021-22527

Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

Fix: 4.5.4 / 5.0.1+
Fix from $1,950 2021-09-13
WordPress MEDIUM 5.3
CVE-2021-39200

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output…

Fix: 5.8.1+
Fix from $1,600 2021-09-09
WordPress MEDIUM 6.5
CVE-2021-39203

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authen…

Mitigation only
Fix from $1,600 2021-09-09
Capture MEDIUM 5.5
CVE-2021-25464

An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.

Fix: 4.8.02+
Fix from $1,600 2021-09-09
Ios Xr MEDIUM 5.5
CVE-2021-34771

A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow. T…

Fix: 7.3.2+
Fix from $1,600 2021-09-09
Richdocuments MEDIUM 5.3
CVE-2021-37629

Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS …

Fix: 3.8.4 / 4.2.1+
Fix from $1,600 2021-09-07
Ntracker Usb Enterprise HIGH 7.5
CVE-2020-7819

A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL …

Fix: after 5
Fix from $1,950 2021-09-07
Otrs MEDIUM 5.3
CVE-2021-36095

Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition…

Fix: 7.0.29+
Fix from $1,600 2021-09-06
Ghost HIGH 7.2
CVE-2021-39192

Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authen…

Fix: 4.10.0+
Fix from $1,950 2021-09-03
Gutenberg Template Library \& Redux Framework MEDIUM 5.3
CVE-2021-38314EPSS 29%

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in…

Fix: after 4.2.11
Fix from $1,600 2021-09-02
Accusine Pcsp Pfvp Firmware HIGH 7.2
CVE-2021-22793

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and Accu…

Fix: 001.006.007 / 002.002.004+
Fix from $1,950 2021-09-02