Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Profilepress MEDIUM 5.3
CVE-2024-11083

The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress…

Fix: 4.15.19+
Fix from $1,600 2024-11-27
Sd 450 Firmware MEDIUM 5.5
CVE-2017-18306

Information disclosure due to uninitialized variable.

No fix yet
Fix from $1,600 2024-11-26
Sd 450 Firmware MEDIUM 5.5
CVE-2017-18307

Information disclosure possible while audio playback.

No fix yet
Fix from $1,600 2024-11-26
Home Flex Firmware MEDIUM 5.7
CVE-2024-7391

ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sen…

Mitigation only
Fix from $1,600 2024-11-22
Ai Core HIGH 7.5
CVE-2024-38647

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attac…

Mitigation only
Fix from $1,950 2024-11-22
PHP MEDIUM 5.8
CVE-2024-8929

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of…

Fix: 8.1.31 / 8.2.26+
Fix from $1,600 2024-11-22
Simple Membership HIGH 7.5
CVE-2024-11088

The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPr…

Fix: 4.5.6+
Fix from $1,950 2024-11-21
Anonymous Restricted Content MEDIUM 5.3
CVE-2024-11089

The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via…

Fix: 1.6.6+
Fix from $1,600 2024-11-21
Unclassified HIGH 7.5
CVE-2024-51163

A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive informati…

Mitigation only
Fix from $1,950 2024-11-20
Graylog MEDIUM 6.5
CVE-2024-52506

Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and scheduling of reports which contai…

Fix: 6.1.2+
Fix from $1,600 2024-11-18
Glpi MEDIUM 5.3
CVE-2024-43416

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an ap…

Fix: 10.0.17+
Fix from $1,600 2024-11-18
Hertzbeat HIGH 7.5
CVE-2024-45791

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Us…

Fix: 1.6.1+
Fix from $1,950 2024-11-18
Mail HIGH 8.1
CVE-2024-52508

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an email addre…

Fix: 1.14.6 / 1.15.4+
Fix from $1,950 2024-11-15
Nextcloud Server MEDIUM 6.5
CVE-2024-52523

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, th…

Fix: 25.0.13.14 / 26.0.13.10+
Fix from $1,600 2024-11-15
Nextcloud Server MEDIUM 5.9
CVE-2024-52517

Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into th…

Fix: 25.0.13.13 / 26.0.13.9+
Fix from $1,600 2024-11-15
Unclassified MEDIUM 5.3
CVE-2022-20648

A vulnerability in a debug function for Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform debu…

Mitigation only
Fix from $1,600 2024-11-15
Essential Addons For Elementor MEDIUM 5.7
CVE-2024-8979

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sens…

Fix: 6.0.10+
Fix from $1,600 2024-11-15
Essential Addons For Elementor MEDIUM 5.7
CVE-2024-8978

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sens…

Fix: 6.0.10+
Fix from $1,600 2024-11-15
Unclassified HIGH 7.5
CVE-2024-47915

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,950 2024-11-14
Tolgee HIGH 7.5
CVE-2024-52297

Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed…

Patch available
Fix from $1,950 2024-11-12
Sinec Ins MEDIUM 5.4
CVE-2024-46894

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorizatio…

Fix: after 1.0
Fix from $1,600 2024-11-12
Unclassified MEDIUM 5.3
CVE-2024-8756

The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0…

Mitigation only
Fix from $1,600 2024-11-09
Ce21 Suite HIGH 7.5
CVE-2024-10285

The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions up to, and including, 2.2.0.…

Fix: after 2.2.0
Fix from $1,950 2024-11-09
Data Domain Operating System MEDIUM 6.5
CVE-2024-48011

Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privile…

Fix: 7.7.5.50+
Fix from $1,600 2024-11-08
Neuron MEDIUM 6.5
CVE-2024-10965

A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the fi…

Fix: after 2.10.0
Fix from $1,600 2024-11-07
Meeting Management MEDIUM 6.5
CVE-2024-20507

A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in c…

Fix: 3.10.0+
Fix from $1,600 2024-11-06
Unified Communications Manager Im And Presence Service MEDIUM 6.5
CVE-2024-20457

A vulnerability in the logging component of Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an authe…

Mitigation only
Fix from $1,600 2024-11-06
Desk Phone 9841 Firmware MEDIUM 5.3
CVE-2024-20445

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthe…

Fix: 14.3+
Fix from $1,600 2024-11-06
Unclassified HIGH 7.5
CVE-2024-6861

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for atta…

Mitigation only
Fix from $1,950 2024-11-06
Dns 320 Firmware MEDIUM 5.3
CVE-2024-10916

A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown p…

No fix yet
Fix from $1,600 2024-11-06