Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Sap Basis MEDIUM 5.3
CVE-2024-37180

Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with…

Patch available
Fix from $1,600 2024-07-09
Landscape Management MEDIUM 5.7
CVE-2024-39593

SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploi…

Mitigation only
Fix from $1,600 2024-07-09
Directus MEDIUM 5.3
CVE-2024-39896

Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authenticati…

Fix: 10.13.0+
Fix from $1,600 2024-07-08
Domino HIGH 7.5
CVE-2024-23562

A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploi…

No fix yet
Fix from $1,950 2024-07-08
Mediawiki HIGH 7.5
CVE-2024-40597

An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_delete…

Fix: after 1.42.1
Fix from $1,950 2024-07-07
Unclassified HIGH 7.5
CVE-2024-39182

An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root user's session via an arbitrar…

Mitigation only
Fix from $1,950 2024-07-05
Best House Rental Management System HIGH 7.5
CVE-2024-39210

Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vul…

Fix: after 1.0
Fix from $1,950 2024-07-05
Unclassified HIGH 8.2
CVE-2024-6506

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a r…

Mitigation only
Fix from $1,950 2024-07-04
Zitadel MEDIUM 6.5
CVE-2024-39683

ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (brows…

Fix: 2.53.8 / 2.54.5+
Fix from $1,600 2024-07-03
Mesbook HIGH 7.1
CVE-2024-6426

Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacker, with user privileges, to a…

Mitigation only
Fix from $1,950 2024-07-03
Mattermost MEDIUM 5.3
CVE-2024-39807

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook …

Fix: 9.5.6 / 9.8.1+
Fix from $1,600 2024-07-03
Toy Blog MEDIUM 5.3
CVE-2024-39313

toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, articles with private visibili…

Fix: 0.6.1+
Fix from $1,600 2024-07-01
Cloud MEDIUM 5.7
CVE-2024-36986

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated…

Fix: 9.0.10 / 9.1.5+
Fix from $1,600 2024-07-01
Dryice Aex HIGH 7.5
CVE-2024-30135

HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

Mitigation only
Fix from $1,950 2024-06-28
Unclassified MEDIUM 5.3
CVE-2024-2795

The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.1 via META description. This…

Mitigation only
Fix from $1,600 2024-06-28
Unclassified MEDIUM 6.8
CVE-2024-22260

VMware Workspace One UEM update addresses an information exposure vulnerability.  A malicious actor with network access to the Workspace One UEM may …

Mitigation only
Fix from $1,600 2024-06-27
M1 Firmware HIGH 7.5
CVE-2024-36829

Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted query string.

Mitigation only
Fix from $1,950 2024-06-26
Whatsup Gold HIGH 7.5
CVE-2024-5010EPSS 70%

In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality.  A specially crafted unauthenticated…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Unclassified HIGH 7.5
CVE-2024-34991

In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (expiry da…

Mitigation only
Fix from $1,950 2024-06-24
Sharepoint Bulk File Download MEDIUM 5.3
CVE-2024-33880

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDo…

Mitigation only
Fix from $1,600 2024-06-24
Sharepoint Bulk File Download MEDIUM 5.3
CVE-2024-33881

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx i…

Mitigation only
Fix from $1,600 2024-06-24
Phpinfo Wp HIGH 7.5
CVE-2024-35776

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.…

Fix: after 5.0
Fix from $1,950 2024-06-21
Event Monster HIGH 7.5
CVE-2024-5059

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Manag…

Fix: after 1.4.0
Fix from $1,950 2024-06-21
Unclassified HIGH 7.8
CVE-2024-22002

CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation d…

Mitigation only
Fix from $1,950 2024-06-18
Jira Data Center MEDIUM 6.5
CVE-2024-21685

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Inf…

Fix: 9.4.21 / 9.12.8+
Fix from $1,600 2024-06-18
Lobe Chat MEDIUM 5.7
CVE-2024-37895

Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they c…

Fix: 0.162.25+
Fix from $1,600 2024-06-17
Synthesis Image System HIGH 7.5
CVE-2024-38467

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.

Fix: 8.3.0+
Fix from $1,950 2024-06-16
Virtual Gpu MEDIUM 5.5
CVE-2024-0093

NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to hav…

Fix: 13.11 / 16.6+
Fix from $1,600 2024-06-13
Cilium MEDIUM 6.5
CVE-2024-37307

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1…

Fix: 1.13.17 / 1.14.12+
Fix from $1,600 2024-06-13
Framemaker Publishing Server CRITICAL 9.8
CVE-2024-30300

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lea…

Fix: 2020+
Fix from $2,300 2024-06-13