Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Learndash MEDIUM 5.3
CVE-2024-1210

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This mak…

Fix: 4.10.2+
Fix from $1,600 2024-02-05
Learndash MEDIUM 5.3
CVE-2024-1208EPSS 5%

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This mak…

Fix: 4.10.3+
Fix from $1,600 2024-02-05
Anonymous Restricted Content HIGH 7.5
CVE-2024-0909

The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is du…

Fix: after 1.6.2
Fix from $1,950 2024-02-03
Hcl Devops Deploy MEDIUM 5.5
CVE-2024-23550

HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.

Fix: 7.0.5.20 / 7.1.2.16+
Fix from $1,600 2024-02-03
Jspxcms MEDIUM 6.5
CVE-2024-1200

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /template…

No fix yet
Fix from $1,600 2024-02-03
Open Irs CRITICAL 9.8
CVE-2024-24757

open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally uploaded when working with g…

Fix: 1.0.1+
Fix from $2,300 2024-02-02
Group Membership Ip Blocks MEDIUM 5.3
CVE-2024-24755

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-mem…

Patch available
Fix from $1,600 2024-02-01
Payment Ex MEDIUM 6.5
CVE-2024-24548

Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise using Payme…

Fix: after 1.1.5b
Fix from $1,600 2024-02-01
Fedora HIGH 8.6
CVE-2024-21626EPSS 18%

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal fi…

Fix: 1.1.12+
Fix from $1,950 2024-01-31
Rebuild HIGH 7.5
CVE-2024-1098

A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file…

Fix: after 3.5.5
Fix from $1,950 2024-01-31
Servicecomb HIGH 7.5
CVE-2023-44312

Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Cente…

Fix: 2.2.0+
Fix from $1,950 2024-01-31
Vantage6 Ui MEDIUM 5.3
CVE-2024-22200

vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can…

Fix: 4.2.0+
Fix from $1,600 2024-01-30
Openbi HIGH 7.5
CVE-2024-1033

A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is the function agent of the file …

Fix: after 1.0.8
Fix from $1,950 2024-01-30
Image Source Control HIGH 7.5
CVE-2023-52187

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Thomas Maier Image Source Control Lite – Show Image Credits and Captions.…

Fix: after 2.17.0
Fix from $1,950 2024-01-27
Line MEDIUM 5.4
CVE-2023-48129

An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

No fix yet
Fix from $1,600 2024-01-26
Line MEDIUM 5.4
CVE-2023-48132

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of…

No fix yet
Fix from $1,600 2024-01-26
Line MEDIUM 5.4
CVE-2023-48135

An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

No fix yet
Fix from $1,600 2024-01-26
Line MEDIUM 5.4
CVE-2023-48130

An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

No fix yet
Fix from $1,600 2024-01-26
Line MEDIUM 5.4
CVE-2023-48131

An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access toke…

No fix yet
Fix from $1,600 2024-01-26
Lemmy MEDIUM 6.5
CVE-2024-23649

Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, ev…

Fix: 0.19.1+
Fix from $1,600 2024-01-24
Profile Builder HIGH 7.5
CVE-2024-22141

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: fr…

Fix: after 3.10.0
Fix from $1,950 2024-01-24
Salesking HIGH 7.5
CVE-2024-22154

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.…

Fix: after 1.6.15
Fix from $1,950 2024-01-24
Country Blocker HIGH 7.5
CVE-2024-22294

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Co…

Fix: 2.33.4+
Fix from $1,950 2024-01-24
Albo Pretorio Online HIGH 7.5
CVE-2024-22301

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On…

Fix: after 4.6.6
Fix from $1,950 2024-01-24
Line MEDIUM 5.4
CVE-2023-43996

An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

No fix yet
Fix from $1,600 2024-01-24
Line MEDIUM 5.4
CVE-2023-43997

An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access t…

No fix yet
Fix from $1,600 2024-01-24
Line MEDIUM 5.4
CVE-2023-43998

An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

No fix yet
Fix from $1,600 2024-01-24
Line MEDIUM 5.4
CVE-2023-43992

An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

No fix yet
Fix from $1,600 2024-01-24
Line MEDIUM 5.4
CVE-2023-43993

An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access to…

No fix yet
Fix from $1,600 2024-01-24
Line MEDIUM 5.4
CVE-2023-43994

An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tok…

No fix yet
Fix from $1,600 2024-01-24