Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2022-32818 The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5. An app may be able to leak sensitive kernel state. macOS 12.5+ Fix from $1,6002022-09-23 MEDIUM 6.5 CVE-2022-32220 An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from pr… Rocket.chat 5.0+ Fix from $1,6002022-09-23 HIGH 7.5 CVE-2022-40629 This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive),… En6200 Prime Quad 35 Firmware 22.21.2+ Fix from $1,9502022-09-23 HIGH 7.5 CVE-2022-40194 Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress Customer Reviews For Woocommerce after 5.3.5 Fix from $1,9502022-09-23 MEDIUM 6.5 CVE-2022-39230 fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Versions 3.1.1 and 3.1.2 are subject… Fhir Works On Aws Authz Smart 3.1.3+ Fix from $1,6002022-09-23 MEDIUM 5.3 CVE-2021-39190 The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is… System Center Configuration Manager 2.3.0+ Fix from $1,6002022-09-22 HIGH 7.5 CVE-2022-23952 In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable. Keylime 6.3.0+ Fix from $1,9502022-09-21 HIGH 7.5 CVE-2022-23948 A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously created unprivil… Keylime 6.3.0+ Fix from $1,9502022-09-21 MEDIUM 5.3 CVE-2019-5641 Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Ins… Insightvm after 6.6.160 Fix from $1,6002022-09-21 HIGH 7.8 CVE-2022-28638 An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that could potentially lead to a loss… Integrated Lights Out 5 Firmware 2.72+ Fix from $1,9502022-09-20 MEDIUM 5.5 CVE-2022-39210 Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not pr… Nextcloud 3.21.0+ Fix from $1,6002022-09-17 MEDIUM 5.3 CVE-2022-39212 Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last vid… Talk 13.0.8 / 14.0.4+ Fix from $1,6002022-09-17 HIGH 7.5 CVE-2022-36074 Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to st… Nextcloud Enterprise Server 22.2.11 / 23.0.7+ Fix from $1,9502022-09-15 MEDIUM 5.3 CVE-2022-31143 GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk featu… Glpi 10.0.3+ Fix from $1,6002022-09-14 MEDIUM 5.2 CVE-2022-32244 Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data,… Businessobjects Business Intelligence Mitigation only Fix from $1,6002022-09-13 MEDIUM 5.3 CVE-2022-36101 Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained… Shopware 5.7.15+ Fix from $1,6002022-09-12 MEDIUM 5.9 CVE-2022-38400 Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a s… Mailform Pro Cgi after 4.3.1 Fix from $1,6002022-09-08 HIGH 7.5 CVE-2022-36079 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields (keys used internally by Pars… Parse Server 4.10.14 / 5.2.5+ Fix from $1,9502022-09-07 MEDIUM 5.3 CVE-2022-2939 The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumera… Wp Cerber Security\, Anti Spam \& Malware Scan after 9.0 Fix from $1,6002022-09-06 MEDIUM 6.5 CVE-2022-34867 Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete su… Wp Libre Form after 2.0.8 Fix from $1,6002022-09-06 MEDIUM 5.3 CVE-2022-2462 The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to… Transposh Wordpress Translation after 1.0.8.1 Fix from $1,6002022-09-06 HIGH 8.1 CVE-2022-31176 Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). … Grafana Image Renderer 3.6.1+ Fix from $1,9502022-09-02 MEDIUM 5.3 CVE-2022-2739 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t… Enterprise Linux Server Mitigation only Fix from $1,6002022-09-01 MEDIUM 5.5 CVE-2022-2806 It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7… Sos 4.2-20.el8_6 / 4.4.7-2.el8ev+ Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-1663 The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment sectio… Stop Spam Comments after 0.2.1.2 Fix from $1,6002022-08-29 HIGH 7.1 CVE-2022-0850 A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace. Linux Kernel 4.4.276 / 4.9.276+ Fix from $1,9502022-08-29 MEDIUM 5.5 CVE-2022-0851 There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription… Enterprise Linux No fix yet Fix from $1,6002022-08-29 MEDIUM 5.5 CVE-2021-3585 A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager. Tripleo Heat Templates 8.4.1+ Fix from $1,6002022-08-26 HIGH 7.8 CVE-2021-20260 A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_host… Foreman Mitigation only Fix from $1,9502022-08-26 HIGH 7.5 CVE-2021-42522 There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of … Anjuta Mitigation only Fix from $1,9502022-08-25