Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HTTP Server MEDIUM 5.3
CVE-2024-20991

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12…

Mitigation only
Fix from $1,600 2024-04-16
Applications Technology Stack MEDIUM 5.3
CVE-2024-20990

Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: Templates). Supported versions that are affected …

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Unclassified HIGH 7.5
CVE-2024-32086

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AitThemes Citadela Listing.This issue affects Citadela Listing: from n/a …

Mitigation only
Fix from $1,950 2024-04-16
Unclassified HIGH 7.5
CVE-2023-50872

The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about ce…

Mitigation only
Fix from $1,950 2024-04-16
Scrapy HIGH 7.5
CVE-2024-3574

In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a th…

Fix: 2.11.1+
Fix from $1,950 2024-04-16
Unclassified MEDIUM 6.0
CVE-2024-24891

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerabili…

Mitigation only
Fix from $1,600 2024-04-15
Unclassified MEDIUM 6.0
CVE-2024-24898

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerabili…

Mitigation only
Fix from $1,600 2024-04-15
Unclassified HIGH 7.8
CVE-2024-3780

A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerability allows a local attacker …

Mitigation only
Fix from $1,950 2024-04-15
Unclassified HIGH 8.3
CVE-2024-22435

A potential security vulnerability has been identified in Web ViewPoint Enterprise software. This vulnerability could be exploited to allow unauthori…

No fix yet
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29842

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_A…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29843

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, …

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29839

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_C…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29840

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_P…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29841

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_K…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Unclassified HIGH 7.2
CVE-2024-29023

Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. Session tokens are exposed …

Patch available
Fix from $1,950 2024-04-12
O2oa MEDIUM 5.9
CVE-2024-3689

A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown fun…

Fix: after 2024-04-03
Fix from $1,600 2024-04-12
Paragon Active Assurance Control Center HIGH 8.4
CVE-2024-30381

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Juniper Networks Paragon Active Assurance Control Center allows a netw…

Mitigation only
Fix from $1,950 2024-04-12
Opengnsys HIGH 7.5
CVE-2024-3706

Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to view a php backup file (c…

Mitigation only
Fix from $1,950 2024-04-12
Ruoyi HIGH 7.5
CVE-2024-29400

An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.

No fix yet
Fix from $1,950 2024-04-12
Trux Waste Management MEDIUM 6.2
CVE-2024-22734

An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive infor…

Fix: 7.19.0018.26912+
Fix from $1,600 2024-04-12
Element Pack HIGH 7.5
CVE-2024-2966

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sen…

Fix: 5.6.0+
Fix from $1,950 2024-04-11
Unclassified HIGH 7.7
CVE-2024-2740

Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacke…

Mitigation only
Fix from $1,950 2024-04-11
Biotime HIGH 7.5
CVE-2023-51142

An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.

No fix yet
Fix from $1,950 2024-04-11
Unclassified CRITICAL 9.1
CVE-2024-1643

By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within tha…

Patch available
Fix from $2,300 2024-04-10
Contact Form Email MEDIUM 5.3
CVE-2024-31302

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from…

Fix: 1.3.44+
Fix from $1,600 2024-04-10
Essential Addons For Elementor MEDIUM 5.3
CVE-2024-2974

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive I…

Fix: 5.9.14+
Fix from $1,600 2024-04-09
Vk All In One Expansion Unit MEDIUM 5.3
CVE-2024-2093

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 …

Fix: 9.96.0.0+
Fix from $1,600 2024-04-09
Unclassified HIGH 7.5
CVE-2023-7046

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is vulnerable to Sensitive I…

Mitigation only
Fix from $1,950 2024-04-09
Wp Go Maps MEDIUM 6.5
CVE-2023-6777

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9…

Fix: 9.0.35+
Fix from $1,600 2024-04-09
Contao MEDIUM 6.5
CVE-2024-28235

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links…

Fix: 4.13.40 / 5.3.4+
Fix from $1,600 2024-04-09