Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2022-27863
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking d…
Vikbooking Hotel Booking Engine \& Property Management System Plugin
after 1.5.3
MEDIUM 5.3
CVE-2022-1186
The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via a…
Be Popia Compliant
after 1.1.5
MEDIUM 5.5
CVE-2011-4917
In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.
Linux Kernel
after 3.1
HIGH 7.5
CVE-2022-27849
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
Simple Ajax Chat
after 20220115
MEDIUM 5.3
CVE-2022-24853
Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our …
Metabase
0.40.8 / 0.41.7+
MEDIUM 6.5
CVE-2022-24849
DisCatSharp is a Discord API wrapper for .NET. Users of versions 9.8.5, 9.8.6, 9.9.0 and previously published prereleases of 10.0.0 who have used eit…
Discatsharp
9.9.1+
MEDIUM 5.0
CVE-2022-25166
An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file …
Aws Client Vpn
No fix yet
HIGH 7.5
CVE-2022-22183
An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect …
Junos Os Evolved
Mitigation only
HIGH 7.5
CVE-2021-43287EPSS 28%
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to t…
Gocd
21.3.0+
MEDIUM 5.3
CVE-2022-22961
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess informa…
Cloud Foundation
5.0 / 9.0+
HIGH 7.5
CVE-2022-27667
Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to ac…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2022-27241
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions…
Mendix
9.11.0+
MEDIUM 5.3
CVE-2022-24837
HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enum…
Hedgedoc
1.9.3+
HIGH 7.5
CVE-2022-27844
Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70
Migration\, Backup\, Staging
0.9.71+
MEDIUM 5.3
CVE-2022-24804
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expo…
Discourse
2.8.3+
MEDIUM 5.3
CVE-2022-25594
Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote attacker can input specific URLs…
Parking Lot Management System
No fix yet
MEDIUM 5.3
CVE-2021-43205
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and bel…
Forticlient
after 7.0.2
MEDIUM 6.5
CVE-2021-40375
Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privileg…
Openeyes
No fix yet
HIGH 7.5
CVE-2022-0709
The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is…
Booking Package
1.5.29+
HIGH 7.5
CVE-2019-14839
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercep…
Business Central
after 7.48.0
CRITICAL 9.1
CVE-2022-24797
Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics h…
Pomerium
0.17.1+
HIGH 7.5
CVE-2022-1077
A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log …
Flex 1085 Firmware
Mitigation only
HIGH 8.8
CVE-2022-24768
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an …
Argo Cd
2.1.14 / 2.2.8+
MEDIUM 5.5
CVE-2022-0854
A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read rand…
Linux Kernel
after 5.16
HIGH 7.5
CVE-2021-27422
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure wi…
Multilin B30 Firmware
8.10+
MEDIUM 5.3
CVE-2021-27424
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MO…
Multilin B30 Firmware
8.10+
HIGH 8.8
CVE-2022-25602
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugi…
Responsive Menu
after 4.1.7
MEDIUM 5.3
CVE-2022-25248
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specif…
Axeda Agent
6.9.1 / 6.9.215+
MEDIUM 5.3
CVE-2022-0430
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.
Httpie
3.1.0+
MEDIUM 6.5
CVE-2022-24762
sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication…
Sysend.js
1.10.0+