Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Email MEDIUM 6.5
CVE-2021-25375

Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when …

Fix: 6.1.14.0+
Fix from $1,600 2021-04-09
Email MEDIUM 5.3
CVE-2021-25376

An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotia…

Fix: 6.1.41.0+
Fix from $1,600 2021-04-09
Android MEDIUM 5.5
CVE-2021-25357

A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), an…

Mitigation only
Fix from $1,600 2021-04-09
Satellite MEDIUM 6.3
CVE-2021-3413

A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Az…

Fix: 2.2.0+
Fix from $1,600 2021-04-08
Ninja Forms HIGH 8.8
CVE-2021-24163

The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, ther…

Fix: 3.4.34+
Fix from $1,950 2021-04-05
Web Stat HIGH 7.5
CVE-2021-24167

When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send an XMLHttpRequest request to …

Fix: 1.4.1+
Fix from $1,950 2021-04-05
User Profile Picture HIGH 7.5
CVE-2021-24170

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functio…

Fix: 2.5.0+
Fix from $1,950 2021-04-05
Wire Webapp MEDIUM 6.5
CVE-2021-21400

wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being …

Fix: after 2019-07-11-13-18
Fix from $1,600 2021-04-02
Node Etsy Client MEDIUM 6.5
CVE-2021-21421

node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer…

Fix: after 0.3.0
Fix from $1,600 2021-04-01
Fedora MEDIUM 5.3
CVE-2021-22876EPSS 5%

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in …

Fix: after 7.75.0
Fix from $1,600 2021-04-01
Jetty MEDIUM 5.3
CVE-2021-28164EPSS 82%

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to a…

Fix: after 11.70.1
Fix from $1,600 2021-04-01
Wire Server MEDIUM 6.5
CVE-2021-21396

wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16 and before version 2021-03-0…

Fix: 2021-03-02+
Fix from $1,600 2021-03-26
Android MEDIUM 5.5
CVE-2021-25369 KEV

An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

Mitigation only
Fix from $1,600 2021-03-26
389 Directory Server MEDIUM 5.3
CVE-2020-35518

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an un…

Fix: 1.4.3.19 / 1.4.4.13+
Fix from $1,600 2021-03-26
Epolicy Orchestrator MEDIUM 6.5
CVE-2021-23890

Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to do…

Fix: 5.9.1+
Fix from $1,600 2021-03-26
Omero.web MEDIUM 6.5
CVE-2021-21376

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the cu…

Fix: 5.9.0+
Fix from $1,600 2021-03-23
Apq8009 Firmware MEDIUM 5.5
CVE-2020-11199

HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, S…

Mitigation only
Fix from $1,600 2021-03-17
Apq8009 Firmware MEDIUM 5.5
CVE-2020-11221

Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the…

Mitigation only
Fix from $1,600 2021-03-17
Moodle MEDIUM 5.3
CVE-2021-20281

It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5,…

Fix: 3.5.17 / 3.8.8+
Fix from $1,600 2021-03-15
Argo Cd HIGH 7.5
CVE-2021-26923

An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is …

Fix: 1.7.12 / 1.8.4+
Fix from $1,950 2021-03-15
Swagger Codegen MEDIUM 5.5
CVE-2021-21364

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen…

Fix: 2.4.19+
Fix from $1,600 2021-03-11
Products.genericsetup MEDIUM 5.3
CVE-2021-21360

Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSet…

Fix: 2.1.1+
Fix from $1,600 2021-03-09
Products.pluggableauthservice MEDIUM 6.5
CVE-2021-21336

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t…

Fix: 2.6.0+
Fix from $1,600 2021-03-08
Tomcat HIGH 7.5
CVE-2021-25122EPSS 18%

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate re…

Fix: 21.3.0+
Fix from $1,950 2021-03-01
Diskstation Manager CRITICAL 9.0
CVE-2021-26566

Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-i…

Fix: 6.2.3-25426-3+
Fix from $2,300 2021-02-26
Amazon Pay CRITICAL 9.1
CVE-2020-28199

best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor.

Fix: 9.4.2+
Fix from $2,300 2021-02-26
Support Core MEDIUM 5.3
CVE-2021-21621

Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details onl…

Fix: after 2.72
Fix from $1,600 2021-02-24
Satellite MEDIUM 5.3
CVE-2021-20256

A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts perm…

Mitigation only
Fix from $1,600 2021-02-23
Brave MEDIUM 5.3
CVE-2021-21323

Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME adblocking feature added in B…

Fix: after 1.20.103
Fix from $1,600 2021-02-23
Directus HIGH 7.5
CVE-2021-26593

In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of infor…

Fix: after 8.8.1
Fix from $1,950 2021-02-23