Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Music HIGH 7.5
CVE-2022-32836

This issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sen…

Mitigation only
Fix from $1,950 2023-02-27
Ipados MEDIUM 5.5
CVE-2022-32855

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted co…

Fix: 15.6+
Fix from $1,600 2023-02-27
Rosariosis HIGH 7.5
CVE-2023-0994

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

Fix: 10.8.2+
Fix from $1,950 2023-02-24
Linux Kernel MEDIUM 5.5
CVE-2023-0597

A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location o…

Patch available
Fix from $1,600 2023-02-23
Codiad HIGH 7.5
CVE-2017-20178

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function s…

Patch available
Fix from $1,950 2023-02-21
Checkmk MEDIUM 5.5
CVE-2022-48319

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0…

Mitigation only
Fix from $1,600 2023-02-20
Pixelfed MEDIUM 5.3
CVE-2023-0901

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4.

Fix: 0.11.4+
Fix from $1,600 2023-02-18
Qradar Security Information And Event Manager HIGH 7.5
CVE-2022-34351

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see …

Fix: 7.4.3+
Fix from $1,950 2023-02-17
Maximo Application Suite HIGH 7.5
CVE-2022-41734

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message…

Patch available
Fix from $1,950 2023-02-17
Db2 HIGH 7.5
CVE-2022-43930

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log…

Patch available
Fix from $1,950 2023-02-17
Db2 HIGH 7.5
CVE-2022-43927

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a speciall…

Patch available
Fix from $1,950 2023-02-17
Gotham MEDIUM 5.3
CVE-2022-27891

Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have…

Fix: 3.22.10.4+
Fix from $1,600 2023-02-16
Sequelize HIGH 7.5
CVE-2023-22580

Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.

Fix: 6.28.1+
Fix from $1,950 2023-02-16
Sn Xvr3804e1 Firmware MEDIUM 6.5
CVE-2023-23458

Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request.

No fix yet
Fix from $1,600 2023-02-15
Businessobjects Business Intelligence Platform HIGH 7.1
CVE-2023-0020

SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is oth…

Mitigation only
Fix from $1,950 2023-02-14
Profile Builder MEDIUM 6.5
CVE-2023-0814

The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_met…

Fix: after 3.9.0
Fix from $1,600 2023-02-14
Agent HIGH 7.5
CVE-2022-45454

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161,…

Mitigation only
Fix from $1,950 2023-02-13
Android MEDIUM 5.5
CVE-2022-47367

In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges nee…

Mitigation only
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-47324

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

Mitigation only
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-47325

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

No fix yet
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-47326

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

Mitigation only
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-47328

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

No fix yet
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-47329

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

No fix yet
Fix from $1,600 2023-02-12
Android MEDIUM 5.5
CVE-2022-38686

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

Mitigation only
Fix from $1,600 2023-02-12
Bastion Access Manager HIGH 7.5
CVE-2023-23592

WALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information.

Fix: 3.0.16 / 4.0.3+
Fix from $1,950 2023-02-09
Android MEDIUM 5.5
CVE-2023-21435

Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address infor…

Mitigation only
Fix from $1,600 2023-02-09
Tinacms\/cli HIGH 7.5
CVE-2023-25164

Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 w…

Fix: 1.0.9+
Fix from $1,950 2023-02-08
Sds 3008 Firmware MEDIUM 5.3
CVE-2022-40691

An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A special…

Fix: after 2.1
Fix from $1,600 2023-02-07
Syft HIGH 7.5
CVE-2023-24827

syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure f…

Patch available
Fix from $1,950 2023-02-07
Imagemagick MEDIUM 6.5
CVE-2022-44268EPSS 90%

ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded …

No fix yet
Fix from $1,600 2023-02-06