Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified CRITICAL 9.1
CVE-2024-42049

TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.

Mitigation only
Fix from $2,300 2024-07-28
Unclassified MEDIUM 5.3
CVE-2024-5614

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 vi…

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-6569

The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is d…

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-6573

The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not p…

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-6546

The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to t…

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-6547

The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin …

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-6548

The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to the plu…

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-6549

The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to the pl…

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-6566

The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due …

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-6545

The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to the p…

Mitigation only
Fix from $1,600 2024-07-27
Unclassified MEDIUM 5.3
CVE-2024-7128

A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions.…

Mitigation only
Fix from $1,600 2024-07-26
GitLab MEDIUM 5.0
CVE-2024-7091

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting f…

Fix: 17.0.5 / 17.1.3+
Fix from $1,600 2024-07-24
GitLab MEDIUM 6.5
CVE-2024-7060

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1…

Fix: 17.0.5 / 17.1.3+
Fix from $1,600 2024-07-24
Duckdb HIGH 7.5
CVE-2024-41672

DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with…

Fix: 1.1.0+
Fix from $1,950 2024-07-24
Pinot HIGH 7.5
CVE-2024-39676

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. U…

Fix: 1.0.0+
Fix from $1,950 2024-07-24
Wp Meteor MEDIUM 5.3
CVE-2024-6553

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.3…

Fix: 3.4.4+
Fix from $1,600 2024-07-24
Optimize Images Alt Text \(alt Tag\) \& Names For Seo Using Ai MEDIUM 5.3
CVE-2024-6571

The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and…

Fix: 3.1.2+
Fix from $1,600 2024-07-24
Rocketmq HIGH 8.8
CVE-2024-23321

For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i…

Fix: 5.3.0+
Fix from $1,950 2024-07-22
Unclassified MEDIUM 5.3
CVE-2024-6560

The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. Th…

Mitigation only
Fix from $1,600 2024-07-20
Elements Kit Elementor Addons MEDIUM 5.3
CVE-2024-6455

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a miss…

Fix: 3.2.1+
Fix from $1,600 2024-07-18
Unclassified MEDIUM 5.3
CVE-2024-40647

sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocess…

Patch available
Fix from $1,600 2024-07-18
Unclassified MEDIUM 5.3
CVE-2024-40633

Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, whi…

Mitigation only
Fix from $1,600 2024-07-17
Webex Teams MEDIUM 6.5
CVE-2024-20396

A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. …

Mitigation only
Fix from $1,600 2024-07-17
Process Manufacturing Financials HIGH 8.1
CVE-2024-21152

Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Allocation Rules). Supported versions th…

Fix: after 12.2.13
Fix from $1,950 2024-07-16
Active Iq Unified Manager HIGH 7.4
CVE-2024-21147

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo…

Mitigation only
Fix from $1,950 2024-07-16
Retail Xstore Office HIGH 8.6
CVE-2024-21136

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected a…

Mitigation only
Fix from $1,950 2024-07-16
Enterprise Server MEDIUM 5.3
CVE-2024-6395

An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Enterprise Server MEDIUM 5.3
CVE-2024-6336

A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterp…

Fix: 3.9.17 / 3.10.14+
Fix from $1,600 2024-07-16
Unclassified MEDIUM 6.3
CVE-2020-25836

Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects …

Mitigation only
Fix from $1,600 2024-07-16
Cyber Protect MEDIUM 6.5
CVE-2022-45449

Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15…

Fix: 15+
Fix from $1,600 2024-07-16