Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Business Intelligence MEDIUM 5.0
CVE-2024-20904

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are…

Patch available
Fix from $1,600 2024-01-16
Edk2 HIGH 7.5
CVE-2023-45236

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unaut…

Fix: after 202311
Fix from $1,950 2024-01-16
T8 Firmware CRITICAL 9.1
CVE-2024-0569

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /…

No fix yet
Fix from $2,300 2024-01-16
Emui CRITICAL 9.1
CVE-2023-52101

Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.

No fix yet
Fix from $2,300 2024-01-16
Emui HIGH 7.5
CVE-2023-44112

Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2024-01-16
Solr MEDIUM 6.5
CVE-2023-50290EPSS 68%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment v…

Fix: 9.3.0+
Fix from $1,600 2024-01-15
Huaxia Erp HIGH 7.5
CVE-2024-0490

A vulnerability was found in Huaxia ERP up to 3.1. It has been rated as problematic. This issue affects some unknown processing of the file /user/get…

Fix: after 3.1
Fix from $1,950 2024-01-13
Dormitory Management System HIGH 7.5
CVE-2024-0472

A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue affects some unknown process…

Mitigation only
Fix from $1,950 2024-01-12
H8951 4g Esp Firmware HIGH 7.5
CVE-2023-49261

The "tokenKey" value used in user authorization is visible in the HTML source of the login page.

Fix: 2310271149+
Fix from $1,950 2024-01-12
Backup Migration HIGH 7.5
CVE-2023-6266

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP…

Fix: after 1.3.6
Fix from $1,950 2024-01-11
macOS MEDIUM 5.5
CVE-2023-41987

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.

Fix: 14.0+
Fix from $1,600 2024-01-10
macOS MEDIUM 5.5
CVE-2023-42829

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey …

Fix: 11.7.9 / 12.6.8+
Fix from $1,600 2024-01-10
Safari MEDIUM 6.5
CVE-2023-40385

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker …

Fix: 14.0 / 17.0+
Fix from $1,600 2024-01-10
macOS MEDIUM 5.5
CVE-2023-40411

This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive data.

Fix: 14.0+
Fix from $1,600 2024-01-10
macOS MEDIUM 5.5
CVE-2022-32931

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access pr…

Fix: 13.0+
Fix from $1,600 2024-01-10
Windows 10 1507 MEDIUM 6.5
CVE-2024-21320EPSS 23%

Windows Themes Spoofing Vulnerability

Fix: 10.0.10240.20402 / 10.0.14393.6614+
Fix from $1,600 2024-01-09
Linux Kernel MEDIUM 5.5
CVE-2024-0340

A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed…

Fix: 6.4+
Fix from $1,600 2024-01-09
Advanced Custom Fields HIGH 7.5
CVE-2022-40696

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom…

Fix: after 6.0.2
Fix from $1,950 2024-01-08
Download Monitor HIGH 7.5
CVE-2022-45354EPSS 38%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a th…

Fix: after 4.7.60
Fix from $1,950 2024-01-08
Fastdup HIGH 7.5
CVE-2023-51406

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue …

Fix: after 2.1.7
Fix from $1,950 2024-01-08
Constant Contact Forms HIGH 7.5
CVE-2023-52208

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Conta…

Fix: after 2.4.2
Fix from $1,950 2024-01-08
Coupon Referral Program HIGH 7.5
CVE-2023-52190

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Prog…

Fix: after 1.7.2
Fix from $1,950 2024-01-08
Ncast HIGH 7.5
CVE-2024-0305EPSS 67%

A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some un…

Fix: after 2017
Fix from $1,950 2024-01-08
Send Users Email MEDIUM 5.3
CVE-2023-52126

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Suman Bhattarai Send Users Email.This issue affects Send Users Email: fro…

Fix: after 1.4.3
Fix from $1,600 2024-01-05
Affiliates Manager MEDIUM 5.3
CVE-2023-52148

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliat…

Fix: after 2.9.30
Fix from $1,600 2024-01-05
Uncanny Automator MEDIUM 5.3
CVE-2023-52151

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything wi…

Fix: after 5.1.0.2
Fix from $1,600 2024-01-05
Jizhicms CRITICAL 9.8
CVE-2023-51154

Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

No fix yet
Fix from $2,300 2024-01-04
Laf MEDIUM 6.5
CVE-2023-50253

Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container witho…

Patch available
Fix from $1,600 2024-01-03
Cubefs CRITICAL 9.8
CVE-2023-46741

CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read …

Fix: 3.3.1+
Fix from $2,300 2024-01-03
Android MEDIUM 5.5
CVE-2023-4164

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no …

Mitigation only
Fix from $1,600 2024-01-02