Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mivoice Connect HIGH 7.5
CVE-2023-39289

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to con…

Fix: after 9.6.2208.101
Fix from $1,950 2023-08-25
Freighter MEDIUM 6.5
CVE-2023-40580

Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet …

Fix: 5.3.1+
Fix from $1,600 2023-08-25
Cp Vnr 3104 Firmware HIGH 7.5
CVE-2023-3705

The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthent…

Patch available
Fix from $1,950 2023-08-24
Iologik E4200 Firmware MEDIUM 5.3
CVE-2023-4230

A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate th…

Fix: after 1.6
Fix from $1,600 2023-08-24
Airflow HIGH 8.1
CVE-2023-37379

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…

Fix: 2.7.0+
Fix from $1,950 2023-08-23
Ak Sm 800a Firmware HIGH 7.5
CVE-2023-25913

Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP ad…

Fix: after 3.3
Fix from $1,950 2023-08-21
Butterfly Button HIGH 7.5
CVE-2023-40735

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) …

Fix: after 2023-08-21
Fix from $1,950 2023-08-21
Acymailing MEDIUM 5.3
CVE-2023-39974

Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of sub…

Fix: 8.7.0+
Fix from $1,600 2023-08-17
Gogs MEDIUM 5.3
CVE-2023-40348

The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its outp…

Fix: after 1.0.15
Fix from $1,600 2023-08-16
Powerscale Onefs HIGH 7.8
CVE-2023-32495

Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker…

Fix: after 9.5.0.3
Fix from $1,950 2023-08-16
Infinitewp Client MEDIUM 5.3
CVE-2023-2916EPSS 24%

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_no…

Fix: 1.12.1+
Fix from $1,600 2023-08-15
Android MEDIUM 5.5
CVE-2023-21267

In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the c…

Mitigation only
Fix from $1,600 2023-08-14
Yaklang HIGH 7.5
CVE-2023-40023

yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file inclusion (LFI) vulnerability. Th…

Patch available
Fix from $1,950 2023-08-14
Emui HIGH 7.5
CVE-2023-39393

Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources…

Mitigation only
Fix from $1,950 2023-08-13
Emui HIGH 7.5
CVE-2023-39383

Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' d…

No fix yet
Fix from $1,950 2023-08-13
Avalanche HIGH 7.5
CVE-2023-32561

A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypa…

Fix: 6.4.1+
Fix from $1,950 2023-08-10
Acrobat Dc MEDIUM 5.5
CVE-2023-38245

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An u…

Fix: 20.005.30514.10514 / 20.005.30516.10516+
Fix from $1,600 2023-08-10
Opentelemetry Instrumentation For Java MEDIUM 6.5
CVE-2023-39951

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumenta…

Fix: 1.28.0+
Fix from $1,600 2023-08-08
Windows 10 MEDIUM 6.5
CVE-2023-36908

Windows Hyper-V Information Disclosure Vulnerability

Fix: 10.0.10240.20107 / 10.0.14393.6167+
Fix from $1,600 2023-08-08
Sharepoint Server MEDIUM 6.5
CVE-2023-36894

Microsoft SharePoint Server Information Disclosure Vulnerability

Patch available
Fix from $1,600 2023-08-08
Empowerid MEDIUM 5.7
CVE-2023-4177

A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknown processing of the component…

Fix: after 7.205.0.0
Fix from $1,600 2023-08-06
Adlisting HIGH 7.5
CVE-2023-4168EPSS 46%

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-…

No fix yet
Fix from $1,950 2023-08-05
Airflow HIGH 8.8
CVE-2023-39508

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apach…

Fix: 2.6.0+
Fix from $1,950 2023-08-05
Metersphere HIGH 7.5
CVE-2023-38494

MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not ha…

Fix: 2.10.4+
Fix from $1,950 2023-08-04
Wp Ultimate Csv Importer HIGH 7.5
CVE-2023-4139

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction i…

Fix: after 7.9.8
Fix from $1,950 2023-08-04
Open Xchange Appsuite Office MEDIUM 5.5
CVE-2023-26441

Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker wi…

Fix: 8.11+
Fix from $1,600 2023-08-02
Brocade Fabric Operating System MEDIUM 5.3
CVE-2023-31927

An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauth…

Fix: 9.1.1c+
Fix from $1,600 2023-08-02
Music MEDIUM 5.5
CVE-2023-28203

The issue was addressed with improved checks. This issue is fixed in Apple Music 4.2.0 for Android. An app may be able to access contacts.

Fix: 4.2.0+
Fix from $1,600 2023-07-28
Directus MEDIUM 6.5
CVE-2023-38503

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permissi…

Fix: 10.5.0+
Fix from $1,600 2023-07-25
TYPO3 MEDIUM 5.3
CVE-2023-38499

TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, …

Fix: 9.5.42 / 10.4.39+
Fix from $1,600 2023-07-25