Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-42523
There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. …
Colord
Patch available
MEDIUM 5.9
CVE-2021-3714
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local e…
Linux Kernel
Mitigation only
MEDIUM 5.5
CVE-2021-3736
A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Me…
Linux Kernel
after 5.14.20
MEDIUM 5.5
CVE-2021-3798
A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor …
Opencryptoki
3.17.0+
MEDIUM 5.5
CVE-2021-3800
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivil…
Debian Linux
2.62.5 / 2.63.6+
MEDIUM 5.5
CVE-2022-31238
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive informat…
Emc Powerscale Onefs
after 9.4.0.2
HIGH 7.5
CVE-2022-34776
Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bi…
Tabit
3.27.0+
MEDIUM 5.3
CVE-2022-2558
The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certai…
Simple Job Board
2.10.0+
HIGH 8.8
CVE-2021-3590
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output…
Satellite
Mitigation only
MEDIUM 5.3
CVE-2022-30693
Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to obtain the data of the…
Office
after 10.8.5
CRITICAL 9.8
CVE-2022-35147
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
Doracms
after 2.1.8
HIGH 7.5
CVE-2022-35290
Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.
Authenticator
1.2.17+
HIGH 7.5
CVE-2022-35715
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur…
Infosphere Information Server
Mitigation only
MEDIUM 5.3
CVE-2022-34659
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applica…
Simcenter Star Ccm\+ Viewer
Mitigation only
MEDIUM 5.5
CVE-2022-34708
Windows Kernel Information Disclosure Vulnerability
Windows 10
Mitigation only
MEDIUM 5.5
CVE-2022-34710
Windows Defender Credential Guard Information Disclosure Vulnerability
Windows 10
No fix yet
MEDIUM 5.5
CVE-2022-34712
Windows Defender Credential Guard Information Disclosure Vulnerability
Windows 10
No fix yet
MEDIUM 5.3
CVE-2022-34692
Microsoft Exchange Server Information Disclosure Vulnerability
Exchange Server
No fix yet
MEDIUM 5.5
CVE-2022-30197
Windows Kernel Information Disclosure Vulnerability
Windows 10
No fix yet
HIGH 7.5
CVE-2022-2704
A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of…
Simple E Learning System
No fix yet
HIGH 7.5
CVE-2022-27630
An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-c…
Linkhub Mesh Wifi Ac1200
No fix yet
HIGH 7.5
CVE-2022-27633
An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-cra…
Linkhub Mesh Wifi Ac1200
No fix yet
MEDIUM 5.5
CVE-2022-29071
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certai…
Cloudvision Portal
after 2022.1.0
MEDIUM 5.0
CVE-2022-36834
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interacti…
Game Launcher
6.0.07+
MEDIUM 5.3
CVE-2022-31185
mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, even if a user had clicked the `…
Mprweb
after 5.0.0
MEDIUM 5.3
CVE-2022-31190
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace…
Dspace
6.4+
HIGH 7.5
CVE-2022-27614
Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attac…
Media Server
1.4-2665 / 1.8.1-2876+
HIGH 7.5
CVE-2021-40180
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContact…
Wechat
No fix yet
HIGH 7.5
CVE-2022-31162
Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug …
Slack Morphism
0.41.0+
MEDIUM 5.3
CVE-2022-2117
The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-A…
Givewp
after 2.20.2