Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Membership \& Content Restriction Paid Member Subscriptions MEDIUM 5.3
CVE-2024-11291

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive …

Fix: 2.13.5+
Fix from $1,600 2024-12-18
Unclassified MEDIUM 5.3
CVE-2024-11295

The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 …

Mitigation only
Fix from $1,600 2024-12-18
Unclassified MEDIUM 5.3
CVE-2024-12250

The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includin…

Mitigation only
Fix from $1,600 2024-12-18
Unclassified MEDIUM 5.3
CVE-2024-11280

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 vi…

Mitigation only
Fix from $1,600 2024-12-17
Unclassified HIGH 8.8
CVE-2024-8326

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable …

Mitigation only
Fix from $1,950 2024-12-17
Unclassified MEDIUM 5.3
CVE-2024-11294

The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress cor…

Mitigation only
Fix from $1,600 2024-12-17
Unclassified MEDIUM 5.5
CVE-2021-26281

Some parameters of the alarm clock module are improperly stored, leaking some sensitive information.

No fix yet
Fix from $1,600 2024-12-17
Unclassified MEDIUM 5.9
CVE-2021-26279

Some parameters of the weather module are improperly stored, leaking some sensitive information.

No fix yet
Fix from $1,600 2024-12-17
Geoserver MEDIUM 5.3
CVE-2024-35230

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and…

Fix: 2.25.1+
Fix from $1,600 2024-12-16
Unclassified MEDIUM 5.3
CVE-2024-12578

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via …

Mitigation only
Fix from $1,600 2024-12-14
Unclassified HIGH 8.7
CVE-2024-55946

Playloom Engine is an open-source, high-performance game development engine. Engine Beta v0.0.1 has a security vulnerability related to data storage,…

Mitigation only
Fix from $1,950 2024-12-13
Unclassified MEDIUM 5.3
CVE-2024-9945

An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resou…

Mitigation only
Fix from $1,600 2024-12-13
Unclassified CRITICAL 9.8
CVE-2024-55875

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vuln…

Patch available
Fix from $2,300 2024-12-12
Harmonyos HIGH 7.5
CVE-2024-54119

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confident…

No fix yet
Fix from $1,950 2024-12-12
Harmonyos HIGH 7.5
CVE-2024-54117

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confident…

No fix yet
Fix from $1,950 2024-12-12
Unclassified MEDIUM 6.9
CVE-2024-12564

Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installi…

Mitigation only
Fix from $1,600 2024-12-12
Accept Stripe Payments Using Contact Form 7 MEDIUM 5.3
CVE-2024-12255

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 …

Fix: 2.6+
Fix from $1,600 2024-12-12
Unclassified MEDIUM 5.3
CVE-2024-11351

The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Expos…

Mitigation only
Fix from $1,600 2024-12-11
Unclassified MEDIUM 5.3
CVE-2024-11008

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in…

Mitigation only
Fix from $1,600 2024-12-11
Splunk MEDIUM 5.7
CVE-2024-53244

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a …

Fix: 9.1.7 / 9.1.2312.206+
Fix from $1,600 2024-12-10
Unclassified MEDIUM 5.3
CVE-2024-11106

The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPres…

Mitigation only
Fix from $1,600 2024-12-10
Directus HIGH 7.5
CVE-2024-54151

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting…

Fix: 11.3.0+
Fix from $1,950 2024-12-09
Liboqs HIGH 7.5
CVE-2024-54137

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been iden…

Fix: 0.12.0+
Fix from $1,950 2024-12-06
Unclassified MEDIUM 5.3
CVE-2024-11292

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the …

Mitigation only
Fix from $1,600 2024-12-06
Unclassified HIGH 8.3
CVE-2024-54134

A publish-access account was compromised for `@solana/web3.js`, a JavaScript library that is commonly used by Solana dapps. This allowed an attacker …

Mitigation only
Fix from $1,950 2024-12-04
Argo Workflows HIGH 7.5
CVE-2024-53862

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When using `--auth-mode=client`, Arc…

Fix: 3.5.13 / 3.6.2+
Fix from $1,950 2024-12-02
Jeewms HIGH 7.5
CVE-2024-11961

A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function pre…

No fix yet
Fix from $1,950 2024-11-28
Unclassified MEDIUM 6.5
CVE-2024-53858

The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that could leak authentication toke…

Mitigation only
Fix from $1,600 2024-11-27
Go Gh HIGH 7.5
CVE-2024-53859

go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerability has been identified in …

Fix: 2.11.1+
Fix from $1,950 2024-11-27
Manageengine Analytics Plus HIGH 8.1
CVE-2024-52323

Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve s…

Fix: 6.1+
Fix from $1,950 2024-11-27