Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2021-42523 There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. … Colord Patch available Fix from $1,9502022-08-25 MEDIUM 5.9 CVE-2021-3714 A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local e… Linux Kernel Mitigation only Fix from $1,6002022-08-23 MEDIUM 5.5 CVE-2021-3736 A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Me… Linux Kernel after 5.14.20 Fix from $1,6002022-08-23 MEDIUM 5.5 CVE-2021-3798 A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor … Opencryptoki 3.17.0+ Fix from $1,6002022-08-23 MEDIUM 5.5 CVE-2021-3800 A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivil… Debian Linux 2.62.5 / 2.63.6+ Fix from $1,6002022-08-23 MEDIUM 5.5 CVE-2022-31238 Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive informat… Emc Powerscale Onefs after 9.4.0.2 Fix from $1,6002022-08-22 HIGH 7.5 CVE-2022-34776 Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bi… Tabit 3.27.0+ Fix from $1,9502022-08-22 MEDIUM 5.3 CVE-2022-2558 The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certai… Simple Job Board 2.10.0+ Fix from $1,6002022-08-22 HIGH 8.8 CVE-2021-3590 A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output… Satellite Mitigation only Fix from $1,9502022-08-22 MEDIUM 5.3 CVE-2022-30693 Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to obtain the data of the… Office after 10.8.5 Fix from $1,6002022-08-18 CRITICAL 9.8 CVE-2022-35147 DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request. Doracms after 2.1.8 Fix from $2,3002022-08-17 HIGH 7.5 CVE-2022-35290 Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted. Authenticator 1.2.17+ Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-35715 IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is retur… Infosphere Information Server Mitigation only Fix from $1,9502022-08-10 MEDIUM 5.3 CVE-2022-34659 A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applica… Simcenter Star Ccm\+ Viewer Mitigation only Fix from $1,6002022-08-10 MEDIUM 5.5 CVE-2022-34708 Windows Kernel Information Disclosure Vulnerability Windows 10 Mitigation only Fix from $1,6002022-08-09 MEDIUM 5.5 CVE-2022-34710 Windows Defender Credential Guard Information Disclosure Vulnerability Windows 10 No fix yet Fix from $1,6002022-08-09 MEDIUM 5.5 CVE-2022-34712 Windows Defender Credential Guard Information Disclosure Vulnerability Windows 10 No fix yet Fix from $1,6002022-08-09 MEDIUM 5.3 CVE-2022-34692 Microsoft Exchange Server Information Disclosure Vulnerability Exchange Server No fix yet Fix from $1,6002022-08-09 MEDIUM 5.5 CVE-2022-30197 Windows Kernel Information Disclosure Vulnerability Windows 10 No fix yet Fix from $1,6002022-08-09 HIGH 7.5 CVE-2022-2704 A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of… Simple E Learning System No fix yet Fix from $1,9502022-08-08 HIGH 7.5 CVE-2022-27630 An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-c… Linkhub Mesh Wifi Ac1200 No fix yet Fix from $1,9502022-08-05 HIGH 7.5 CVE-2022-27633 An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-cra… Linkhub Mesh Wifi Ac1200 No fix yet Fix from $1,9502022-08-05 MEDIUM 5.5 CVE-2022-29071 This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certai… Cloudvision Portal after 2022.1.0 Fix from $1,6002022-08-05 MEDIUM 5.0 CVE-2022-36834 Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interacti… Game Launcher 6.0.07+ Fix from $1,6002022-08-05 MEDIUM 5.3 CVE-2022-31185 mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, even if a user had clicked the `… Mprweb after 5.0.0 Fix from $1,6002022-08-01 MEDIUM 5.3 CVE-2022-31190 DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace… Dspace 6.4+ Fix from $1,6002022-08-01 HIGH 7.5 CVE-2022-27614 Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attac… Media Server 1.4-2665 / 1.8.1-2876+ Fix from $1,9502022-07-28 HIGH 7.5 CVE-2021-40180 In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContact… Wechat No fix yet Fix from $1,9502022-07-26 HIGH 7.5 CVE-2022-31162 Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug … Slack Morphism 0.41.0+ Fix from $1,9502022-07-22 MEDIUM 5.3 CVE-2022-2117 The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-A… Givewp after 2.20.2 Fix from $1,6002022-07-18