Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2024-6562

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3…

Mitigation only
Fix from $1,600 2024-08-12
365 Apps MEDIUM 6.5
CVE-2024-38200EPSS 20%

Microsoft Office Spoofing Vulnerability

Patch available
Fix from $1,600 2024-08-12
Infoscan MEDIUM 5.3
CVE-2024-42493

Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript pr…

Mitigation only
Fix from $1,600 2024-08-08
Infoscan HIGH 7.5
CVE-2024-39287

Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.

Mitigation only
Fix from $1,950 2024-08-08
GitLab MEDIUM 6.5
CVE-2024-7554

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, …

Fix: 17.0.6 / 17.1.4+
Fix from $1,600 2024-08-08
Unclassified MEDIUM 5.3
CVE-2024-6552

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2024-08-08
Endpoint Manager Mobile MEDIUM 6.5
CVE-2024-34788

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in…

Fix: 12.1.0.1+
Fix from $1,600 2024-08-07
Arubaos CRITICAL 9.8
CVE-2024-42394

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploit…

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $2,300 2024-08-06
Office MEDIUM 6.5
CVE-2024-39817

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product…

Fix: 10.8.7+
Fix from $1,600 2024-08-06
Unclassified HIGH 7.5
CVE-2024-42010EPSS 53%

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-m…

Mitigation only
Fix from $1,950 2024-08-05
Openstack Platform MEDIUM 5.0
CVE-2024-7319

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon …

Mitigation only
Fix from $1,600 2024-08-02
Ebook Store MEDIUM 5.3
CVE-2024-6567

The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin ut…

Fix: after 5.8001
Fix from $1,600 2024-08-02
Zephyr Project Manager HIGH 7.5
CVE-2024-38761

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Mana…

Fix: 3.3.100+
Fix from $1,950 2024-08-01
Navidrome CRITICAL 9.1
CVE-2024-41259

Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.

Fix: after 0.52.3
Fix from $2,300 2024-08-01
Casdoor HIGH 7.5
CVE-2024-41264

An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

Mitigation only
Fix from $1,950 2024-08-01
Sh 4050a5 5l\(mm\) Firmware MEDIUM 5.3
CVE-2024-7339EPSS 32%

A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as…

No fix yet
Fix from $1,600 2024-08-01
Ctt Expresso Para Woocommerce HIGH 7.5
CVE-2024-6687

The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via…

Fix: 3.2.13+
Fix from $1,950 2024-08-01
Youdiancms MEDIUM 5.3
CVE-2024-7328

A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing of the file /t.php?a…

No fix yet
Fix from $1,600 2024-07-31
Fogproject MEDIUM 5.9
CVE-2024-41108

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only …

Fix: 1.5.10.41+
Fix from $1,600 2024-07-31
Admin Classic Bundle MEDIUM 6.5
CVE-2024-41109

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user e…

Fix: 1.3.10 / 1.4.6+
Fix from $1,600 2024-07-30
Unclassified MEDIUM 5.3
CVE-2024-41701

AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,600 2024-07-30
Unclassified MEDIUM 5.3
CVE-2024-41694

Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,600 2024-07-30
Unclassified HIGH 7.5
CVE-2024-41696

Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,950 2024-07-30
Ipados MEDIUM 5.5
CVE-2024-40836

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, w…

Fix: 10.6 / 14.6+
Fix from $1,600 2024-07-29
macOS MEDIUM 5.5
CVE-2024-40823

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be ab…

Fix: 12.7.6 / 13.6.8+
Fix from $1,600 2024-07-29
Ipados MEDIUM 5.5
CVE-2024-40793

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monter…

Fix: 10.6 / 12.7.6+
Fix from $1,600 2024-07-29
macOS MEDIUM 5.5
CVE-2024-40804

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A malicious application may be able to access private informa…

Fix: 14.6+
Fix from $1,600 2024-07-29
Iphone Os MEDIUM 5.5
CVE-2024-27884

This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS…

Fix: 1.2 / 10.5+
Fix from $1,600 2024-07-29
macOS MEDIUM 5.5
CVE-2024-40775

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ven…

Fix: 12.7.6 / 13.6.8+
Fix from $1,600 2024-07-29
A3700r Firmware HIGH 7.5
CVE-2024-7156EPSS 13%

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionalit…

No fix yet
Fix from $1,950 2024-07-28