Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mattermost Server MEDIUM 5.3
CVE-2023-1777

Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the con…

Fix: 7.1.6+
Fix from $1,600 2023-03-31
Grade Point Average \(gpa\) Calculator HIGH 7.5
CVE-2023-1769

A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0. Affected is an unknown func…

Mitigation only
Fix from $1,950 2023-03-31
Flow X\/m Firmware MEDIUM 5.3
CVE-2023-1258

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) all…

Fix: after 3.2.6
Fix from $1,600 2023-03-31
Acymailing HIGH 7.5
CVE-2023-28732

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access…

Fix: 8.3.0+
Fix from $1,950 2023-03-30
Haproxy HIGH 7.5
CVE-2023-0836

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 …

Fix: 2.2.27+
Fix from $1,950 2023-03-29
Xunruicms HIGH 7.5
CVE-2023-1680

A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayr…

No fix yet
Fix from $1,950 2023-03-29
Intellij Idea HIGH 7.5
CVE-2022-48430

In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.

Fix: 2023.1+
Fix from $1,950 2023-03-29
Xunruicms HIGH 7.5
CVE-2023-1683

A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/…

No fix yet
Fix from $1,950 2023-03-29
Xunruicms HIGH 7.5
CVE-2023-1681

A vulnerability, which was classified as problematic, was found in Xunrui CMS 4.61. Affected is an unknown function of the file /config/myfield/test.…

No fix yet
Fix from $1,950 2023-03-28
Veracode MEDIUM 5.5
CVE-2023-25722

A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured…

Fix: 23.3.19.0+
Fix from $1,600 2023-03-28
Emui HIGH 7.5
CVE-2022-48346

The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2023-03-27
Emui HIGH 7.5
CVE-2022-48347

The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2023-03-27
Emui CRITICAL 9.1
CVE-2022-48348

The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and …

No fix yet
Fix from $2,300 2023-03-27
Powerstation Firmware CRITICAL 9.8
CVE-2023-24838

HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the admini…

Mitigation only
Fix from $2,300 2023-03-27
Angular Server Side Configuration HIGH 7.5
CVE-2023-28444

angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables.…

Fix: 15.1.0+
Fix from $1,950 2023-03-24
Android HIGH 7.5
CVE-2023-21067

Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/A

No fix yet
Fix from $1,950 2023-03-24
Geonode MEDIUM 5.3
CVE-2023-28442

GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Prior to versions 2.20.6, 2.19.6…

Fix: 2.18.7 / 2.19.6+
Fix from $1,600 2023-03-24
Catalyst Center HIGH 8.8
CVE-2023-20055

A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the w…

Fix: 2.3.3.6+
Fix from $1,950 2023-03-23
Minio HIGH 7.5
CVE-2023-28432 KEVEPSS 84%

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T2…

Fix: 2023-03-20t20-16-18z+
Fix from $1,950 2023-03-22
Kinghistorian HIGH 7.5
CVE-2022-45124EPSS 13%

An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted …

No fix yet
Fix from $1,950 2023-03-20
Miniflux HIGH 7.5
CVE-2023-27591

Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instan…

Fix: 2.0.43+
Fix from $1,950 2023-03-17
Rooms HIGH 7.5
CVE-2023-22880

Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 c…

Fix: 5.13.1 / 5.13.3+
Fix from $1,950 2023-03-16
Android MEDIUM 5.5
CVE-2023-21449

Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information with…

Mitigation only
Fix from $1,600 2023-03-16
Robotic Process Automation MEDIUM 6.5
CVE-2023-25680

IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obf…

Fix: 21.0.6+
Fix from $1,600 2023-03-15
Spectrum Scale HIGH 8.2
CVE-2020-4927

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary d…

Fix: 5.1.7.0+
Fix from $1,950 2023-03-15
Sterling B2b Integrator MEDIUM 6.5
CVE-2023-22876

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive in…

Fix: 6.0.3.8 / 6.1.2.2+
Fix from $1,600 2023-03-15
Ajax Search HIGH 7.5
CVE-2022-38456

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.

Fix: after 4.10.3
Fix from $1,950 2023-03-15
Onedrive MEDIUM 5.5
CVE-2023-24923

Microsoft OneDrive for Android Information Disclosure Vulnerability

Fix: 6.73+
Fix from $1,600 2023-03-14
Onedrive MEDIUM 5.5
CVE-2023-24882

Microsoft OneDrive for Android Information Disclosure Vulnerability

Fix: 6.73+
Fix from $1,600 2023-03-14
Businessobjects Business Intelligence MEDIUM 5.3
CVE-2023-27894

SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameter…

Mitigation only
Fix from $1,600 2023-03-14