Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Komoot HIGH 7.5
CVE-2021-21823

An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted s…

Fix: after 11.1.11
Fix from $1,950 2021-08-20
Ironport Web Security Appliance HIGH 8.6
CVE-2021-34749

A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), an…

Patch available
Fix from $1,950 2021-08-18
Airflow MEDIUM 5.3
CVE-2021-35936

If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server…

Fix: 2.1.2+
Fix from $1,600 2021-08-16
Xshell MEDIUM 5.3
CVE-2021-37326

NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.

Mitigation only
Fix from $1,600 2021-08-15
Routes HIGH 7.5
CVE-2021-36793

The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure beca…

Fix: 2.1.1+
Fix from $1,950 2021-08-13
Openmanage Enterprise CRITICAL 9.8
CVE-2021-21564

Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentiall…

Fix: 3.6.1+
Fix from $2,300 2021-08-09
Openmanage Enterprise MEDIUM 6.5
CVE-2021-21584

Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenti…

Patch available
Fix from $1,600 2021-08-09
Openmanage Enterprise HIGH 8.8
CVE-2021-21596

Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code …

Fix: after 3.6.1
Fix from $1,950 2021-08-09
Mobile Platform MEDIUM 5.5
CVE-2015-7731

SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security N…

Mitigation only
Fix from $1,600 2021-08-09
R08sfcpu Firmware HIGH 7.5
CVE-2021-20594

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SF…

Mitigation only
Fix from $1,950 2021-08-06
Debian Linux MEDIUM 5.5
CVE-2021-3566

Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that refer…

Fix: 4.3+
Fix from $1,600 2021-08-05
Curl MEDIUM 5.3
CVE-2021-22925

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pair…

Fix: 7.78.0+
Fix from $1,600 2021-08-05
Evolved Programmable Network Manager MEDIUM 6.5
CVE-2021-34707

A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitiv…

Fix: after 5.0
Fix from $1,600 2021-08-04
Otrs MEDIUM 6.5
CVE-2021-21440

Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edi…

Fix: after 8.0.14
Fix from $1,600 2021-07-26
Adxadmin MEDIUM 5.3
CVE-2020-7387EPSS 36%

Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installati…

Fix: 93.2.53+
Fix from $1,600 2021-07-22
Cf Deployment HIGH 7.5
CVE-2021-22001

In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an iden…

Fix: 16.18.0 / 75.3.0+
Fix from $1,950 2021-07-22
Elasticsearch MEDIUM 6.5
CVE-2021-22145EPSS 76%

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queri…

Fix: after 7.13.3
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 5.3
CVE-2021-22721

A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.5
CVE-2021-22728

A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …

Mitigation only
Fix from $1,600 2021-07-21
Easergy T300 Firmware MEDIUM 6.5
CVE-2021-22770

A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensitive information to an actor no…

Fix: after 2.7.1
Fix from $1,600 2021-07-21
Dir 3040 Firmware HIGH 7.5
CVE-2021-21817

An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network …

No fix yet
Fix from $1,950 2021-07-16
Junos MEDIUM 6.5
CVE-2021-0291

An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-level resource is not being suff…

Mitigation only
Fix from $1,600 2021-07-15
Gatsby Source Wordpress HIGH 7.5
CVE-2021-32770

Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authenti…

Fix: 4.0.8 / 5.9.2+
Fix from $1,950 2021-07-15
Security Verify Access MEDIUM 5.3
CVE-2021-20498

IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X…

Patch available
Fix from $1,600 2021-07-15
Muwire MEDIUM 5.7
CVE-2021-32750

MuWire is a file publishing and networking tool that protects the identity of its users by using I2P technology. Users of MuWire desktop client prior…

Fix: 0.8.8+
Fix from $1,600 2021-07-15
Jetty MEDIUM 5.3
CVE-2021-34429EPSS 99%

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of t…

Fix: 9.4.43 / 10.0.6+
Fix from $1,600 2021-07-15
Android HIGH 7.8
CVE-2021-0602

In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users to view and modify Wi-Fi settings for all configur…

Mitigation only
Fix from $1,950 2021-07-14
Esoms HIGH 7.5
CVE-2021-35527

Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user cre…

Fix: 6.3.1+
Fix from $1,950 2021-07-14
Icinga MEDIUM 6.5
CVE-2021-32747

Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed…

Fix: 2.7.5 / 2.8.3+
Fix from $1,600 2021-07-12
Talk MEDIUM 6.5
CVE-2021-32689

Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier…

Fix: 11.2.2+
Fix from $1,600 2021-07-12