Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2022-43889

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att…

Fix: 11.5+
Fix from $1,600 2023-10-17
Simple Download Button Shortcode HIGH 7.5
CVE-2012-10016

A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPress. Affected is an unknown f…

Patch available
Fix from $1,950 2023-10-17
Discourse MEDIUM 5.3
CVE-2023-44391

Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_p…

Fix: after 3.1.1
Fix from $1,600 2023-10-16
Discourse HIGH 7.5
CVE-2023-45131

Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus.…

Fix: after 3.1.1
Fix from $1,950 2023-10-16
Otrs MEDIUM 5.3
CVE-2023-38059

The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to ret…

Fix: 7.0.47 / 8.0.37+
Fix from $1,600 2023-10-16
Security Verify Access Oidc Provider MEDIUM 5.3
CVE-2022-43868

IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-…

Patch available
Fix from $1,600 2023-10-14
Sandbox MEDIUM 6.5
CVE-2023-5579

A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

No fix yet
Fix from $1,600 2023-10-14
Airflow MEDIUM 6.5
CVE-2023-42780

Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, …

Fix: 2.7.2+
Fix from $1,600 2023-10-14
Airflow MEDIUM 6.5
CVE-2023-42663

Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat…

Fix: 2.7.2+
Fix from $1,600 2023-10-14
Junos Os Evolved MEDIUM 5.5
CVE-2023-44187

An Exposure of Sensitive Information vulnerability in the 'file copy' command of Junos OS Evolved allows a local, authenticated attacker with shell a…

Fix: 20.4+
Fix from $1,600 2023-10-11
Harmonyos HIGH 7.5
CVE-2023-44097

Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerability may affect service confid…

No fix yet
Fix from $1,950 2023-10-11
Harmonyos HIGH 7.5
CVE-2023-44093

Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect servic…

No fix yet
Fix from $1,950 2023-10-11
Windows Server 2008 HIGH 7.5
CVE-2023-29348

Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability

Patch available
Fix from $1,950 2023-10-10
Next Gen Application Firewall MEDIUM 6.5
CVE-2023-30804EPSS 13%

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authentica…

No fix yet
Fix from $1,600 2023-10-10
Collaborative Lifecycle Management MEDIUM 5.5
CVE-2022-34355

IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a us…

Mitigation only
Fix from $1,600 2023-10-06
Urllib3 HIGH 8.1
CVE-2023-43804

urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing…

Fix: 1.26.17 / 2.0.6+
Fix from $1,950 2023-10-04
Openshift Data Science HIGH 7.5
CVE-2023-3361

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads…

Fix: 1.28.1+
Fix from $1,950 2023-10-04
Quarkus HIGH 7.5
CVE-2023-1584

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, w…

Fix: 2.13.8+
Fix from $1,950 2023-10-04
Disconnected Log Collector HIGH 7.5
CVE-2022-22447

IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclose unintended information. I…

Fix: 1.8.3+
Fix from $1,950 2023-10-04
Ibermatica Rps HIGH 7.5
CVE-2023-3349

Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, …

Mitigation only
Fix from $1,950 2023-10-03
Netman 204 Firmware HIGH 7.5
CVE-2022-47892

All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credenti…

Mitigation only
Fix from $1,950 2023-10-03
Drupal HIGH 7.5
CVE-2023-5256

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cac…

Fix: 9.5.11 / 10.0.11+
Fix from $1,950 2023-09-28
Jumpserver HIGH 8.2
CVE-2023-42820EPSS 5%

JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly…

Fix: 2.28.19 / 3.6.5+
Fix from $1,950 2023-09-27
Glpi MEDIUM 6.5
CVE-2023-41321

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $1,600 2023-09-27
Glpi MEDIUM 5.3
CVE-2023-41323EPSS 34%

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $1,600 2023-09-27
Ws Ftp Server MEDIUM 5.3
CVE-2023-40049

In WS_FTP Server version prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing.

Fix: 8.8.2+
Fix from $1,600 2023-09-27
Protection Engine MEDIUM 6.5
CVE-2023-23958

Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.

Fix: 9.1.0+
Fix from $1,600 2023-09-27
Docker Desktop MEDIUM 6.5
CVE-2023-5166

Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.

Fix: 4.23.0+
Fix from $1,600 2023-09-25
Emui HIGH 7.5
CVE-2023-41293

Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2023-09-25
Openstack Platform MEDIUM 5.5
CVE-2023-1633

A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce…

Mitigation only
Fix from $1,600 2023-09-24