Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Telepresence Collaboration Endpoint MEDIUM 6.7
CVE-2022-20776

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 10.20.1+
Fix from $1,600 2022-10-26
Telepresence Collaboration Endpoint HIGH 7.2
CVE-2022-20811

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 9.15.13.0 / 10.15.1+
Fix from $1,950 2022-10-26
Telepresence Collaboration Endpoint MEDIUM 5.5
CVE-2022-20953

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 10.19.1+
Fix from $1,600 2022-10-26
Fabric Operating System MEDIUM 5.5
CVE-2022-33181

An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a lo…

Fix: 7.4.2.j / 8.2.3c+
Fix from $1,600 2022-10-25
Joomla\! MEDIUM 5.3
CVE-2022-27912

An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.

Fix: after 4.2.3
Fix from $1,600 2022-10-25
Tug Home Base Server HIGH 8.1
CVE-2022-1070

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Fix: 24+
Fix from $1,950 2022-10-21
Tug Home Base Server HIGH 7.5
CVE-2022-26423

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Fix: 24+
Fix from $1,950 2022-10-21
Messenger MEDIUM 6.5
CVE-2022-41707

Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user of the application. This is po…

No fix yet
Fix from $1,600 2022-10-19
Mercurial MEDIUM 5.3
CVE-2022-43410

Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its w…

Fix: after 1251.va_b_121f184902
Fix from $1,600 2022-10-19
Git MEDIUM 5.5
CVE-2022-39253

Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2…

Fix: 2.30.6 / 2.31.5+
Fix from $1,600 2022-10-19
Zgr Tps200 Ng Firmware HIGH 7.5
CVE-2020-8975

ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of th…

Mitigation only
Fix from $1,950 2022-10-17
Otrs HIGH 7.5
CVE-2022-3501

Article template contents with sensitive data could be accessed from agents without permissions.

Fix: 8.0.26+
Fix from $1,950 2022-10-17
Gocd MEDIUM 6.5
CVE-2022-39309

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go…

Fix: 21.1.0+
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-38688

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2022-10-14
Android MEDIUM 5.5
CVE-2022-38689

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…

Mitigation only
Fix from $1,600 2022-10-14
Grafana HIGH 7.5
CVE-2022-39201

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Gr…

Fix: 8.5.14 / 9.1.8+
Fix from $1,950 2022-10-13
Grafana HIGH 7.5
CVE-2022-31130

Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authe…

Fix: 8.5.14 / 9.1.8+
Fix from $1,950 2022-10-13
Geodrive HIGH 7.8
CVE-2022-33919

Dell GeoDrive, versions 2.1 - 2.2, contains an information disclosure vulnerability in GUI. An authenticated non-admin user could potentially exploit…

Fix: 2.2.3+
Fix from $1,950 2022-10-12
Business Objects Business Intelligence Platform HIGH 7.6
CVE-2022-39013

Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify …

Mitigation only
Fix from $1,950 2022-10-11
Desigo Pxm30 1 Firmware MEDIUM 5.7
CVE-2022-40177

A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM…

Fix: 02.20.126.11-37 / 02.20.126.11-41+
Fix from $1,600 2022-10-11
Zoneminder HIGH 7.5
CVE-2022-39289

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log conten…

Fix: 1.37.24+
Fix from $1,950 2022-10-07
Dex MEDIUM 6.5
CVE-2022-39222

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clie…

Fix: 2.35.0+
Fix from $1,600 2022-10-06
Bosch Video Management System MEDIUM 5.9
CVE-2022-32540

Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows m…

Fix: after 11.1.0
Fix from $1,600 2022-09-30
Smart Evision MEDIUM 6.5
CVE-2022-39029

Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privilege, who is not explicitly auth…

Fix: after 2022.02.21
Fix from $1,600 2022-09-28
Smart Evision HIGH 7.5
CVE-2022-39030

smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, who is not explicitly authorize…

Mitigation only
Fix from $1,950 2022-09-28
Smart Evision MEDIUM 5.3
CVE-2022-39031

Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit this vulnerability to acquire…

Mitigation only
Fix from $1,600 2022-09-28
Mailcow\ HIGH 8.2
CVE-2022-39258

mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Author…

Fix: 2022-09+
Fix from $1,950 2022-09-27
Ipados MEDIUM 5.5
CVE-2022-32825

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6,…

Fix: 8.7 / 11.6.8+
Fix from $1,600 2022-09-23
Ipados MEDIUM 5.5
CVE-2022-32849

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8,…

Fix: 10.15.7 / 11.6.8+
Fix from $1,600 2022-09-23
Mac Os X MEDIUM 5.5
CVE-2022-32805

The issue was addressed with improved handling of caches. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monte…

Fix: 10.15.7 / 11.6.8+
Fix from $1,600 2022-09-23