Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Digital Experience Platform MEDIUM 5.9
CVE-2022-42132

The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 …

Fix: 7.4.3.5+
Fix from $1,600 2022-11-15
Calendar MEDIUM 5.4
CVE-2022-41913

Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic.…

Patch available
Fix from $1,600 2022-11-14
Discourse MEDIUM 6.5
CVE-2022-39385

Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several privat…

Fix: 2.8.10+
Fix from $1,600 2022-11-14
Cics Tx MEDIUM 5.3
CVE-2022-34329

IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467.

Patch available
Fix from $1,600 2022-11-14
Airflow HIGH 7.5
CVE-2022-27949

A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (fo…

Fix: 2.3.1+
Fix from $1,950 2022-11-14
Ezplatform Graphql MEDIUM 5.3
CVE-2022-41876

ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecur…

Fix: 1.0.13 / 2.3.12+
Fix from $1,600 2022-11-10
Grafana MEDIUM 5.3
CVE-2022-39307

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the …

Fix: 8.5.15 / 9.2.4+
Fix from $1,600 2022-11-09
Electron MEDIUM 6.1
CVE-2022-36077

The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1…

Fix: 18.3.7 / 19.0.11+
Fix from $1,600 2022-11-08
Cyber Protect Home Office MEDIUM 5.5
CVE-2022-44746

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows)…

Fix: 40107+
Fix from $1,600 2022-11-07
Domino MEDIUM 5.5
CVE-2022-38654

HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directo…

Mitigation only
Fix from $1,600 2022-11-04
Discourse MEDIUM 5.3
CVE-2022-39378

Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic …

Fix: 2.8.9+
Fix from $1,600 2022-11-02
Forticlient MEDIUM 5.5
CVE-2022-33878

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a…

Fix: after 7.0.5
Fix from $1,600 2022-11-02
Fortios HIGH 7.5
CVE-2022-35842

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6…

Fix: after 7.0.6
Fix from $1,950 2022-11-02
Ipados MEDIUM 5.5
CVE-2022-42810

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16.1, iOS 16.1 and iPadOS 16, macOS …

Fix: 13.0 / 15.7.1+
Fix from $1,600 2022-11-01
macOS MEDIUM 5.5
CVE-2022-42815

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

Fix: 13.0+
Fix from $1,600 2022-11-01
Ipados MEDIUM 6.5
CVE-2022-42817

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watchOS 9.1.…

Fix: 9.1 / 15.7.1+
Fix from $1,600 2022-11-01
macOS MEDIUM 5.9
CVE-2022-42818

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. A user in a privileged network position may be able …

Fix: 12.6+
Fix from $1,600 2022-11-01
macOS MEDIUM 5.5
CVE-2022-42819

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. An…

Fix: 11.7 / 12.6+
Fix from $1,600 2022-11-01
macOS MEDIUM 5.5
CVE-2022-32862

This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.7.1, macOS Ventura 13, macOS Monterey 12.6.1. An app …

Fix: 11.7.1 / 12.6.1+
Fix from $1,600 2022-11-01
Iphone Os MEDIUM 5.0
CVE-2022-32875

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Mon…

Fix: 9.0 / 11.7+
Fix from $1,600 2022-11-01
macOS MEDIUM 5.5
CVE-2022-32877

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Monterey 12.6. An app may be able …

Fix: 11.7 / 12.6+
Fix from $1,600 2022-11-01
Iphone Os MEDIUM 5.5
CVE-2022-32858

The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. An app may be able to leak sensiti…

Fix: 9.0 / 13.0+
Fix from $1,600 2022-11-01
Enterprise Server MEDIUM 5.7
CVE-2022-23738

An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files …

Fix: 3.2.20 / 3.3.15+
Fix from $1,600 2022-11-01
Hubshare HIGH 7.5
CVE-2022-39018

Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a know…

Fix: 3.3.11.3+
Fix from $1,950 2022-10-31
Access Management MEDIUM 6.5
CVE-2022-24670

An attacker can use the unrestricted LDAP queries to determine configuration entries

Fix: after 7.0.2
Fix from $1,600 2022-10-27
Library Automation System MEDIUM 5.3
CVE-2021-45475

Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosure vulnerability.

Fix: 19.02+
Fix from $1,600 2022-10-27
Metabase MEDIUM 6.5
CVE-2022-39359

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL…

Fix: 0.41.9 / 0.42.6+
Fix from $1,600 2022-10-26
Metabase MEDIUM 6.5
CVE-2022-39358

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked p…

Fix: 0.42.6 / 0.43.7+
Fix from $1,600 2022-10-26
Telepresence Collaboration Endpoint HIGH 7.1
CVE-2022-20954

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 10.19.1+
Fix from $1,950 2022-10-26
Telepresence Collaboration Endpoint HIGH 7.1
CVE-2022-20955

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 10.19.1+
Fix from $1,950 2022-10-26