Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Dns 320 Firmware MEDIUM 5.3
CVE-2024-8461

A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discover…

No fix yet
Fix from $1,600 2024-09-05
Dns 320 Firmware MEDIUM 5.9
CVE-2024-8460

A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue is some unknown functionality …

No fix yet
Fix from $1,600 2024-09-05
Ivory Search MEDIUM 5.3
CVE-2024-6835

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via…

Fix: 5.5.7+
Fix from $1,600 2024-09-05
Duo Authentication For Epic MEDIUM 5.5
CVE-2024-20503

A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affect…

Mitigation only
Fix from $1,600 2024-09-04
Zzcms MEDIUM 6.1
CVE-2024-44820

A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When ac…

Fix: after 2023
Fix from $1,600 2024-09-04
Wp Extended MEDIUM 6.5
CVE-2024-8106

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl…

Fix: 3.0.9+
Fix from $1,600 2024-09-04
Emui MEDIUM 5.5
CVE-2024-45447

Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2024-09-04
Emui HIGH 7.5
CVE-2024-45450

Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidential…

No fix yet
Fix from $1,950 2024-09-04
Tinacms\/cli HIGH 7.5
CVE-2024-45391

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a…

Fix: 1.6.2+
Fix from $1,950 2024-09-03
Hoverfly HIGH 7.5
CVE-2024-45388EPSS 56%

Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler…

Fix: 1.10.3+
Fix from $1,950 2024-09-02
Jellyfin MEDIUM 5.4
CVE-2024-43801

Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack again…

Fix: after 10.9.10
Fix from $1,600 2024-09-02
Popup Builder HIGH 7.5
CVE-2024-2541

The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscriber…

Fix: after 4.3.3
Fix from $1,950 2024-08-29
Wp Seo Plugin HIGH 7.5
CVE-2024-3679

The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.0…

Fix: after 1.6.001
Fix from $1,950 2024-08-29
Givewp MEDIUM 5.3
CVE-2024-6551

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including…

Fix: 3.16.0+
Fix from $1,600 2024-08-29
Unclassified MEDIUM 5.3
CVE-2024-45043

The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream messages and parsing the records …

Patch available
Fix from $1,600 2024-08-28
Hwameistor MEDIUM 6.7
CVE-2024-45054

Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resources. If a malicious user can ac…

Fix: 0.14.6+
Fix from $1,600 2024-08-28
Netiq Advanced Authentication MEDIUM 5.5
CVE-2021-22529

A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication v…

Fix: 6.3+
Fix from $1,600 2024-08-28
Mollie Payments For Woocommerce MEDIUM 5.3
CVE-2024-6448

The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 7.7.0. This is d…

Fix: 7.8.0+
Fix from $1,600 2024-08-28
Filecatalyst Workflow CRITICAL 9.8
CVE-2024-6633

The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of the…

Fix: 5.1.7+
Fix from $2,300 2024-08-27
Bit Form MEDIUM 6.5
CVE-2024-43251

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit Form Pro: from n/a through 2…

Fix: after 2.6.4
Fix from $1,600 2024-08-26
Leopard MEDIUM 6.5
CVE-2024-43257

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - …

Fix: after 2.0.36
Fix from $1,600 2024-08-26
Store Locator Plus HIGH 7.5
CVE-2024-43258

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a throug…

Fix: after 2311.17.01
Fix from $1,950 2024-08-26
Wpforo Forum HIGH 7.5
CVE-2024-43289

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a thro…

Fix: 2.3.5+
Fix from $1,950 2024-08-26
Purevpn MEDIUM 5.3
CVE-2023-48957

PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP o…

No fix yet
Fix from $1,600 2024-08-25
Identity MEDIUM 6.5
CVE-2024-42337

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,600 2024-08-25
Maxbuttons MEDIUM 5.3
CVE-2024-6499

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This m…

Fix: 9.8.0+
Fix from $1,600 2024-08-24
Mage Ai MEDIUM 5.3
CVE-2024-8072

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

No fix yet
Fix from $1,600 2024-08-22
Unclassified HIGH 8.1
CVE-2024-39344

An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via …

Mitigation only
Fix from $1,950 2024-08-21
Unclassified MEDIUM 5.1
CVE-2022-26327

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive…

Mitigation only
Fix from $1,600 2024-08-21
Unclassified MEDIUM 5.3
CVE-2024-6568

The Flamix: Bitrix24 and Contact Form 7 integrations plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including,…

Mitigation only
Fix from $1,600 2024-08-21