Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
macOS MEDIUM 5.5
CVE-2024-44182

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura …

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17
Ipados MEDIUM 5.5
CVE-2024-44184

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia …

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17
macOS MEDIUM 5.5
CVE-2024-44186

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected u…

Fix: 15.0+
Fix from $1,600 2024-09-17
macOS MEDIUM 5.5
CVE-2024-44129

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Ventura 13.7. An app may be able to leak sensitive user …

Fix: 13.7+
Fix from $1,600 2024-09-17
macOS HIGH 7.5
CVE-2024-44152

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be able to ac…

Fix: 15.0+
Fix from $1,950 2024-09-17
Ipados MEDIUM 5.5
CVE-2024-44158

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Sequoia 15, macOS S…

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17
macOS MEDIUM 5.5
CVE-2024-40842

An issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15. An app may be able to access user-…

Fix: 15.0+
Fix from $1,600 2024-09-17
Ipados MEDIUM 5.5
CVE-2024-40850

A file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoi…

Fix: 2.0 / 11.0+
Fix from $1,600 2024-09-17
Xcode MEDIUM 5.3
CVE-2024-40862

A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the o…

Fix: 16.0+
Fix from $1,600 2024-09-17
Ipados MEDIUM 5.5
CVE-2024-40863

This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to leak sensitive user inform…

Fix: 18.0+
Fix from $1,600 2024-09-17
Fluxcp MEDIUM 6.1
CVE-2024-45799

FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/buyers list pages and shop nam…

Fix: 1.3.0+
Fix from $1,600 2024-09-16
Omflow MEDIUM 6.5
CVE-2024-8780

OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privi…

Fix: after 1.2.1.3
Fix from $1,600 2024-09-16
Omflow HIGH 7.5
CVE-2024-8777

OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations…

Fix: 1.2.1.3+
Fix from $1,950 2024-09-16
Experience Commerce HIGH 7.5
CVE-2024-46938EPSS 46%

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 …

Fix: after 10.4
Fix from $1,950 2024-09-15
Vaultwarden MEDIUM 6.5
CVE-2024-39925

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a re…

Mitigation only
Fix from $1,600 2024-09-13
Unclassified MEDIUM 5.0
CVE-2024-44685

Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exp…

Mitigation only
Fix from $1,600 2024-09-13
Custom Post Limits MEDIUM 5.3
CVE-2024-6544

The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plu…

Fix: after 4.4.1
Fix from $1,600 2024-09-13
Fusion Digital Power Designer MEDIUM 5.5
CVE-2024-41629

An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storag…

Mitigation only
Fix from $1,600 2024-09-12
Unclassified HIGH 7.5
CVE-2024-45624

Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unaut…

Mitigation only
Fix from $1,950 2024-09-12
Unclassified MEDIUM 6.7
CVE-2024-8097

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credenti…

Mitigation only
Fix from $1,600 2024-09-11
Soplanning CRITICAL 9.8
CVE-2024-27113

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view se…

Fix: 1.52.02+
Fix from $2,300 2024-09-11
Spectrum HIGH 7.5
CVE-2023-37232

Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.

Fix: after 4.6
Fix from $1,950 2024-09-10
Fortisandbox MEDIUM 6.5
CVE-2024-31490

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through …

Fix: 4.2.7 / 4.4.5+
Fix from $1,600 2024-09-10
Simatic Rf360r Firmware MEDIUM 6.5
CVE-2024-37991

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6B…

Fix: 1.1 / 2.2+
Fix from $1,600 2024-09-10
One HIGH 8.0
CVE-2024-42019

A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction …

Fix: 12.2.0.4093+
Fix from $1,950 2024-09-07
Unclassified CRITICAL 9.9
CVE-2024-38650

An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.

Mitigation only
Fix from $2,300 2024-09-07
Dir 823g Firmware HIGH 7.5
CVE-2024-44408

D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the down…

No fix yet
Fix from $1,950 2024-09-06
Gnark Crypto MEDIUM 6.2
CVE-2024-45039

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multip…

Fix: 0.11.0+
Fix from $1,600 2024-09-06
Gnark Crypto MEDIUM 5.9
CVE-2024-45040

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth1…

Fix: 0.11.0+
Fix from $1,600 2024-09-06
Remember Me Controls MEDIUM 5.3
CVE-2024-7415

The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the p…

Fix: 2.1+
Fix from $1,600 2024-09-06