Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Nautobot MEDIUM 5.3
CVE-2024-29199

Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to u…

Fix: 1.6.16 / 2.1.9+
Fix from $1,600 2024-03-26
Security Verify Directory MEDIUM 5.3
CVE-2022-32751

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-For…

Mitigation only
Fix from $1,600 2024-03-22
Ciges HIGH 7.5
CVE-2024-2725

Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all …

Mitigation only
Fix from $1,950 2024-03-22
Ciges MEDIUM 5.5
CVE-2024-2728

Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of pro…

Mitigation only
Fix from $1,600 2024-03-22
Storage Protect Plus MEDIUM 5.5
CVE-2024-27277

The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certific…

Fix: after 10.1.6
Fix from $1,600 2024-03-21
School Fees Management System HIGH 7.5
CVE-2023-49981

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the applicati…

No fix yet
Fix from $1,950 2024-03-21
React Storefront MEDIUM 6.5
CVE-2024-29036

Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authentica…

Fix: 1.0.2+
Fix from $1,600 2024-03-20
Zulip Server MEDIUM 6.5
CVE-2024-27286

Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only…

Fix: 8.3+
Fix from $1,600 2024-03-20
Unclassified MEDIUM 5.3
CVE-2024-1477

The Easy Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the RE…

Mitigation only
Fix from $1,600 2024-03-20
Unclassified HIGH 7.5
CVE-2024-2632

A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot of information about the appli…

Mitigation only
Fix from $1,950 2024-03-19
Openclinic Ga HIGH 7.5
CVE-2023-40278

An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp compone…

No fix yet
Fix from $1,950 2024-03-19
Openclinic Ga CRITICAL 9.1
CVE-2023-40275

An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchBy…

Mitigation only
Fix from $2,300 2024-03-19
Openclinic Ga CRITICAL 9.1
CVE-2023-40276

An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp.

No fix yet
Fix from $2,300 2024-03-19
Experience Manager MEDIUM 5.3
CVE-2024-26119

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature by…

Fix: 6.5.20.0 / 2024.3.0+
Fix from $1,600 2024-03-18
Experience Manager MEDIUM 5.3
CVE-2024-26063

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature by…

Fix: 6.5.20.0 / 2024.3.0+
Fix from $1,600 2024-03-18
Unilogic HIGH 8.8
CVE-2024-27769

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking O…

Fix: 1.35.227+
Fix from $1,950 2024-03-18
Wp Editor HIGH 7.5
CVE-2024-25591

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Benjamin Rojas WP Editor.This issue affects WP Editor: from n/a through 1…

Fix: 1.2.8+
Fix from $1,950 2024-03-17
Frontend File Manager HIGH 7.5
CVE-2024-25903

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: f…

Fix: 22.8+
Fix from $1,950 2024-03-17
Visitor Statistics HIGH 7.5
CVE-2024-24867

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Osamaesh WP Visitor Statistics (Real Time Traffic).This issue affects WP …

Fix: after 6.9.4
Fix from $1,950 2024-03-17
Peprodev Ultimate Invoice HIGH 7.5
CVE-2024-25933

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ul…

Fix: 1.9.8+
Fix from $1,950 2024-03-17
Unclassified MEDIUM 6.5
CVE-2024-23523

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Elementor Pro.This issue affects Elementor Pro: from n/a through 3.19.2.

No fix yet
Fix from $1,600 2024-03-16
Unclassified MEDIUM 5.3
CVE-2024-24845

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sewpafly Post Thumbnail Editor.This issue affects Post Thumbnail Editor: …

No fix yet
Fix from $1,600 2024-03-16
Discourse HIGH 7.5
CVE-2024-28242

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have…

Fix: 3.2.0 / 3.3.0+
Fix from $1,950 2024-03-15
Discourse MEDIUM 5.3
CVE-2024-24748

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a pu…

Fix: after 3.2.0
Fix from $1,600 2024-03-15
Follow Redirects MEDIUM 6.5
CVE-2024-28849

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versi…

Fix: 1.15.6+
Fix from $1,600 2024-03-14
Your Spotify MEDIUM 6.5
CVE-2024-28193

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to create a public token in the setti…

Fix: 1.8.0+
Fix from $1,600 2024-03-13
Masterstudy Lms HIGH 7.5
CVE-2024-2106

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to,…

Fix: 3.2.11+
Fix from $1,950 2024-03-13
Simple Restrict MEDIUM 5.3
CVE-2024-1083

The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.6 via the REST API…

Fix: 1.2.7+
Fix from $1,600 2024-03-13
Worker MEDIUM 6.5
CVE-2024-28236

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution c…

Fix: 0.23.2+
Fix from $1,600 2024-03-12
Cbk40 Firmware MEDIUM 5.4
CVE-2024-28339

An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to …

No fix yet
Fix from $1,600 2024-03-12