Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Aws Orchestrator HIGH 7.5
CVE-2024-42006

Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.

Fix: 2.01+
Fix from $1,950 2024-08-20
Sip Client Firmware HIGH 7.5
CVE-2024-41700

Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,950 2024-08-20
Priority HIGH 7.5
CVE-2024-41698

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Fix: 24.0+
Fix from $1,950 2024-08-20
Zzcms HIGH 7.5
CVE-2024-7925

A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/e…

No fix yet
Fix from $1,950 2024-08-19
Ntpl Xpon1gfevn Firmware CRITICAL 9.8
CVE-2024-42658

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter

Mitigation only
Fix from $2,300 2024-08-19
Ntpl Xpon1gfevn Firmware HIGH 7.5
CVE-2024-42657

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption dur…

Mitigation only
Fix from $1,950 2024-08-19
Cilium HIGH 7.2
CVE-2024-42486

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1…

Fix: after 1.15.8
Fix from $1,950 2024-08-16
Relevanssi HIGH 7.5
CVE-2024-7630

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2…

Fix: 4.23.0+
Fix from $1,950 2024-08-16
Online Graduate Tracer System HIGH 7.5
CVE-2024-7843

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function …

No fix yet
Fix from $1,950 2024-08-15
Online Graduate Tracer System HIGH 7.5
CVE-2024-7842

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unk…

No fix yet
Fix from $1,950 2024-08-15
Friendica MEDIUM 6.1
CVE-2024-27731

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filterin…

Patch available
Fix from $1,600 2024-08-15
Unclassified MEDIUM 5.3
CVE-2024-7411

The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not pr…

Mitigation only
Fix from $1,600 2024-08-15
Comfortkey HIGH 7.5
CVE-2024-27120

A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacke…

Fix: 24.1.2+
Fix from $1,950 2024-08-14
Workplace Desktop MEDIUM 6.5
CVE-2024-39822

Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an …

Fix: 6.0.12 / 6.1.0+
Fix from $1,600 2024-08-14
Olive One Click Demo Import HIGH 7.5
CVE-2024-38749

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality N…

Fix: after 1.1.2
Fix from $1,950 2024-08-13
Unclassified MEDIUM 5.3
CVE-2024-38756

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrai…

Mitigation only
Fix from $1,600 2024-08-13
Unclassified MEDIUM 5.3
CVE-2024-38760

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properl…

Mitigation only
Fix from $1,600 2024-08-13
Unclassified MEDIUM 5.3
CVE-2024-38742

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Accessing Functionality Not Properl…

Mitigation only
Fix from $1,600 2024-08-13
Unclassified HIGH 7.5
CVE-2024-38747

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce a…

Mitigation only
Fix from $1,950 2024-08-13
Commerce MEDIUM 5.3
CVE-2024-41733

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to lear…

Mitigation only
Fix from $1,600 2024-08-13
Commerce Cloud CRITICAL 9.1
CVE-2024-33003

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile number…

Mitigation only
Fix from $2,300 2024-08-13
Unclassified MEDIUM 5.3
CVE-2024-37924

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Cons…

Mitigation only
Fix from $1,600 2024-08-12
E Cology HIGH 7.5
CVE-2024-7704

A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/…

No fix yet
Fix from $1,950 2024-08-12
Carlcare HIGH 7.5
CVE-2024-7697

Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.

No fix yet
Fix from $1,950 2024-08-12
No Update Nag MEDIUM 5.3
CVE-2024-7412

The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin …

Fix: after 1.4.12
Fix from $1,600 2024-08-12
Unclassified MEDIUM 5.3
CVE-2024-7413

The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin…

Mitigation only
Fix from $1,600 2024-08-12
Unclassified MEDIUM 5.3
CVE-2024-7414

The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.116. This is due to …

Mitigation only
Fix from $1,600 2024-08-12
Unclassified MEDIUM 5.3
CVE-2024-7416

The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7. This is due to the plugin a…

Mitigation only
Fix from $1,600 2024-08-12
Unclassified MEDIUM 5.3
CVE-2024-7382

The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the plugin ut…

Mitigation only
Fix from $1,600 2024-08-12
Unclassified MEDIUM 5.3
CVE-2024-7410

The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.3. This is due the plu…

Mitigation only
Fix from $1,600 2024-08-12