Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Grafana HIGH 8.8
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including …

Fix: 9.2.10 / 9.3.4+
Fix from $1,950 2023-02-03
Nvs 365 V01 Firmware HIGH 7.5
CVE-2022-47070

NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the second packag…

No fix yet
Fix from $1,950 2023-02-03
1704 Wgl Firmware HIGH 7.5
CVE-2023-0659

A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of…

Mitigation only
Fix from $1,950 2023-02-03
Re057 Firmware HIGH 7.5
CVE-2023-0658

A vulnerability, which was classified as critical, was found in Multilaser RE057 and RE170 2.1/2.2. This affects an unknown part of the file /param.f…

Mitigation only
Fix from $1,950 2023-02-03
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2021-22786

A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller wh…

Fix: 3.40+
Fix from $1,950 2023-02-01
Dast Api Scanner MEDIUM 6.5
CVE-2022-4206

A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization h…

Fix: 2.0.102+
Fix from $1,600 2023-02-01
Btcpay Server HIGH 7.5
CVE-2022-32984

BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive …

Fix: after 1.5.3
Fix from $1,950 2023-01-31
Ecostruxure Geo Scada Expert 2019 HIGH 7.5
CVE-2023-22611

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific mess…

Patch available
Fix from $1,950 2023-01-31
Metabase MEDIUM 6.3
CVE-2023-23629

Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashbo…

Fix: 0.43.7.1 / 0.44.6.1+
Fix from $1,600 2023-01-28
Discourse MEDIUM 5.3
CVE-2023-23620

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branc…

Fix: 3.0.1+
Fix from $1,600 2023-01-28
Discourse MEDIUM 5.3
CVE-2023-23624

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passe…

Fix: 3.0.1+
Fix from $1,600 2023-01-28
Contentstudio MEDIUM 5.3
CVE-2023-0557

The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unau…

Fix: 1.2.6+
Fix from $1,600 2023-01-27
Opensearch MEDIUM 6.5
CVE-2023-23613

OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implementation of field-level secur…

Fix: 1.3.8 / 2.5.0+
Fix from $1,600 2023-01-26
Cr6 Firmware CRITICAL 9.1
CVE-2023-0321

Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensiti…

No fix yet
Fix from $2,300 2023-01-26
GitLab MEDIUM 5.5
CVE-2022-4054

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all ver…

Fix: 15.4.6 / 15.5.5+
Fix from $1,600 2023-01-26
Vrealize Log Insight MEDIUM 5.3
CVE-2022-31711EPSS 22%

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and applicatio…

Fix: 8.10.2+
Fix from $1,600 2023-01-26
Mediawiki MEDIUM 5.3
CVE-2022-39193

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the p…

Patch available
Fix from $1,600 2023-01-20
Cloud Pak For Security MEDIUM 6.5
CVE-2021-39089

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafte…

Fix: after 1.10.6.0
Fix from $1,600 2023-01-20
Spectrum Virtualize MEDIUM 5.9
CVE-2022-39167

IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-t…

Patch available
Fix from $1,600 2023-01-19
Opentext Extended Ecm HIGH 7.5
CVE-2022-45925EPSS 17%

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this pa…

Fix: after 22.3
Fix from $1,950 2023-01-18
Emc Solutions Enabler Virtual Appliance MEDIUM 6.5
CVE-2022-45103

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A lo…

Fix: 9.2.3.6 / 9.2.3.12+
Fix from $1,600 2023-01-18
GitLab MEDIUM 6.5
CVE-2022-2907

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, …

Fix: 15.1.6 / 15.2.4+
Fix from $1,600 2023-01-17
Qradar Security Information And Event Manager HIGH 7.5
CVE-2023-22875

IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do …

Mitigation only
Fix from $1,950 2023-01-17
Freeradius HIGH 7.5
CVE-2022-41859

In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce …

Fix: 3.0.0+
Fix from $1,950 2023-01-17
Equipment Predictive Maintenance HIGH 7.5
CVE-2022-3091

RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an a…

Mitigation only
Fix from $1,950 2023-01-17
Eternal Terminal MEDIUM 5.3
CVE-2022-48258

In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.

Patch available
Fix from $1,600 2023-01-13
Ar7088h A Firmware MEDIUM 5.3
CVE-2022-46371

Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.

Fix: after 16.10.3
Fix from $1,600 2023-01-12
GitLab MEDIUM 5.3
CVE-2022-3870

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, …

Fix: 15.5.7 / 15.6.4+
Fix from $1,600 2023-01-12
Warp MEDIUM 5.5
CVE-2022-4457

Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker coul…

Fix: 6.20+
Fix from $1,600 2023-01-11
Systemd MEDIUM 5.5
CVE-2022-4415

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpab…

Fix: 253+
Fix from $1,600 2023-01-11