Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Telemetry Dashboard MEDIUM 5.5
CVE-2024-30472

Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local acces…

Mitigation only
Fix from $1,600 2024-06-13
Azure Data Science Virtual Machine HIGH 8.1
CVE-2024-37325

Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability

Fix: 24.05.24+
Fix from $1,950 2024-06-11
Dynamics 365 MEDIUM 5.7
CVE-2024-35263

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Patch available
Fix from $1,600 2024-06-11
Windows 10 1809 MEDIUM 5.5
CVE-2024-30096

Windows Cryptographic Services Information Disclosure Vulnerability

Fix: 10.0.17763.5936 / 10.0.19044.4529+
Fix from $1,600 2024-06-11
Metform Elementor Contact Form Builder HIGH 7.5
CVE-2024-4266

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in…

Fix: 3.8.9+
Fix from $1,950 2024-06-11
Access Manager MEDIUM 6.5
CVE-2020-11843

This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before

Fix: 4.4+
Fix from $1,600 2024-06-11
Businessobjects Business Intelligence Platform MEDIUM 6.0
CVE-2024-34684

On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local serv…

Patch available
Fix from $1,600 2024-06-11
Netweaver Application Server Java MEDIUM 5.3
CVE-2024-28164

SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would other…

Mitigation only
Fix from $1,600 2024-06-11
Apex One MEDIUM 5.5
CVE-2024-36307

A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive in…

Fix: after 14.0.13139
Fix from $1,600 2024-06-10
Allura HIGH 7.5
CVE-2024-36471

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp…

Fix: 1.17.0+
Fix from $1,950 2024-06-10
Ipados MEDIUM 5.5
CVE-2024-27806

This issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS…

Fix: 10.5 / 12.7.5+
Fix from $1,600 2024-06-10
macOS MEDIUM 5.3
CVE-2022-32933

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to t…

Fix: 12.5+
Fix from $1,600 2024-06-10
Unclassified MEDIUM 6.5
CVE-2024-35691

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Marketing Fire, LLC Widget Options - Extended.This issue affects Widget O…

No fix yet
Fix from $1,600 2024-06-08
Otter Blocks MEDIUM 5.3
CVE-2024-35682

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a …

Fix: 2.6.12+
Fix from $1,600 2024-06-08
Unclassified MEDIUM 5.3
CVE-2024-35710

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Podlove Podlove Web Player.This issue affects Podlove Web Player: from n/…

No fix yet
Fix from $1,600 2024-06-08
Lunary HIGH 8.1
CVE-2024-5133

In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifi…

Fix: 1.2.14+
Fix from $1,950 2024-06-06
Deno MEDIUM 6.5
CVE-2024-37150

An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the regis…

Patch available
Fix from $1,600 2024-06-06
Jupyter Server HIGH 7.5
CVE-2024-35178

The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attacke…

Fix: 2.14.1+
Fix from $1,950 2024-06-06
Open Graph MEDIUM 5.3
CVE-2024-5615

The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_d…

Fix: 1.11.3+
Fix from $1,600 2024-06-06
Restrict For Elementor MEDIUM 5.3
CVE-2024-0910

The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 due to im…

Fix: 1.0.8+
Fix from $1,600 2024-06-06
Satellite MEDIUM 6.2
CVE-2024-3716

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce…

Mitigation only
Fix from $1,600 2024-06-05
Learnpress MEDIUM 5.3
CVE-2024-5483

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.…

Fix: 4.2.6.8.1+
Fix from $1,600 2024-06-05
Netty Incubator Codec Ohttp CRITICAL 9.1
CVE-2024-36121

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and us…

Fix: 0.0.11+
Fix from $2,300 2024-06-04
Beyondinsight MEDIUM 5.3
CVE-2024-4220

Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

Fix: 23.1+
Fix from $1,600 2024-06-04
Unclassified MEDIUM 5.3
CVE-2023-49774

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functi…

Mitigation only
Fix from $1,600 2024-06-04
Unclassified MEDIUM 5.3
CVE-2024-34754

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue affects Contact Form Widget: fro…

Mitigation only
Fix from $1,600 2024-06-03
Fortiweb MEDIUM 5.5
CVE-2024-23107

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0…

Fix: 7.0.9 / 7.2.5+
Fix from $1,600 2024-06-03
Moodle MEDIUM 6.5
CVE-2024-34002

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedba…

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle MEDIUM 5.9
CVE-2024-34003

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore worksh…

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle MEDIUM 6.5
CVE-2024-34004

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki m…

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31