Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2022-30625 Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A direct… P5e Gnss Firmware Mitigation only Fix from $1,6002022-07-18 MEDIUM 5.5 CVE-2021-4135 A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device s… Linux Kernel 5.16+ Fix from $1,6002022-07-14 MEDIUM 6.5 CVE-2022-2401 Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by … Mattermost Server 6.3.9 / 6.5.2+ Fix from $1,6002022-07-14 MEDIUM 6.5 CVE-2021-39019 IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP… Engineering Lifecycle Optimization Publishing Patch available Fix from $1,6002022-07-14 MEDIUM 5.5 CVE-2022-1662 In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password via the C… Convert2rhel Patch available Fix from $1,6002022-07-14 MEDIUM 6.0 CVE-2022-35169 SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002022-07-12 MEDIUM 5.5 CVE-2011-4916 Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*. Linux Kernel after 3.1 Fix from $1,6002022-07-12 HIGH 7.5 CVE-2020-4159 IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to mount further attacks agains… Qradar Network Security Patch available Fix from $1,9502022-07-12 MEDIUM 6.5 CVE-2022-29901 Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak… Fedora Mitigation only Fix from $1,6002022-07-12 CRITICAL 9.8 CVE-2020-35167 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discr… HTTP Server 4.1.5 / 4.6+ Fix from $2,3002022-07-11 HIGH 7.5 CVE-2022-31139 UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data … Unsafe Accessor 1.7.0+ Fix from $1,9502022-07-11 MEDIUM 6.5 CVE-2022-29512 Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticat… Garoon after 5.9.1 Fix from $1,6002022-07-11 HIGH 7.1 CVE-2022-33741 Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond… Fedora 4.9.322 / 4.14.287+ Fix from $1,9502022-07-05 HIGH 7.1 CVE-2022-33742 Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond… Fedora 4.9.322 / 4.14.287+ Fix from $1,9502022-07-05 HIGH 8.2 CVE-2022-31112 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery d… Parse Server 4.10.13 / 5.2.4+ Fix from $1,9502022-06-30 MEDIUM 6.5 CVE-2017-20109 A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the fi… Teleopti Workforce Management after 7.1.0 Fix from $1,6002022-06-29 HIGH 7.5 CVE-2017-20110 A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue is some unknown functionalit… Teleopti Workforce Management after 7.1.0 Fix from $1,9502022-06-29 MEDIUM 5.3 CVE-2022-31068 GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affec… Glpi 10.0.2+ Fix from $1,6002022-06-28 HIGH 7.7 CVE-2022-31090 Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handle… Debian Linux 6.5.8 / 7.4.5+ Fix from $1,9502022-06-27 HIGH 7.7 CVE-2022-31091 Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a r… Debian Linux 6.5.8 / 7.4.5+ Fix from $1,9502022-06-27 MEDIUM 6.5 CVE-2022-2221 Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access … Remote Desktop Manager 2022.1.8+ Fix from $1,6002022-06-27 MEDIUM 5.7 CVE-2017-20101 A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_down… Projectsend No fix yet Fix from $1,6002022-06-27 HIGH 7.5 CVE-2022-0722 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0. Parse Url 7.0.0+ Fix from $1,9502022-06-27 MEDIUM 6.5 CVE-2022-31095 discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an… Discourse Chat 0.4+ Fix from $1,6002022-06-21 MEDIUM 6.5 CVE-2022-30607 IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive info… Robotic Process Automation Patch available Fix from $1,6002022-06-17 MEDIUM 5.5 CVE-2022-30184EPSS 5% .NET and Visual Studio Information Disclosure Vulnerability Fedora 6.2.1 / 16.9.22+ Fix from $1,6002022-06-15 HIGH 7.5 CVE-2022-31069 NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to control when Auth… Nestjs Proxy 0.7.0+ Fix from $1,9502022-06-15 HIGH 7.5 CVE-2022-31070 NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to block sensitive c… Nestjs Proxy 0.7.0+ Fix from $1,9502022-06-15 HIGH 7.7 CVE-2022-20664 A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco … Email Security Appliance 13.6.2-090 / 14.0.2-020+ Fix from $1,9502022-06-15 MEDIUM 5.3 CVE-2022-31060 Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5` in the `beta` and `tests-pas… Discourse 2.8.4+ Fix from $1,6002022-06-14