Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Cbk40 Firmware HIGH 7.5
CVE-2024-28340

An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attacker…

No fix yet
Fix from $1,950 2024-03-12
Windows 10 1507 MEDIUM 5.5
CVE-2024-26177

Windows Kernel Information Disclosure Vulnerability

Fix: 10.0.10240.20526 / 10.0.14393.6796+
Fix from $1,600 2024-03-12
Monitool MEDIUM 5.5
CVE-2024-1302

Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application…

Fix: 4.7+
Fix from $1,600 2024-03-12
Unclassified MEDIUM 6.2
CVE-2024-2371

Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol uses plaintext to transfer da…

Mitigation only
Fix from $1,600 2024-03-12
F\(x\) Private Site MEDIUM 5.3
CVE-2024-0906

The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. T…

Fix: after 1.2.1
Fix from $1,600 2024-03-12
Codeium HIGH 7.5
CVE-2024-28120

codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check …

No fix yet
Fix from $1,950 2024-03-11
Online MEDIUM 5.3
CVE-2024-25114

Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "K…

Fix: 21.11.9.4 / 22.05.22+
Fix from $1,600 2024-03-11
Archer HIGH 7.5
CVE-2024-26309

Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could pote…

Fix: 6.14.0.2.2+
Fix from $1,950 2024-03-08
Ipados MEDIUM 5.5
CVE-2023-28826

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4…

Fix: 12.7.4 / 13.6.5+
Fix from $1,600 2024-03-08
Casaos CRITICAL 9.8
CVE-2024-24765

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files …

Fix: 0.4.7+
Fix from $2,300 2024-03-06
Duo Authentication For Windows Logon And Rdp MEDIUM 5.5
CVE-2024-20292

A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view s…

Fix: 4.3.0+
Fix from $1,600 2024-03-06
Archibus MEDIUM 6.1
CVE-2023-48644

An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance module…

Mitigation only
Fix from $1,600 2024-03-05
Jm Twitter Cards MEDIUM 5.3
CVE-2024-1769

The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14 via the meta description dat…

Fix: 14.1.0+
Fix from $1,600 2024-03-05
Security Verify Privilege On Premises HIGH 7.5
CVE-2022-43890

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att…

Fix: after 11.5
Fix from $1,950 2024-03-04
Software Package MEDIUM 5.9
CVE-2024-20019

In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional execut…

Fix: after 2023.11.10
Fix from $1,600 2024-03-04
Helm MEDIUM 6.5
CVE-2019-25210

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is use…

Mitigation only
Fix from $1,600 2024-03-03
Anythingllm MEDIUM 6.5
CVE-2024-0765

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and r…

Fix: 1.0.0+
Fix from $1,600 2024-03-03
Super Newsletter HIGH 7.5
CVE-2024-25839

An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to es…

Fix: after 1.4.21
Fix from $1,950 2024-03-03
Directus MEDIUM 5.3
CVE-2024-27296

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being…

Fix: 10.8.3+
Fix from $1,600 2024-03-01
Cognos Command Center MEDIUM 5.3
CVE-2023-50324

IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information…

Mitigation only
Fix from $1,600 2024-03-01
Mattermost Server MEDIUM 6.5
CVE-2024-23493

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a …

Fix: 8.1.9 / 9.2.5+
Fix from $1,600 2024-02-29
.net 9 Starter Kit HIGH 8.1
CVE-2024-26470

A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to lea…

No fix yet
Fix from $1,950 2024-02-29
Couchbase Server HIGH 7.5
CVE-2024-23302

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

Fix: 7.2.4+
Fix from $1,950 2024-02-29
Passster MEDIUM 5.3
CVE-2024-0616

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…

Fix: 4.2.6.3+
Fix from $1,600 2024-02-29
Password Protect Wordpress MEDIUM 5.3
CVE-2024-0620

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 vi…

Fix: 1.9.0+
Fix from $1,600 2024-02-29
Under Construction \/ Maintenance Mode MEDIUM 6.5
CVE-2023-6922

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inc…

Fix: after 2.6
Fix from $1,600 2024-02-28
Rails MEDIUM 5.3
CVE-2024-26144

Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By defau…

Fix: 6.1.7.7 / 7.1.0+
Fix from $1,600 2024-02-27
Aurora CRITICAL 9.1
CVE-2024-27905

** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte…

Mitigation only
Fix from $2,300 2024-02-27
Innovaphone Pbx MEDIUM 5.3
CVE-2024-24720

An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists o…

Fix: 14r1+
Fix from $1,600 2024-02-27
Mt6000 Firmware HIGH 7.5
CVE-2024-27356EPSS 24%

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user infor…

Mitigation only
Fix from $1,950 2024-02-27