Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Dolphinscheduler HIGH 7.5
CVE-2023-49068

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: befor…

Fix: 3.2.1+
Fix from $1,950 2023-11-27
Dolphinscheduler HIGH 7.5
CVE-2023-48796

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors …

Fix: 3.0.2+
Fix from $1,950 2023-11-24
Email Marketing For Woocommerce HIGH 7.5
CVE-2023-47244

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend.This issue affects E…

Fix: 1.13.9+
Fix from $1,950 2023-11-23
Cloud Templates \& Patterns Collection HIGH 7.5
CVE-2023-47529

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud …

Fix: 1.2.3+
Fix from $1,950 2023-11-23
Pandora Fms MEDIUM 6.5
CVE-2023-41786

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users…

Fix: 773+
Fix from $1,600 2023-11-23
Storm MEDIUM 5.5
CVE-2023-43123

On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set th…

Fix: 2.6.0+
Fix from $1,600 2023-11-23
Booster For Woocommerce MEDIUM 6.5
CVE-2023-40002

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce plugin <= 7.1.1 versions.

Fix: after 7.1.1
Fix from $1,600 2023-11-23
Restrict Content HIGH 7.5
CVE-2023-47668

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.

Fix: after 3.2.7
Fix from $1,950 2023-11-23
Wp Client Reports MEDIUM 6.5
CVE-2023-23978

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions.

Fix: 1.0.17+
Fix from $1,600 2023-11-23
Devolutions Server MEDIUM 5.3
CVE-2023-6264

Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker to list the configured Devolut…

Fix: 2023.3.8.0+
Fix from $1,600 2023-11-22
Cloud Pak For Security MEDIUM 6.5
CVE-2022-36777

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0could allow an authenticated us…

Fix: 1.10.17.0+
Fix from $1,600 2023-11-22
Userpro MEDIUM 6.5
CVE-2023-2446

The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1…

Fix: 5.1.2+
Fix from $1,600 2023-11-22
Mercedes Me MEDIUM 5.3
CVE-2023-47392

An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order re…

Fix: after 1.34.0
Fix from $1,600 2023-11-22
Mercedes Me MEDIUM 5.3
CVE-2023-47393

An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of other users and access sensitive …

Fix: after 1.34.0
Fix from $1,600 2023-11-22
Graph Api HIGH 7.5
CVE-2023-49103 KEVEPSS 78%

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.…

Mitigation only
Fix from $1,950 2023-11-21
Syrus 4g Iot Telematics Gateway Firmware CRITICAL 9.8
CVE-2023-6248

The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex…

Mitigation only
Fix from $2,300 2023-11-21
Suitecrm MEDIUM 5.3
CVE-2023-47643

SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentic…

Patch available
Fix from $1,600 2023-11-21
Manageengine Analytics Plus MEDIUM 5.5
CVE-2023-6105

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged O…

Fix: 2.0.0 / 5.3+
Fix from $1,600 2023-11-15
Endpoint Manager Mobile CRITICAL 9.1
CVE-2023-39337

A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access …

Fix: 11.10.0.4 / 11.11.0.2+
Fix from $2,300 2023-11-15
TYPO3 MEDIUM 5.3
CVE-2023-47126

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone i…

Fix: 12.4.8+
Fix from $1,600 2023-11-14
Aptio V Uefi Firmware Integrator Tools MEDIUM 5.5
CVE-2023-28723

Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user t…

Mitigation only
Fix from $1,600 2023-11-14
Unison Software MEDIUM 5.5
CVE-2022-46646

Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enable infor…

Fix: 20.14.2.3053 / 20.14.4244+
Fix from $1,600 2023-11-14
Fortisiem MEDIUM 6.5
CVE-2023-41676

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with acces…

Fix: after 6.7.5
Fix from $1,600 2023-11-14
System Center Operations Manager MEDIUM 6.5
CVE-2023-36043

Open Management Infrastructure Information Disclosure Vulnerability

Patch available
Fix from $1,600 2023-11-14
Label Studio HIGH 7.5
CVE-2023-47117

Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insec…

Fix: 1.9.2+
Fix from $1,950 2023-11-13
Maiwei Safety Production Control Platform MEDIUM 5.3
CVE-2023-6100

A vulnerability classified as problematic was found in Maiwei Safety Production Control Platform 4.1. This vulnerability affects unknown code of the …

Mitigation only
Fix from $1,600 2023-11-13
Maiwei Safety Production Control Platform HIGH 7.5
CVE-2023-6101

A vulnerability, which was classified as problematic, has been found in Maiwei Safety Production Control Platform 4.1. This issue affects some unknow…

Mitigation only
Fix from $1,950 2023-11-13
Airflow MEDIUM 6.5
CVE-2023-42781

Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat…

Fix: 2.7.3+
Fix from $1,600 2023-11-12
Restaurant Table Booking System HIGH 7.5
CVE-2023-6076

A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown f…

Mitigation only
Fix from $1,950 2023-11-10
Encoreanywhere HIGH 7.5
CVE-2018-8863

The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.

Fix: after 2.36.3.3
Fix from $1,950 2023-11-09