Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Emui HIGH 7.5
CVE-2023-37239

Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the …

No fix yet
Fix from $1,950 2023-07-06
Emui CRITICAL 9.8
CVE-2021-46891

Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect servic…

No fix yet
Fix from $2,300 2023-07-05
Emui CRITICAL 9.1
CVE-2023-3455

Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.

No fix yet
Fix from $2,300 2023-07-05
Fastconnect 6700 Firmware MEDIUM 5.5
CVE-2023-21624

Information disclosure in DSP Services while loading dynamic module.

No fix yet
Fix from $1,600 2023-07-04
The King\'s Temple Church Website CRITICAL 9.1
CVE-2023-36817

`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repos…

Mitigation only
Fix from $2,300 2023-07-03
Meetings HIGH 7.5
CVE-2023-36539

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

No fix yet
Fix from $1,950 2023-06-30
Calamares Nixos Extensions MEDIUM 5.5
CVE-2023-36476

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions versio…

Fix: 0.3.13+
Fix from $1,600 2023-06-29
Android MEDIUM 5.5
CVE-2023-21237 KEV

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insuffic…

Mitigation only
Fix from $1,600 2023-06-28
Cloud Pak For Security HIGH 7.5
CVE-2023-30993

IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another ten…

Fix: after 1.9.2.0
Fix from $1,950 2023-06-27
Central Authentication Service HIGH 7.5
CVE-2023-28857

Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X50…

Fix: 6.5.9.1 / 6.6.6+
Fix from $1,950 2023-06-27
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2022-34352

IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned t…

Patch available
Fix from $1,600 2023-06-27
Shopware MEDIUM 5.3
CVE-2023-34098

Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript c…

Fix: 5.7.18+
Fix from $1,600 2023-06-27
Mainwp Child HIGH 7.5
CVE-2023-3132

The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient c…

Fix: after 4.4.1.1
Fix from $1,950 2023-06-27
Eft Server MEDIUM 5.3
CVE-2023-2991

Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Glo…

Fix: after 8.1.0.14
Fix from $1,600 2023-06-22
Vaadin MEDIUM 6.5
CVE-2023-25499

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0,…

Fix: 10.0.23 / 14.10.1+
Fix from $1,600 2023-06-22
Airflow MEDIUM 6.5
CVE-2023-35005

In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact…

Fix: 2.6.2+
Fix from $1,600 2023-06-19
Mattermost MEDIUM 6.5
CVE-2023-2792

Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg com…

Fix: after 7.9.3
Fix from $1,600 2023-06-16
Cilium MEDIUM 5.3
CVE-2023-34242

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to version 1.13.4, when Gateway API is enabled in Ci…

Fix: 1.13.4+
Fix from $1,600 2023-06-15
Commerce MEDIUM 5.3
CVE-2023-29287

Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability …

Mitigation only
Fix from $1,600 2023-06-15
Video Management System HIGH 7.7
CVE-2023-28175

Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted …

Fix: after 11.1.1
Fix from $1,950 2023-06-15
Security Directory Suite Va MEDIUM 6.5
CVE-2022-33159

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X…

Fix: after 8.0.1.19
Fix from $1,600 2023-06-15
Powervm Hypervisor HIGH 7.5
CVE-2023-25683

IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could all…

Mitigation only
Fix from $1,950 2023-06-15
Threat Response Auto Pull MEDIUM 6.8
CVE-2023-2820

An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an…

Fix: 5.10.0+
Fix from $1,600 2023-06-14
Traffic Server HIGH 7.5
CVE-2023-33933

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach…

Fix: 8.1.7 / 9.2.1+
Fix from $1,950 2023-06-14
Traffic Server HIGH 7.5
CVE-2022-47184

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach…

Fix: 8.1.7 / 9.2.1+
Fix from $1,950 2023-06-14
Ujcms MEDIUM 6.5
CVE-2023-3231

A vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown code of the component ZIP Packa…

Fix: after 6.0.2
Fix from $1,600 2023-06-14
Discourse MEDIUM 5.3
CVE-2023-34250

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passe…

Fix: 3.0.4+
Fix from $1,600 2023-06-13
Servicenow MEDIUM 6.5
CVE-2022-43684

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional…

No fix yet
Fix from $1,600 2023-06-13
Ak Em100 Firmware HIGH 7.5
CVE-2023-22586

The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter.

Fix: 2.2.0.12+
Fix from $1,950 2023-06-11
Ak Em100 Firmware MEDIUM 5.3
CVE-2023-25912

The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information s…

Fix: 2.2.0.12+
Fix from $1,600 2023-06-11