Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Ipados MEDIUM 5.5
CVE-2022-42866

The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2…

Fix: 9.2 / 13.1+
Fix from $1,600 2022-12-15
Safari MEDIUM 6.5
CVE-2022-42852

The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.…

Fix: 9.2 / 15.7.2+
Fix from $1,600 2022-12-15
macOS MEDIUM 5.5
CVE-2022-42854

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1. An app may be able to disclo…

Fix: 12.6.2+
Fix from $1,600 2022-12-15
Ipados MEDIUM 5.5
CVE-2022-42843

This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. …

Fix: 9.2 / 16.2+
Fix from $1,600 2022-12-15
Moto E20 Firmware MEDIUM 5.5
CVE-2022-3917

Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with…

Mitigation only
Fix from $1,600 2022-12-14
Fp Newsletter HIGH 7.5
CVE-2022-47410

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.…

Fix: 1.1.1 / 2.1.2+
Fix from $1,950 2022-12-14
Fp Newsletter HIGH 7.5
CVE-2022-47411

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.…

Fix: 1.1.1 / 2.1.2+
Fix from $1,950 2022-12-14
6gk5204 0ba00 2mb2 Firmware HIGH 7.5
CVE-2022-46355

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204R…

Fix: 3.2.7+
Fix from $1,950 2022-12-13
Sf100 Firmware MEDIUM 5.5
CVE-2022-37930

A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary Flash Arrays which could pote…

Fix: 5.2.1.900+
Fix from $1,600 2022-12-12
Sd Wan MEDIUM 5.3
CVE-2022-37909

Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in…

Fix: 6.5.4.22 / 8.6.0.17+
Fix from $1,600 2022-12-12
Freshrss HIGH 7.5
CVE-2022-23497

FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition to user preferences, such co…

Fix: 1.20.2+
Fix from $1,950 2022-12-09
Traefik MEDIUM 6.5
CVE-2022-23469

Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulnerability in Traefik displayin…

Fix: 2.9.6+
Fix from $1,600 2022-12-08
Android MEDIUM 5.5
CVE-2022-39897

Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information v…

Mitigation only
Fix from $1,600 2022-12-08
Android MEDIUM 5.5
CVE-2022-42782

In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

Mitigation only
Fix from $1,600 2022-12-06
Android MEDIUM 5.5
CVE-2022-42766

In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

No fix yet
Fix from $1,600 2022-12-06
Megarac Sp X HIGH 7.5
CVE-2022-2827

AMI MegaRAC User Enumeration Vulnerability

Mitigation only
Fix from $1,950 2022-12-05
Curl CRITICAL 9.8
CVE-2022-32221

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOP…

Fix: 7.86.0 / 12.6.3+
Fix from $2,300 2022-12-05
Nextcloud Talk MEDIUM 6.5
CVE-2022-41971

Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continu…

Fix: 12.2.8 / 13.0.10+
Fix from $1,600 2022-12-01
Websphere Automation For Ibm Cloud Pak For Watson Aiops MEDIUM 5.5
CVE-2022-43901

IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit…

Fix: 1.4.3+
Fix from $1,600 2022-12-01
Isic.lk HIGH 7.5
CVE-2022-28607

An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to gain sensitive information …

Fix: after 2018-02-13
Fix from $1,950 2022-12-01
M Files Server MEDIUM 5.3
CVE-2022-1911

Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of…

Fix: 22.6.11534.4+
Fix from $1,600 2022-11-30
Book Store Management System HIGH 7.5
CVE-2022-4228

A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affects an unknown part of the file…

No fix yet
Fix from $1,950 2022-11-30
Talk MEDIUM 5.5
CVE-2022-41926

Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broa…

Fix: 14.1.0+
Fix from $1,600 2022-11-25
Dolphinscheduler HIGH 7.5
CVE-2022-26885

When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.

Fix: 2.0.6+
Fix from $1,950 2022-11-24
Postgresql Jdbc Driver MEDIUM 5.5
CVE-2022-41946

pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)`…

Fix: 42.2.27 / 42.3.8+
Fix from $1,600 2022-11-23
Security Event Manager MEDIUM 5.3
CVE-2022-38113

This vulnerability discloses build and services versions in the server response header.

Mitigation only
Fix from $1,600 2022-11-23
Knative Func HIGH 7.4
CVE-2022-41939

knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Developers using a malicious or comp…

Fix: 1.8.1+
Fix from $1,950 2022-11-19
Quiz And Survey Master HIGH 7.5
CVE-2022-42883

Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.

Fix: after 7.3.10
Fix from $1,950 2022-11-18
Media Library Assistant MEDIUM 5.3
CVE-2022-41618

Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.

Fix: 3.01+
Fix from $1,600 2022-11-18
Phone Orders For Woocommerce MEDIUM 6.5
CVE-2022-41655

Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress.

Fix: 3.7.2+
Fix from $1,600 2022-11-18