Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Strapi HIGH 7.5
CVE-2023-34235

Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fields if one is using the `t(nu…

Fix: 4.10.8+
Fix from $1,950 2023-07-25
Strapi HIGH 7.1
CVE-2023-34093

Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attri…

Fix: 4.10.8+
Fix from $1,950 2023-07-25
Kubepi HIGH 7.5
CVE-2023-37916

KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 leak password hash of any user (…

Fix: 1.6.5+
Fix from $1,950 2023-07-21
Pimcore MEDIUM 6.5
CVE-2023-3819

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.

Fix: 10.6.4+
Fix from $1,600 2023-07-21
Hybrid Client MEDIUM 5.5
CVE-2023-32476

Dell Hybrid Client version 2.0 contains a Sensitive Data Exposure vulnerability. An unauthenticated malicious user on the device can access hard code…

Mitigation only
Fix from $1,600 2023-07-20
Essential Addons For Elementor MEDIUM 5.3
CVE-2023-3779

The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 d…

Fix: after 5.8.1
Fix from $1,600 2023-07-20
Cloud Pak For Data HIGH 7.5
CVE-2023-26026

Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…

Patch available
Fix from $1,950 2023-07-19
Cloud Pak For Data HIGH 7.5
CVE-2023-27877

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the …

Patch available
Fix from $1,950 2023-07-19
Infosphere Information Server MEDIUM 6.5
CVE-2023-35898

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in…

Patch available
Fix from $1,600 2023-07-19
Robotic Process Automation MEDIUM 5.3
CVE-2023-35900

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information…

Fix: after 23.0.5
Fix from $1,600 2023-07-19
Autosuggest HIGH 7.5
CVE-2021-4428EPSS 16%

A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. Affected by this vulnerabilit…

Fix: 4.0.1+
Fix from $1,950 2023-07-18
Royal Elementor Addons MEDIUM 5.3
CVE-2023-3709

The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to t…

Fix: after 1.3.70
Fix from $1,600 2023-07-18
Infosphere Information Server MEDIUM 5.3
CVE-2023-33857

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in f…

Patch available
Fix from $1,600 2023-07-17
Gitops Terraform Controller MEDIUM 6.5
CVE-2023-34236

Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerabilit…

Fix: 0.14.4+
Fix from $1,600 2023-07-14
Zabbix HIGH 7.5
CVE-2023-29450

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix S…

Fix: after 6.4.4
Fix from $1,950 2023-07-13
Analytics MEDIUM 5.3
CVE-2023-34131

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access…

Fix: 9.3.2+
Fix from $1,600 2023-07-13
Analytics MEDIUM 6.5
CVE-2023-34134

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to read adminis…

Fix: 9.3.2+
Fix from $1,600 2023-07-13
Teamcity MEDIUM 6.5
CVE-2023-38062

In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations

Fix: 2023.05.1+
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2022-46651

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Co…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Decidim HIGH 7.5
CVE-2023-34090

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…

Fix: 0.27.3+
Fix from $1,950 2023-07-11
Sharepoint Server HIGH 7.5
CVE-2023-33165

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2023-07-11
Windows 10 1507 MEDIUM 5.5
CVE-2023-33174

Windows Cryptographic Information Disclosure Vulnerability

Fix: 10.0.10240.20048 / 10.0.14393.6085+
Fix from $1,600 2023-07-11
Teams MEDIUM 6.5
CVE-2023-24881

Microsoft Teams Information Disclosure Vulnerability

Fix: 2.10.1+
Fix from $1,600 2023-07-11
Teampass HIGH 7.5
CVE-2023-3553

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Fix: 3.0.10+
Fix from $1,950 2023-07-08
Fedora HIGH 8.2
CVE-2023-35934

yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs m…

Fix: 2023.07.06 / 2023.07.06.185519+
Fix from $1,950 2023-07-06
Emui CRITICAL 9.8
CVE-2022-48510

Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.

No fix yet
Fix from $2,300 2023-07-06
Harmonyos HIGH 7.5
CVE-2022-48514

The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiali…

No fix yet
Fix from $1,950 2023-07-06
Emui HIGH 7.5
CVE-2022-48516

Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will aff…

Mitigation only
Fix from $1,950 2023-07-06
Emui HIGH 7.5
CVE-2022-48519

Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2023-07-06
Emui HIGH 7.5
CVE-2022-48520

Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2023-07-06