Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Fortios HIGH 7.5
CVE-2024-23662

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2…

Fix: 7.2.6 / 7.4.2+
Fix from $1,950 2024-04-09
Dataease MEDIUM 5.3
CVE-2024-30269EPSS 16%

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0…

Fix: 2.5.0+
Fix from $1,600 2024-04-08
Ex200 Firmware HIGH 7.5
CVE-2024-31817EPSS 55%

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

No fix yet
Fix from $1,950 2024-04-08
Ex200 Firmware HIGH 7.5
CVE-2024-31816

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

Mitigation only
Fix from $1,950 2024-04-08
Emui HIGH 7.5
CVE-2024-27897

Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2024-04-08
Android HIGH 7.5
CVE-2023-52341

In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote in…

Mitigation only
Fix from $1,950 2024-04-08
Easy Seo MEDIUM 5.3
CVE-2024-2950

The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6…

Fix: 1.6.15+
Fix from $1,600 2024-04-06
Unclassified MEDIUM 5.3
CVE-2023-5692

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function…

Mitigation only
Fix from $1,600 2024-04-05
Unclassified HIGH 7.7
CVE-2024-30263

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF attachments using the PDF View…

Mitigation only
Fix from $1,950 2024-04-04
Unclassified MEDIUM 5.9
CVE-2024-31207

Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.d…

Patch available
Fix from $1,600 2024-04-04
Unclassified MEDIUM 5.5
CVE-2024-3262

Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to r…

Mitigation only
Fix from $1,600 2024-04-04
Unclassified MEDIUM 5.3
CVE-2024-3274EPSS 33%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problemati…

Mitigation only
Fix from $1,600 2024-04-04
R6850 Firmware HIGH 7.5
CVE-2024-30569

An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication requ…

No fix yet
Fix from $1,950 2024-04-03
R6850 Firmware MEDIUM 5.3
CVE-2024-30570

An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

No fix yet
Fix from $1,600 2024-04-03
R6850 Firmware HIGH 7.5
CVE-2024-30571EPSS 14%

An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authenticat…

No fix yet
Fix from $1,950 2024-04-03
Db2 MEDIUM 6.5
CVE-2023-38729

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using A…

Mitigation only
Fix from $1,600 2024-04-03
Unclassified MEDIUM 5.3
CVE-2024-3160

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Intelbras MHDX 1004, MHDX 1008, MHDX 1016, MHDX 5016, HDCVI 1008 an…

Mitigation only
Fix from $1,600 2024-04-02
Wholesale For Woocommerce MEDIUM 5.3
CVE-2024-30469

Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

Fix: 2.3.1+
Fix from $1,600 2024-03-29
Ipados MEDIUM 5.5
CVE-2023-42936

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17…

Fix: 10.2 / 12.7.2+
Fix from $1,600 2024-03-28
Createwiki MEDIUM 6.5
CVE-2024-29898

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may hav…

Fix: 2024-03-27+
Fix from $1,600 2024-03-28
Booster For Woocommerce MEDIUM 6.5
CVE-2023-52231

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This issue affects Booster Plus for …

Fix: 7.1.2+
Fix from $1,600 2024-03-28
Booster For Woocommerce MEDIUM 6.5
CVE-2023-52234

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Elite for WooCommerce.This issue affects Booster Elite fo…

Fix: 7.1.2+
Fix from $1,600 2024-03-28
Pi Hole MEDIUM 6.5
CVE-2024-28247

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been …

Fix: 5.18+
Fix from $1,600 2024-03-27
Apollo Vx20 Firmware HIGH 7.5
CVE-2024-25734

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is ente…

Fix: 1.3.58+
Fix from $1,950 2024-03-27
Vp59 Firmware HIGH 7.5
CVE-2024-28442

Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of u…

No fix yet
Fix from $1,950 2024-03-26
Unclassified MEDIUM 5.9
CVE-2023-25965

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in mbbhatti Upload Resume.This issue affects Upload Resume: from n/a through…

No fix yet
Fix from $1,600 2024-03-26
Unclassified MEDIUM 5.3
CVE-2023-27630

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n…

Mitigation only
Fix from $1,600 2024-03-26
Pimcore MEDIUM 6.5
CVE-2024-29197

Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished …

Fix: 11.1.6.1 / 11.2.2+
Fix from $1,600 2024-03-26
Gridvis HIGH 8.8
CVE-2023-50894

In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password encryptio…

Fix: 9.0.67+
Fix from $1,950 2024-03-26
Wholesalex MEDIUM 6.5
CVE-2024-30233

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through…

Fix: 1.3.2+
Fix from $1,600 2024-03-26