Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2024-6565

The AForms — Form Builder for Price Calculator & Cost Estimation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, an…

Mitigation only
Fix from $1,600 2024-07-16
Unclassified MEDIUM 5.3
CVE-2024-6570

The Glossary plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.26. This is due the plugin utilizin…

Mitigation only
Fix from $1,600 2024-07-16
Unclassified MEDIUM 5.3
CVE-2024-6559

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up…

Mitigation only
Fix from $1,600 2024-07-16
Unclassified MEDIUM 5.3
CVE-2024-6557

The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher plugin for WordPr…

Mitigation only
Fix from $1,600 2024-07-16
Tmall Demo HIGH 7.5
CVE-2024-40554

An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.

Mitigation only
Fix from $1,950 2024-07-15
Secure Web Gateway MEDIUM 5.3
CVE-2024-6398

An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizabl…

Fix: 11.2.24 / 12.2.10+
Fix from $1,600 2024-07-15
Unclassified MEDIUM 5.3
CVE-2024-6574

The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This is due to the plugin not prev…

Mitigation only
Fix from $1,600 2024-07-13
Unclassified MEDIUM 5.3
CVE-2024-6555

The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.0.1. Thi…

Mitigation only
Fix from $1,600 2024-07-12
Whc 5918a Firmware HIGH 7.5
CVE-2024-6407

CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.

No fix yet
Fix from $1,950 2024-07-11
Branda MEDIUM 5.3
CVE-2024-6554

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, an…

Fix: 3.4.19+
Fix from $1,600 2024-07-11
Unclassified MEDIUM 5.3
CVE-2024-6210

The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for una…

Mitigation only
Fix from $1,600 2024-07-11
Unclassified MEDIUM 5.3
CVE-2024-27090

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…

Patch available
Fix from $1,600 2024-07-10
Unclassified MEDIUM 5.3
CVE-2024-6646EPSS 46%

A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Mitigation only
Fix from $1,600 2024-07-10
Unclassified MEDIUM 5.3
CVE-2024-37498

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Tab…

No fix yet
Fix from $1,600 2024-07-10
Unclassified MEDIUM 5.3
CVE-2024-37504

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document…

No fix yet
Fix from $1,600 2024-07-10
Unclassified HIGH 7.5
CVE-2024-37110

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member …

Mitigation only
Fix from $1,950 2024-07-10
Unclassified CRITICAL 9.8
CVE-2024-37113

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member …

Mitigation only
Fix from $2,300 2024-07-10
Unclassified HIGH 7.5
CVE-2024-37115

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a t…

Mitigation only
Fix from $1,950 2024-07-10
Unclassified MEDIUM 5.3
CVE-2024-6556

The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, a…

Mitigation only
Fix from $1,600 2024-07-10
Unclassified MEDIUM 5.3
CVE-2024-6550

The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.1. Th…

Mitigation only
Fix from $1,600 2024-07-10
Unclassified HIGH 7.0
CVE-2024-32670

Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes to potentially identify the t…

Mitigation only
Fix from $1,950 2024-07-10
Exynos 1280 Firmware HIGH 7.5
CVE-2024-27362

A vulnerability was discovered in Samsung Mobile Processors Exynos 1280, Exynos 2200, Exynos 1330, Exynos 1380, and Exynos 2400 where they do not pro…

Mitigation only
Fix from $1,950 2024-07-09
Windows 10 1607 MEDIUM 5.5
CVE-2024-38041

Windows Kernel Information Disclosure Vulnerability

Fix: 10.0.14393.7159 / 10.0.17763.6054+
Fix from $1,600 2024-07-09
Windows 10 1507 MEDIUM 6.5
CVE-2024-38030EPSS 51%

Windows Themes Spoofing Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,600 2024-07-09
365 Apps MEDIUM 6.5
CVE-2024-38020

Microsoft Outlook Spoofing Vulnerability

Patch available
Fix from $1,600 2024-07-09
Windows 10 1507 MEDIUM 5.5
CVE-2024-38017

Microsoft Message Queuing Information Disclosure Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,600 2024-07-09
Windows 10 1507 HIGH 7.1
CVE-2024-30081EPSS 24%

Windows NTLM Spoofing Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,950 2024-07-09
Firefox MEDIUM 5.3
CVE-2024-6612

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked…

Fix: 128.0+
Fix from $1,600 2024-07-09
Unclassified HIGH 7.5
CVE-2023-52237

A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCO…

No fix yet
Fix from $1,950 2024-07-09
Kiwi Social Share MEDIUM 5.3
CVE-2024-3228

The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi…

Fix: 2.1.8+
Fix from $1,600 2024-07-09