Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Security Verify Access MEDIUM 5.3
CVE-2021-20585

IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system…

Mitigation only
Fix from $1,600 2021-06-01
Rocket.chat HIGH 7.5
CVE-2021-22892

An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed …

Fix: 3.11.3 / 3.12.2+
Fix from $1,950 2021-05-27
Spacelynk Firmware MEDIUM 5.9
CVE-2021-22739

Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when…

Fix: after 2.6.0
Fix from $1,600 2021-05-26
Spacelynk Firmware MEDIUM 6.5
CVE-2021-22740

Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when …

Fix: after 2.6.0
Fix from $1,600 2021-05-26
Wicket HIGH 7.5
CVE-2021-23937

A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups fro…

Fix: after 9.2.0
Fix from $1,950 2021-05-25
Keystone 5 MEDIUM 5.3
CVE-2021-32624

Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly discovered capability in our query…

Fix: after 19.3.2
Fix from $1,600 2021-05-24
.net Based Opc Ua Client\/server Sdk HIGH 7.5
CVE-2021-27434

Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions onl…

Fix: after 3.0.7
Fix from $1,950 2021-05-20
Python MEDIUM 5.7
CVE-2021-3426

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc…

Fix: 2.7.18 / 3.6.13+
Fix from $1,600 2021-05-20
Express Handlebars MEDIUM 6.8
CVE-2021-32817

express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express rend…

Fix: after 5.3.2
Fix from $1,600 2021-05-14
Squirrelly HIGH 8.8
CVE-2021-32819EPSS 60%

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine c…

Patch available
Fix from $1,950 2021-05-14
Express Handlebars HIGH 8.6
CVE-2021-32820EPSS 18%

Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the…

Fix: after 5.3.2
Fix from $1,950 2021-05-14
Elasticsearch MEDIUM 5.3
CVE-2021-22137

In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries…

Fix: 6.8.15 / 7.11.2+
Fix from $1,600 2021-05-13
Elasticsearch MEDIUM 5.3
CVE-2021-22135

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Docu…

Fix: 6.8.15 / 7.11.2+
Fix from $1,600 2021-05-13
Symfony MEDIUM 5.3
CVE-2021-21424

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without…

Fix: 3.4.48 / 4.4.23+
Fix from $1,600 2021-05-13
0852 0303 Firmware MEDIUM 5.3
CVE-2021-20993

In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources locat…

Fix: after 1.2.3.s0
Fix from $1,600 2021-05-13
Debian Linux HIGH 7.5
CVE-2021-20313

A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. T…

Fix: 7.0.11-0+
Fix from $1,950 2021-05-11
Sharepoint Foundation MEDIUM 5.3
CVE-2021-31173

Microsoft SharePoint Server Information Disclosure Vulnerability

Patch available
Fix from $1,600 2021-05-11
Openstack HIGH 7.5
CVE-2021-31918

A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a…

Mitigation only
Fix from $1,950 2021-05-06
Hybrid Client MEDIUM 5.5
CVE-2021-21536

Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerabili…

Fix: 1.5+
Fix from $1,600 2021-04-30
Hybrid Client MEDIUM 5.5
CVE-2021-21537

Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerabili…

Fix: 1.5+
Fix from $1,600 2021-04-30
Ansible Engine HIGH 7.5
CVE-2021-20228

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using th…

Patch available
Fix from $1,950 2021-04-29
Managewiki HIGH 7.5
CVE-2021-29483

ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' API leaked the value of private configuration variables set through the ManageW…

Fix: 2021-04-28+
Fix from $1,950 2021-04-28
P2r8852e2 Firmware CRITICAL 9.8
CVE-2021-30168

The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and furth…

Fix: 7.1.94.8908+
Fix from $2,300 2021-04-28
P2r8852e2 Firmware HIGH 7.5
CVE-2021-30169

The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.

Fix: 7.1.94.8908+
Fix from $1,950 2021-04-28
Tapestry HIGH 7.5
CVE-2021-30638EPSS 7%

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia…

Fix: 5.6.4 / 5.7.2+
Fix from $1,950 2021-04-27
Flow MEDIUM 6.5
CVE-2020-36319

Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensi…

Fix: 3.0.6 / 15.0.5+
Fix from $1,600 2021-04-23
Mediawiki MEDIUM 5.3
CVE-2021-31545

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked the existence of certain delet…

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Tapestry CRITICAL 9.8
CVE-2021-27850EPSS 94%

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…

Fix: 5.6.2 / 5.7.1+
Fix from $2,300 2021-04-15
Accessally HIGH 7.5
CVE-2021-24226EPSS 5%

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_for…

Fix: 3.5.7+
Fix from $1,950 2021-04-12
Patreon Wordpress HIGH 7.5
CVE-2021-24227EPSS 6%

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone vi…

Fix: 1.7.0+
Fix from $1,950 2021-04-12