Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Junos MEDIUM 5.5
CVE-2024-39527

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX S…

Fix: 21.4+
Fix from $1,600 2024-10-11
Shoplentor MEDIUM 6.5
CVE-2024-9538

The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' func…

Fix: 2.9.9+
Fix from $1,600 2024-10-11
Gradio HIGH 7.5
CVE-2024-47868

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio componen…

Fix: 5.0.0+
Fix from $1,950 2024-10-10
Checkmk HIGH 7.5
CVE-2024-6747

Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive da…

Fix: 2.1.0+
Fix from $1,950 2024-10-10
Connections MEDIUM 5.7
CVE-2024-30118

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitl…

Mitigation only
Fix from $1,600 2024-10-09
Unclassified HIGH 8.1
CVE-2024-3656

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This…

No fix yet
Fix from $1,950 2024-10-09
Copilot Studio HIGH 7.5
CVE-2024-43610

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …

Mitigation only
Fix from $1,950 2024-10-09
365 Apps MEDIUM 6.5
CVE-2024-43609

Microsoft Office Spoofing Vulnerability

Patch available
Fix from $1,600 2024-10-08
Unclassified CRITICAL 9.8
CVE-2024-8884

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has a…

Mitigation only
Fix from $2,300 2024-10-08
Unclassified MEDIUM 5.3
CVE-2024-47344

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Stylemix uListing ulisting.This issue affects uListing: from n/a through …

Mitigation only
Fix from $1,600 2024-10-07
Unclassified HIGH 7.8
CVE-2024-45245

Diebold Nixdorf – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,950 2024-10-06
Unclassified MEDIUM 6.9
CVE-2024-47848

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Byp…

Mitigation only
Fix from $1,600 2024-10-05
Nexus Dashboard Fabric Controller HIGH 8.6
CVE-2024-20490

A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an a…

Fix: 4.2 / 4.4.1.1012+
Fix from $1,950 2024-10-02
Nexus Dashboard Fabric Controller HIGH 8.6
CVE-2024-20491

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive …

Fix: 4.2 / 4.4.1.1012+
Fix from $1,950 2024-10-02
Unclassified MEDIUM 6.3
CVE-2024-46548

TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and a…

Mitigation only
Fix from $1,600 2024-09-30
Restrictedpython MEDIUM 6.5
CVE-2024-47532

RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensibl…

Fix: 7.3+
Fix from $1,600 2024-09-30
Mantisbt MEDIUM 6.5
CVE-2024-45792

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve inf…

Fix: 2.26.4+
Fix from $1,600 2024-09-30
Membership Management System HIGH 7.5
CVE-2024-46471

The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentiall…

No fix yet
Fix from $1,950 2024-09-27
Maven Archetype HIGH 7.5
CVE-2024-47197

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This …

Mitigation only
Fix from $1,950 2024-09-26
Unclassified MEDIUM 5.3
CVE-2024-43237

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag Groups tag-groups.This issue…

Mitigation only
Fix from $1,600 2024-09-25
Mas Static Content MEDIUM 6.5
CVE-2024-8483

The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content(…

Fix: 1.0.9+
Fix from $1,600 2024-09-25
Peepso MEDIUM 5.3
CVE-2024-7426

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all v…

Fix: 6.4.6.0+
Fix from $1,600 2024-09-25
W3 Total Cache HIGH 7.5
CVE-2023-5359

The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API …

Fix: 2.7.6+
Fix from $1,950 2024-09-25
Galaxy CRITICAL 9.1
CVE-2024-42351

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and …

Fix: 21.05+
Fix from $2,300 2024-09-20
Zitadel MEDIUM 6.5
CVE-2024-47060

Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively thei…

Fix: 2.54.10 / 2.55.8+
Fix from $1,600 2024-09-20
Xwiki MEDIUM 5.3
CVE-2024-46979

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification …

Fix: 14.10.21 / 15.5.5+
Fix from $1,600 2024-09-18
Camaleon Cms HIGH 7.7
CVE-2024-46987EPSS 15%

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaControlle…

Fix: 2.8.2+
Fix from $1,950 2024-09-18
Unclassified MEDIUM 6.5
CVE-2024-8969

OMFLOW from The SYSCOM Group has a vulnerability involving the exposure of sensitive data. This allows remote attackers who have logged into the syst…

Mitigation only
Fix from $1,600 2024-09-18
macOS MEDIUM 5.5
CVE-2024-44163

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. A malicious application…

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17
macOS MEDIUM 5.5
CVE-2024-44181

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An …

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17