Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Elastic Cloud On Kubernetes MEDIUM 5.3
CVE-2023-31416

Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being a…

Fix: 2.8+
Fix from $1,600 2023-10-26
Line HIGH 7.5
CVE-2023-38845

An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

No fix yet
Fix from $1,950 2023-10-25
Line HIGH 7.5
CVE-2023-38846

An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

No fix yet
Fix from $1,950 2023-10-25
Line HIGH 7.5
CVE-2023-38847

An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

No fix yet
Fix from $1,950 2023-10-25
Line HIGH 7.5
CVE-2023-38849

An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

No fix yet
Fix from $1,950 2023-10-25
Ipados MEDIUM 6.8
CVE-2023-41988

This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPad…

Fix: 10.1 / 14.1+
Fix from $1,600 2023-10-25
Ipados MEDIUM 5.3
CVE-2023-42846

This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, tvOS 17.1, iOS 17.1 and …

Fix: 10.1 / 16.7.2+
Fix from $1,600 2023-10-25
Fides MEDIUM 6.5
CVE-2023-46125

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem…

Fix: 2.22.1+
Fix from $1,600 2023-10-25
Nautobot MEDIUM 6.5
CVE-2023-46128

Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobo…

Fix: 2.0.3+
Fix from $1,600 2023-10-25
Eisbaer Scada HIGH 7.5
CVE-2023-42490

EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Fix: after 3.0.6433.1964
Fix from $1,950 2023-10-25
Uomasa Saiji New HIGH 8.2
CVE-2023-39735

The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mess…

No fix yet
Fix from $1,950 2023-10-25
Fukunaga Memberscard HIGH 8.2
CVE-2023-39736

The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast m…

No fix yet
Fix from $1,950 2023-10-25
Matsuya HIGH 8.2
CVE-2023-39737

The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

No fix yet
Fix from $1,950 2023-10-25
Regina Sweets\&bakery HIGH 8.2
CVE-2023-39739

The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast m…

No fix yet
Fix from $1,950 2023-10-25
Stable Diffusion Webui Infinite Image Browsing HIGH 7.5
CVE-2023-46315

The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion w…

Fix: 5.0+
Fix from $1,950 2023-10-22
Social Media Share Buttons \& Social Sharing Icons MEDIUM 6.5
CVE-2023-5070

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inc…

Fix: 2.8.6+
Fix from $1,600 2023-10-20
Migration\, Backup\, Staging CRITICAL 9.3
CVE-2023-5576

The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.9…

Fix: after 0.9.91
Fix from $2,300 2023-10-20
Home Assistant MEDIUM 5.4
CVE-2023-41893

Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logg…

Fix: 2023.9.0+
Fix from $1,600 2023-10-20
Tauri MEDIUM 5.5
CVE-2023-46115

Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base it…

Fix: 2.0.0+
Fix from $1,600 2023-10-20
Dexgate MEDIUM 5.3
CVE-2023-42666

The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnerability, which may allow an attacker to cre…

Mitigation only
Fix from $1,600 2023-10-19
Wpbot MEDIUM 5.3
CVE-2023-5254

The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_chec…

Fix: 4.9.1+
Fix from $1,600 2023-10-19
Bentley Nevada 3500 System Firmware HIGH 7.5
CVE-2023-34437

Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could a…

Mitigation only
Fix from $1,950 2023-10-19
Comscale HIGH 7.5
CVE-2023-45912

WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underl…

No fix yet
Fix from $1,950 2023-10-18
R Seenet CRITICAL 9.8
CVE-2023-5642EPSS 17%

Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…

No fix yet
Fix from $2,300 2023-10-18
Firewall HIGH 7.5
CVE-2023-5552

A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewa…

Fix: after 19.5.3
Fix from $1,950 2023-10-18
Weblogic Server HIGH 7.5
CVE-2023-22086

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Patch available
Fix from $1,950 2023-10-17
HTTP Server HIGH 7.5
CVE-2023-22019

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12…

Patch available
Fix from $1,950 2023-10-17
Mattermost Desktop MEDIUM 5.5
CVE-2023-5339

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including pa…

Fix: after 5.4.0
Fix from $1,600 2023-10-17
Traffic Server HIGH 7.5
CVE-2023-41752

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.…

Fix: 8.1.9 / 9.2.3+
Fix from $1,950 2023-10-17
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2021-38859

IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that co…

Fix: 11.5+
Fix from $1,600 2023-10-17