Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Rack Cors Middleware CRITICAL 9.1
CVE-2024-27456

rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.

Patch available
Fix from $2,300 2024-02-26
Myshopkit MEDIUM 5.3
CVE-2024-1436

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issu…

Fix: after 1.0.9
Fix from $1,600 2024-02-26
Fedora MEDIUM 5.3
CVE-2024-21501

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allo…

Fix: 2.12.1+
Fix from $1,600 2024-02-24
Survey Tma HIGH 7.5
CVE-2024-24309

In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without rest…

Fix: after 2.0.0
Fix from $1,950 2024-02-23
Ethernet Controller I225 It Firmware MEDIUM 5.3
CVE-2021-33146

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticate…

Fix: 1.87 / 29.0.1+
Fix from $1,600 2024-02-23
Tuleap MEDIUM 6.5
CVE-2024-25130

Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edit…

Fix: 15.4-7 / 15.5-4+
Fix from $1,600 2024-02-22
Calendar MEDIUM 5.3
CVE-2024-24817

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discussion platform Discourse. Prior…

Fix: 0.4+
Fix from $1,600 2024-02-22
Electroncord HIGH 7.5
CVE-2024-26136

kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `confi…

Fix: 2024-02-19+
Fix from $1,950 2024-02-20
Emui HIGH 7.5
CVE-2023-52097

Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploitation of this vulnerability may affect service co…

No fix yet
Fix from $1,950 2024-02-18
Android MEDIUM 5.5
CVE-2024-0020

In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused …

Patch available
Fix from $1,600 2024-02-16
Fortianalyzer MEDIUM 5.0
CVE-2023-44253

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before…

Fix: after 7.2.3
Fix from $1,600 2024-02-15
Landing Page Cat MEDIUM 5.3
CVE-2024-0708

The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all…

Fix: 1.7.3+
Fix from $1,600 2024-02-15
Vxworks HIGH 7.5
CVE-2023-51787

An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory i…

Mitigation only
Fix from $1,950 2024-02-15
TYPO3 HIGH 7.1
CVE-2024-25121

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstra…

Fix: 8.7.57 / 9.5.46+
Fix from $1,950 2024-02-13
TYPO3 MEDIUM 6.5
CVE-2024-25118

TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms…

Fix: 8.7.57 / 9.5.46+
Fix from $1,600 2024-02-13
Dynamics 365 Business Central HIGH 8.0
CVE-2024-21380

Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability

Patch available
Fix from $1,950 2024-02-13
R7000 Firmware MEDIUM 6.5
CVE-2024-1431

A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of…

No fix yet
Fix from $1,600 2024-02-11
R7000 Firmware MEDIUM 6.5
CVE-2024-1430

A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown funct…

No fix yet
Fix from $1,600 2024-02-11
Wrt54gl Firmware HIGH 7.5
CVE-2024-1404

A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Mitigation only
Fix from $1,950 2024-02-09
Nonebot MEDIUM 6.5
CVE-2024-21624

nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. This security advisory pertains to a potential information leak…

Fix: 2.2.0+
Fix from $1,600 2024-02-09
Solr HIGH 7.5
CVE-2023-50298

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, fr…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Dirac HIGH 7.5
CVE-2024-24825

DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. This may ex…

Fix: 8.0.37+
Fix from $1,950 2024-02-09
Qolsys Iq Panel 4 Firmware CRITICAL 9.8
CVE-2024-0242

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

Fix: 4.4.2+
Fix from $2,300 2024-02-08
Nvt Web Server MEDIUM 5.3
CVE-2024-24215

An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a craf…

Mitigation only
Fix from $1,600 2024-02-08
Mailjet HIGH 7.5
CVE-2024-24304

In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical information without restriction.

Fix: 3.5.1+
Fix from $1,950 2024-02-07
Recovery Orchestrator HIGH 8.8
CVE-2024-22022

Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the se…

Fix: 7.0+
Fix from $1,950 2024-02-07
Sepidzdigitalmenu HIGH 7.5
CVE-2024-1255

A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic. This vulnerability affects unknown code of…

Fix: after 7.1.0728.1
Fix from $1,950 2024-02-06
Urbancode Deploy MEDIUM 5.5
CVE-2024-22331

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM…

Fix: 7.0.5.20 / 7.1.2.16+
Fix from $1,600 2024-02-06
Tuleap MEDIUM 6.5
CVE-2024-23344

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted informatio…

Fix: 15.3.5 / 15.4.99.140+
Fix from $1,600 2024-02-06
Learndash MEDIUM 5.3
CVE-2024-1209

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file a…

Fix: 4.10.3+
Fix from $1,600 2024-02-05