Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Moodle MEDIUM 5.3
CVE-2023-5545

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Label Studio HIGH 8.8
CVE-2023-43791

Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within t…

Fix: 1.8.2+
Fix from $1,950 2023-11-09
Couchbase Server HIGH 7.5
CVE-2023-45875

An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.

Mitigation only
Fix from $1,950 2023-11-08
Harmonyos HIGH 7.5
CVE-2023-46757

The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affec…

No fix yet
Fix from $1,950 2023-11-08
Emui HIGH 7.5
CVE-2023-44098

Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-11-08
Harmonyos HIGH 7.5
CVE-2023-44115

Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confiden…

No fix yet
Fix from $1,950 2023-11-08
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2023-4061

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from…

Fix: 15.0.30+
Fix from $1,600 2023-11-08
Yugabytedb HIGH 7.5
CVE-2023-6001

Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

Fix: 2.18.4.0+
Fix from $1,950 2023-11-08
Bifrost Gpu Kernel Driver MEDIUM 5.5
CVE-2023-4272

A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.

Mitigation only
Fix from $1,600 2023-11-07
One CRITICAL 9.8
CVE-2023-38547EPSS 19%

A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configur…

Patch available
Fix from $2,300 2023-11-07
Coldbox Elixir HIGH 7.5
CVE-2021-4430

A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaul…

Patch available
Fix from $1,950 2023-11-06
Robotic Process Automation For Cloud Pak MEDIUM 6.5
CVE-2023-45189

A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 m…

Fix: after 23.0.10
Fix from $1,600 2023-11-03
G 040w Q Firmware MEDIUM 5.3
CVE-2023-41354

Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit t…

Mitigation only
Fix from $1,600 2023-11-03
Request Tracker HIGH 7.5
CVE-2023-45024

Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

Fix: 5.0.5+
Fix from $1,950 2023-11-03
Request Tracker HIGH 7.5
CVE-2023-41259

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email …

Fix: 4.4.7 / 5.0.5+
Fix from $1,950 2023-11-03
Request Tracker HIGH 7.5
CVE-2023-41260

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.

Fix: 4.4.7 / 5.0.5+
Fix from $1,950 2023-11-03
D Copia253mf Plus Firmware MEDIUM 5.3
CVE-2023-34261EPSS 8%

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they lead to a…

Fix: after 2vg_s000.002.561
Fix from $1,600 2023-11-03
Line Mini App HIGH 7.5
CVE-2023-39057

An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

No fix yet
Fix from $1,950 2023-11-02
Line Mini App HIGH 7.5
CVE-2023-39042

An information leak in Gyouza-newhushimi v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

No fix yet
Fix from $1,950 2023-11-02
Line Mini App HIGH 7.5
CVE-2023-39047

An information leak in shouzu sweets oz v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

Patch available
Fix from $1,950 2023-11-02
Line Mini App HIGH 7.5
CVE-2023-39048

An information leak in Tokudaya.honten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

No fix yet
Fix from $1,950 2023-11-02
Line Mini App HIGH 7.5
CVE-2023-39050

An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

No fix yet
Fix from $1,950 2023-11-02
Line Mini App HIGH 7.5
CVE-2023-39051

An information leak in VISION MEAT WORKS Track Diner 10/10mbl v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

No fix yet
Fix from $1,950 2023-11-02
Line Mini App HIGH 7.5
CVE-2023-39053

An information leak in Hattoriya v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

No fix yet
Fix from $1,950 2023-11-02
Line Mini App HIGH 7.5
CVE-2023-39054

An information leak in Tokudaya.ekimae_mc v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

No fix yet
Fix from $1,950 2023-11-02
Esoms MEDIUM 5.3
CVE-2023-5516

Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about th…

Fix: after 6.3.13
Fix from $1,600 2023-11-01
Esoms MEDIUM 5.3
CVE-2023-5515

The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure o…

Fix: after 6.3.13
Fix from $1,600 2023-11-01
Fedora MEDIUM 5.3
CVE-2023-43796

Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Syn…

Fix: 1.95.1+
Fix from $1,600 2023-10-31
App Store App HIGH 7.5
CVE-2022-3611

An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to …

Fix: 11.8.0+
Fix from $1,950 2023-10-27
Ocomon HIGH 7.5
CVE-2023-33558

An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information…

Fix: 4.0.1+
Fix from $1,950 2023-10-26