Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Moodle MEDIUM 6.5
CVE-2024-34005

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore databa…

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Unclassified MEDIUM 6.5
CVE-2021-44534

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

Mitigation only
Fix from $1,600 2024-05-31
Astrotalks MEDIUM 5.3
CVE-2024-5524

Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal li…

Mitigation only
Fix from $1,600 2024-05-31
Fides MEDIUM 6.5
CVE-2024-35189

Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records a…

Fix: 2.37.0+
Fix from $1,600 2024-05-30
Linux Kernel HIGH 7.7
CVE-2024-36955

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node() The docum…

Fix: 5.15.159 / 6.1.91+
Fix from $1,950 2024-05-30
Linux Kernel HIGH 8.4
CVE-2024-36910

In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Don't free decrypted memory In CoCo VMs it is possible for the …

Fix: 6.1.91 / 6.6.31+
Fix from $1,950 2024-05-30
Quantum Spark Firmware HIGH 8.6
CVE-2024-24919 KEVEPSS 100%

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote …

Patch available
Fix from $1,950 2024-05-28
Unclassified MEDIUM 5.3
CVE-2024-36107

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` heade…

Patch available
Fix from $1,600 2024-05-28
Unclassified HIGH 7.5
CVE-2024-35341

Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFile.ini or …

Mitigation only
Fix from $1,950 2024-05-28
Unclassified CRITICAL 9.8
CVE-2024-35343

Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/…

Mitigation only
Fix from $2,300 2024-05-28
Aj Report MEDIUM 6.5
CVE-2024-5354

A vulnerability classified as problematic was found in anji-plus AJ-Report up to 1.4.1. This vulnerability affects unknown code of the file /reportSh…

Fix: after 1.4.1
Fix from $1,600 2024-05-26
Unclassified HIGH 7.7
CVE-2024-5202

Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservices

Mitigation only
Fix from $1,950 2024-05-23
Unclassified MEDIUM 5.3
CVE-2024-28188

Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-schedu…

Patch available
Fix from $1,600 2024-05-23
Unclassified MEDIUM 5.3
CVE-2024-35223

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app in…

Patch available
Fix from $1,600 2024-05-23
Unclassified MEDIUM 5.3
CVE-2024-5230EPSS 19%

A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functio…

No fix yet
Fix from $1,600 2024-05-23
Qts HIGH 8.1
CVE-2024-21902

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploit…

Mitigation only
Fix from $1,950 2024-05-21
Linux Kernel HIGH 7.1
CVE-2021-47403

In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix module reference leak A reference to the carrier module was…

Fix: 4.4.286 / 4.9.285+
Fix from $1,950 2024-05-21
Scrapy HIGH 7.5
CVE-2024-1968

In scrapy/scrapy, an issue was identified where the Authorization header is not removed during redirects that only change the scheme (e.g., HTTPS to …

Fix: 2.11.2+
Fix from $1,950 2024-05-20
Unclassified MEDIUM 5.3
CVE-2024-5096

A vulnerability classified as problematic was found in Hipcam Device up to 20240511. This vulnerability affects unknown code of the file /log/wifi.ma…

Mitigation only
Fix from $1,600 2024-05-19
Download Manager HIGH 7.5
CVE-2024-32131

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affe…

Fix: 3.2.83+
Fix from $1,950 2024-05-17
Unclassified MEDIUM 6.5
CVE-2024-3182

Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6…

Mitigation only
Fix from $1,600 2024-05-15
Telerik Report Server MEDIUM 5.3
CVE-2024-4837

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Se…

Fix: 10.1.24.514+
Fix from $1,600 2024-05-15
Prestashop MEDIUM 5.3
CVE-2024-34717

PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by s…

Mitigation only
Fix from $1,600 2024-05-14
TYPO3 MEDIUM 5.3
CVE-2024-34358

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…

Fix: 9.5.48 / 10.4.45+
Fix from $1,600 2024-05-14
Linqi HIGH 7.5
CVE-2024-33865

An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endp…

Fix: 1.4.0.1+
Fix from $1,950 2024-05-14
Ruggedcom Crossbow MEDIUM 5.3
CVE-2024-27947

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwarded to a s…

Fix: 5.5+
Fix from $1,600 2024-05-14
Workstation MEDIUM 6.0
CVE-2024-22270

VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor …

Fix: 13.5.2 / 17.5.2+
Fix from $1,600 2024-05-14
Workstation MEDIUM 6.0
CVE-2024-22269

VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative p…

Fix: 13.5.2 / 17.5.2+
Fix from $1,600 2024-05-14
Academy Lms MEDIUM 5.3
CVE-2024-35171

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.…

Fix: 1.9.26+
Fix from $1,600 2024-05-14
Filebird HIGH 7.5
CVE-2024-35166

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.

Fix: 5.6.4+
Fix from $1,950 2024-05-14