Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2022-24742 Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains u… Sylius 1.9.10 / 1.10.11+ Fix from $1,6002022-03-14 MEDIUM 5.5 CVE-2021-41849 An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext usin… G90 Firmware No fix yet Fix from $1,6002022-03-11 HIGH 7.8 CVE-2021-41850 An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three I… G90 Firmware No fix yet Fix from $1,9502022-03-11 MEDIUM 5.3 CVE-2021-32473 It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.… Moodle 3.5.18 / 3.8.9+ Fix from $1,6002022-03-11 HIGH 7.5 CVE-2022-25512 FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys. Freetakserver Ui No fix yet Fix from $1,9502022-03-11 MEDIUM 5.3 CVE-2022-26847 SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects. Debian Linux 3.2.14 / 4.0.5+ Fix from $1,6002022-03-10 MEDIUM 6.5 CVE-2022-24398 Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access informat… Business Objects Business Intelligence Platform No fix yet Fix from $1,6002022-03-10 HIGH 7.5 CVE-2022-22547 Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a ran… Simple Diagnostics Agent 1.58+ Fix from $1,9502022-03-10 HIGH 7.5 CVE-2022-0813 PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang para… phpMyAdmin after 5.1.1 Fix from $1,9502022-03-10 HIGH 7.8 CVE-2022-0516 A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a … Linux Kernel 5.17+ Fix from $1,9502022-03-10 HIGH 7.5 CVE-2022-0725 A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vuln… Fedora Mitigation only Fix from $1,9502022-03-10 MEDIUM 5.5 CVE-2021-4023 A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellatio… Linux Kernel after 5.14 Fix from $1,6002022-03-10 MEDIUM 5.5 CVE-2021-3732 A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local u… Linux Kernel 5.14+ Fix from $1,6002022-03-10 MEDIUM 5.3 CVE-2020-14112 Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing configuration. Attackers can expl… Ax6000 Firmware 1.0.56+ Fix from $1,6002022-03-10 MEDIUM 5.3 CVE-2022-24747 Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no proper… Shopware 6.4.8.2+ Fix from $1,6002022-03-09 HIGH 7.6 CVE-2021-22783 A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected … Ritto Wiser Door Mitigation only Fix from $1,9502022-03-09 MEDIUM 5.3 CVE-2021-41239 Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user… Nextcloud Server 20.0.14 / 21.0.6+ Fix from $1,6002022-03-08 MEDIUM 6.5 CVE-2022-24737 HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that bel… Fedora 3.1.0+ Fix from $1,6002022-03-07 MEDIUM 5.5 CVE-2022-24725 Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when… Shescape 1.5.1+ Fix from $1,6002022-03-03 MEDIUM 5.5 CVE-2021-3602 An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Doc… Enterprise Linux 1.16.8 / 1.17.2+ Fix from $1,6002022-03-03 HIGH 7.5 CVE-2022-23648EPSS 27% containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.1… Debian Linux 1.4.13 / 1.5.10+ Fix from $1,9502022-03-03 HIGH 7.5 CVE-2021-4076 A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys. Tang 11+ Fix from $1,9502022-03-02 MEDIUM 6.5 CVE-2021-3677 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated da… PostgreSQL 11.13 / 12.8+ Fix from $1,6002022-03-02 MEDIUM 5.3 CVE-2022-23779EPSS 15% Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading … Manageengine Desktop Central 10.1.2137.8+ Fix from $1,6002022-03-02 MEDIUM 5.5 CVE-2022-22303 An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 … Fortimanager after 7.0.2 Fix from $1,6002022-03-02 MEDIUM 6.5 CVE-2022-0577 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1. Debian Linux 2.6.1+ Fix from $1,6002022-03-02 MEDIUM 5.3 CVE-2021-25118EPSS 6% The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST … Yoast Seo 17.3+ Fix from $1,6002022-02-28 MEDIUM 5.3 CVE-2022-24633 All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<userna… Filecloud 21.3.0.18447+ Fix from $1,6002022-02-24 HIGH 7.5 CVE-2022-0654 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0. Node Request Retry 7.0.0+ Fix from $1,9502022-02-23 HIGH 7.5 CVE-2022-23984 Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). Wpdiscuz after 7.3.11 Fix from $1,9502022-02-21