Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-21590

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user wi…

Fix: 5.1.0.0.5.394+
Fix from $1,600 2021-07-12
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-21591

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user wi…

Fix: 5.1.0.0.5.394+
Fix from $1,600 2021-07-12
Brave MEDIUM 5.9
CVE-2021-22916

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking featu…

Fix: after 1.26.60
Fix from $1,600 2021-07-12
Browser MEDIUM 6.5
CVE-2021-22917

Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing throug…

Fix: 1.20+
Fix from $1,600 2021-07-12
Android HIGH 7.5
CVE-2021-25426

Improper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR July-2021 Release 1 allows untrusted applications to…

No fix yet
Fix from $1,950 2021-07-08
Storage Manager MEDIUM 5.3
CVE-2021-32528

Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system information without permissions.…

Fix: after 3.3.1
Fix from $1,600 2021-07-07
Xwiki MEDIUM 5.3
CVE-2021-32731

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and…

Patch available
Fix from $1,600 2021-07-01
Sylius MEDIUM 5.3
CVE-2021-32720

Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, part of the details (order ID, o…

Fix: 1.9.5+
Fix from $1,600 2021-06-28
Shopware HIGH 7.5
CVE-2021-32717

Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the h…

Fix: 6.4.1.1+
Fix from $1,950 2021-06-24
Shopware MEDIUM 5.3
CVE-2021-32712

Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are rec…

Fix: 5.6.10+
Fix from $1,600 2021-06-24
Shopware HIGH 7.5
CVE-2021-32711

Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed…

Fix: 6.3.5.1+
Fix from $1,950 2021-06-24
Aura Utility Services MEDIUM 5.5
CVE-2021-25649

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may po…

Fix: after 7.1.3
Fix from $1,600 2021-06-24
Aura Appliance Virtualization Platform MEDIUM 5.5
CVE-2021-25652

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities…

Fix: after 8.1.3.1
Fix from $1,600 2021-06-24
Sonicos HIGH 7.5
CVE-2021-20019

A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an int…

Fix: 7.0.0.376 / 7.0.1-r1036+
Fix from $1,950 2021-06-23
Diskstation Manager HIGH 7.5
CVE-2021-29086

Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426…

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $1,950 2021-06-23
Joomla\! HIGH 7.5
CVE-2010-1432

Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in l…

Fix: after 1.5.15
Fix from $1,950 2021-06-21
Helm HIGH 8.6
CVE-2021-32690

Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists wher…

Fix: 3.6.1+
Fix from $1,950 2021-06-16
Radeon Pro Software MEDIUM 5.5
CVE-2020-12987

A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass.

Fix: 20.7.1 / 21.q1+
Fix from $1,600 2021-06-11
Command Centre MEDIUM 6.5
CVE-2021-23204

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to…

Fix: 8.30.1359 / 8.40.1888+
Fix from $1,600 2021-06-11
Nextcloud MEDIUM 6.5
CVE-2021-22905

Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by de…

Fix: 3.16.0+
Fix from $1,600 2021-06-11
Nextcloud MEDIUM 6.5
CVE-2021-22912

Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instea…

Fix: 3.4.2+
Fix from $1,600 2021-06-11
Deck MEDIUM 6.5
CVE-2021-22913

Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by defaul…

Fix: 1.2.7 / 1.4.1+
Fix from $1,600 2021-06-11
Modicon X80 Bmxnor0200h Rtu Firmware MEDIUM 5.3
CVE-2021-22749

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that …

Mitigation only
Fix from $1,600 2021-06-11
Android MEDIUM 5.5
CVE-2021-25392

Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information v…

No fix yet
Fix from $1,600 2021-06-11
Qss MEDIUM 5.5
CVE-2021-28805

Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability…

Fix: 1.0.3 / 1.0.12+
Fix from $1,600 2021-06-11
Debian Linux MEDIUM 5.3
CVE-2021-28169EPSS 78%

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access pro…

Fix: 9.4.41 / 10.0.3+
Fix from $1,600 2021-06-09
Foremanfogproxmox HIGH 7.8
CVE-2021-20259

A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with vi…

Fix: 0.13.1+
Fix from $1,950 2021-06-07
Luca HIGH 7.5
CVE-2021-33839

Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Locatio…

Fix: after 1.7.4
Fix from $1,950 2021-06-04
Satellite MEDIUM 6.5
CVE-2020-14371

A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on t…

Mitigation only
Fix from $1,600 2021-06-02
Satellite MEDIUM 5.5
CVE-2020-14335

A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows…

Mitigation only
Fix from $1,600 2021-06-02