Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Linux Kernel MEDIUM 5.5
CVE-2022-4543

A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via p…

No fix yet
Fix from $1,600 2023-01-11
Travel Support Program HIGH 7.5
CVE-2022-46163

Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Ha…

Fix: 2022-11-29+
Fix from $1,950 2023-01-10
Bank Account Management MEDIUM 5.7
CVE-2023-0023

In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directl…

Mitigation only
Fix from $1,600 2023-01-10
Weave Gitops MEDIUM 6.0
CVE-2022-23509

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps r…

Fix: 0.12.0+
Fix from $1,600 2023-01-09
Netcore Router Firmware HIGH 7.5
CVE-2023-0113

A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown func…

Mitigation only
Fix from $1,950 2023-01-07
Ryde HIGH 8.8
CVE-2022-42979EPSS 24%

Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an acc…

Mitigation only
Fix from $1,950 2023-01-06
Discourse MEDIUM 5.3
CVE-2023-22453

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-p…

Fix: 2.8.14+
Fix from $1,600 2023-01-05
Discourse MEDIUM 5.5
CVE-2022-23546

In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, poss…

Fix: 2.9.0+
Fix from $1,600 2023-01-05
Robotic Process Automation MEDIUM 5.3
CVE-2022-43573

IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level object…

Fix: 21.0.7+
Fix from $1,600 2023-01-05
Artaxerxes HIGH 7.5
CVE-2022-4869

A vulnerability was found in Evolution Events Artaxerxes. It has been declared as problematic. This vulnerability affects unknown code of the file ar…

Fix: 2022-08-12+
Fix from $1,950 2023-01-05
Clearpass Policy Manager MEDIUM 5.5
CVE-2022-43540

A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensit…

Fix: 6.9.12 / 6.10.7+
Fix from $1,600 2023-01-05
Sterling B2b Integrator MEDIUM 6.5
CVE-2022-22337

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive information to an authenticated user. IBM X-Force ID: …

Fix: 6.0.3.7 / 6.1.0.6+
Fix from $1,600 2023-01-04
Connect HIGH 7.5
CVE-2022-46081

In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of private personal information. N…

No fix yet
Fix from $1,950 2023-01-04
Wp Print Friendly HIGH 7.5
CVE-2013-10007

A vulnerability classified as problematic has been found in ethitter WP-Print-Friendly up to 0.5.2. This affects an unknown part of the file wp-print…

Fix: 0.5.3+
Fix from $1,950 2023-01-03
Octopus Server HIGH 7.5
CVE-2022-3460

In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed in variab…

Fix: 2022.3.10750 / 2022.4.8063+
Fix from $1,950 2023-01-03
Gpu Display Driver MEDIUM 6.1
CVE-2022-34674

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than …

Fix: 11.11 / 13.6+
Fix from $1,600 2022-12-30
Nomad MEDIUM 5.3
CVE-2019-14802

HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GH…

Fix: 0.9.5+
Fix from $1,600 2022-12-26
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2019-18177

In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This aff…

Fix: 13.0-58.30+
Fix from $1,600 2022-12-26
Mediawiki MEDIUM 5.3
CVE-2022-41767

An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are…

Fix: 1.35.8 / 1.37.5+
Fix from $1,600 2022-12-26
Thunderbird HIGH 8.1
CVE-2022-45414

If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER att…

Fix: 102.5.1+
Fix from $1,950 2022-12-22
Firefox Mobile MEDIUM 6.5
CVE-2022-31746

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Fi…

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-29916

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to pro…

Fix: 91.9 / 100.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22745

Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91…

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Liquidjs MEDIUM 5.3
CVE-2022-25948

The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking pr…

Fix: 10.0.0+
Fix from $1,600 2022-12-22
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3185

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning the devic…

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Harmonyos HIGH 7.5
CVE-2022-46310

The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.

Fix: 3.0.0+
Fix from $1,950 2022-12-20
Bigbluebutton HIGH 7.5
CVE-2022-23488

BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Da…

Fix: 2.4+
Fix from $1,950 2022-12-17
Bigbluebutton MEDIUM 5.7
CVE-2022-41964

BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can st…

Patch available
Fix from $1,600 2022-12-16
Android MEDIUM 5.5
CVE-2022-20591

In ppmpu_set of ppmpu.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure…

Mitigation only
Fix from $1,600 2022-12-16
Ipados MEDIUM 5.5
CVE-2022-46702

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory.

Fix: 16.2+
Fix from $1,600 2022-12-15