Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Businessobjects Business Intelligence HIGH 7.2
CVE-2023-28762

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the log…

Mitigation only
Fix from $1,950 2023-05-09
Ghost HIGH 7.5
CVE-2023-31133EPSS 46%

Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Pri…

Fix: 5.46.1+
Fix from $1,950 2023-05-08
Ncr\/camera Firmware HIGH 7.5
CVE-2023-24505

Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.

No fix yet
Fix from $1,950 2023-05-08
Couchdb MEDIUM 5.3
CVE-2023-26268

Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design d…

Fix: 3.2.3 / 3.3.2+
Fix from $1,600 2023-05-02
Confluence Data Center MEDIUM 5.3
CVE-2023-22503

Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a pr…

Fix: 7.13.15 / 7.19.7+
Fix from $1,600 2023-05-01
Build Action MEDIUM 6.5
CVE-2023-30853

Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradl…

Fix: 2.4.2+
Fix from $1,600 2023-04-28
Dx5401 B0 Firmware HIGH 7.5
CVE-2023-28770EPSS 58%

The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(AB…

Fix: 5.17+
Fix from $1,950 2023-04-27
Payload MEDIUM 6.5
CVE-2023-30843

Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidd…

Fix: 1.7.0+
Fix from $1,600 2023-04-26
Baremetal Operator MEDIUM 5.5
CVE-2023-30841

Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed w…

Fix: 0.3.0+
Fix from $1,600 2023-04-26
Grafana HIGH 7.5
CVE-2023-1387

Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a J…

Fix: 9.2.17 / 9.3.13+
Fix from $1,950 2023-04-26
Solarwinds Platform MEDIUM 6.5
CVE-2023-23839

The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCo…

Fix: 2023.2.0+
Fix from $1,600 2023-04-25
White Rabbit Switch Firmware HIGH 7.5
CVE-2023-22577

Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community …

Fix: after 6.0.1
Fix from $1,950 2023-04-24
Reactions MEDIUM 5.3
CVE-2023-30611

Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data ab…

Patch available
Fix from $1,600 2023-04-19
Xwiki HIGH 7.5
CVE-2023-29517

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office document viewer macro was allowin…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19
Debian Linux MEDIUM 5.3
CVE-2023-26049

Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookie…

Fix: 9.4.51 / 10.0.14+
Fix from $1,600 2023-04-18
Checkmk Appliance Firmware MEDIUM 5.5
CVE-2023-22307

Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.

Fix: 1.6.4+
Fix from $1,600 2023-04-18
Mattermost Server HIGH 7.5
CVE-2023-1831

Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental …

Fix: 7.7.3 / 7.8.2+
Fix from $1,950 2023-04-17
Cmdb MEDIUM 6.5
CVE-2022-34125

front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in th…

Fix: 3.0.3+
Fix from $1,600 2023-04-16
Spring Session MEDIUM 6.5
CVE-2023-20866

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to thos…

Mitigation only
Fix from $1,600 2023-04-13
Windows 10 1507 MEDIUM 5.5
CVE-2023-28271

Windows Kernel Memory Information Disclosure Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,600 2023-04-11
Windows 10 1507 HIGH 7.0
CVE-2023-28221

Windows Error Reporting Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,950 2023-04-11
Fortinac HIGH 7.5
CVE-2022-43951

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, …

Fix: 7.2.0 / 9.4.2+
Fix from $1,950 2023-04-11
Simatic Ipc647d Firmware MEDIUM 6.3
CVE-2023-23588

A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on…

Fix: 4.09.00.25611+
Fix from $1,600 2023-04-11
Businessobjects Business Intelligence CRITICAL 9.8
CVE-2023-28765EPSS 15%

An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to…

Mitigation only
Fix from $2,300 2023-04-11
Exit Strategy HIGH 7.5
CVE-2013-10024

A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this vulnerability is an unknown …

Patch available
Fix from $1,950 2023-04-08
GitLab MEDIUM 5.3
CVE-2023-1710

A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to …

Fix: 15.8.5 / 15.9.4+
Fix from $1,600 2023-04-05
Earnings And Expense Tracker App HIGH 7.5
CVE-2023-1858

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part…

Mitigation only
Fix from $1,950 2023-04-05
Samba MEDIUM 6.5
CVE-2023-0614

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may b…

Fix: 4.16.10 / 4.17.7+
Fix from $1,600 2023-04-03
Simple Task Allocation System HIGH 7.5
CVE-2023-1790

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Task Allocation System 1.0. Affected is an unknown function …

Mitigation only
Fix from $1,950 2023-04-01
Mattermost Server MEDIUM 6.5
CVE-2023-1775

When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all use…

Fix: 7.1.6+
Fix from $1,600 2023-03-31