Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Itop MEDIUM 5.3
CVE-2024-51739

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to brute…

Fix: 2.7.11 / 3.0.5+
Fix from $1,600 2024-11-05
Unclassified MEDIUM 5.7
CVE-2023-29114

System logs could be accessed through web management application due to a lack of access control. An attacker can obtain the following sensitive in…

Mitigation only
Fix from $1,600 2024-11-05
Itop MEDIUM 5.8
CVE-2024-32870

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by an…

Fix: 2.7.11 / 3.0.5+
Fix from $1,600 2024-11-05
Unclassified MEDIUM 6.3
CVE-2024-8553

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions …

Mitigation only
Fix from $1,600 2024-10-31
Wbr 6012 Firmware MEDIUM 5.3
CVE-2024-33603EPSS 9%

The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbo…

No fix yet
Fix from $1,600 2024-10-30
Wbr 6012 Firmware MEDIUM 5.3
CVE-2024-33626

The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, suc…

Mitigation only
Fix from $1,600 2024-10-30
Zimaos HIGH 7.5
CVE-2024-49357EPSS 24%

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpo…

Fix: 1.2.5+
Fix from $1,950 2024-10-24
Zzcms HIGH 7.5
CVE-2024-10290

A vulnerability, which was classified as problematic, was found in ZZCMS 2023. This affects an unknown part of the file 3/qq-connect2.0/API/com/inc.p…

Mitigation only
Fix from $1,950 2024-10-23
Openshift Container Platform MEDIUM 5.3
CVE-2024-50312

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retri…

Patch available
Fix from $1,600 2024-10-22
Teplobot HIGH 7.3
CVE-2024-9627

The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the …

Fix: after 1.3
Fix from $1,950 2024-10-22
All In One Wp Migration MEDIUM 5.3
CVE-2024-8852

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8…

Fix: 7.87+
Fix from $1,600 2024-10-22
Onedev HIGH 7.5
CVE-2024-45309EPSS 25%

OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary f…

Fix: 11.0.9+
Fix from $1,950 2024-10-21
Oneview MEDIUM 5.5
CVE-2024-42508

This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.

Fix: 9.20.00+
Fix from $1,600 2024-10-18
Unclassified MEDIUM 5.3
CVE-2024-49284

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BogdanFix WP SendFox wp-sendfox allows Retrieve Embedded Sensitive Data.T…

Mitigation only
Fix from $1,600 2024-10-17
Unclassified MEDIUM 6.5
CVE-2024-22032

A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When re…

Mitigation only
Fix from $1,600 2024-10-16
Formidable Form Builder MEDIUM 5.3
CVE-2017-20194

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms…

Fix: after 2.05.03
Fix from $1,600 2024-10-16
Migration\, Backup\, Staging MEDIUM 6.5
CVE-2020-36835

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to…

Fix: 0.9.36+
Fix from $1,600 2024-10-16
Fusion Middleware MEDIUM 6.5
CVE-2024-21205

Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affe…

Mitigation only
Fix from $1,600 2024-10-15
Unclassified HIGH 8.7
CVE-2024-47824

matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and befo…

Patch available
Fix from $1,950 2024-10-15
Unclassified HIGH 7.0
CVE-2024-47779

Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, unde…

Patch available
Fix from $1,950 2024-10-15
Unclassified HIGH 8.7
CVE-2024-47080

matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `Ma…

Patch available
Fix from $1,950 2024-10-15
Unclassified HIGH 7.0
CVE-2024-47771

Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under s…

Patch available
Fix from $1,950 2024-10-15
Wpide MEDIUM 5.3
CVE-2024-9546

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This i…

Fix: 3.5.0+
Fix from $1,600 2024-10-15
Unclassified HIGH 7.5
CVE-2024-48824

An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to obtain sensitive inform…

Mitigation only
Fix from $1,950 2024-10-14
Unclassified HIGH 7.5
CVE-2024-48789

An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.

Mitigation only
Fix from $1,950 2024-10-14
Unclassified HIGH 7.5
CVE-2024-48796

An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.

Mitigation only
Fix from $1,950 2024-10-14
Unclassified HIGH 7.5
CVE-2024-48797

An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware up…

Mitigation only
Fix from $1,950 2024-10-14
Unclassified HIGH 7.5
CVE-2024-48798

An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update…

Mitigation only
Fix from $1,950 2024-10-14
Unclassified HIGH 7.5
CVE-2024-48799

An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update proc…

Mitigation only
Fix from $1,950 2024-10-14
Unclassified HIGH 8.8
CVE-2024-9821

The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the…

Mitigation only
Fix from $1,950 2024-10-12