Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2022-0708
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members…
Mattermost
after 6.3.0
HIGH 7.5
CVE-2022-23982
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.
Perfect Brands For Woocommerce
after 2.0.4
MEDIUM 5.5
CVE-2022-0672
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMin…
Lemminx
0.19.0+
MEDIUM 5.5
CVE-2021-20320
A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special us…
Linux Kernel
5.15+
CRITICAL 9.8
CVE-2021-3773EPSS 5%
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network …
Linux Kernel
5.14 / 5.15.15+
MEDIUM 6.5
CVE-2022-23643
Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed side-channel vulnerabilitity i…
Sourcegraph
3.35.2 / 3.36.3+
MEDIUM 5.3
CVE-2021-45310
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restrictio…
Switchvox
No fix yet
CRITICAL 9.8
CVE-2021-45420EPSS 18%
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cg…
Dixell Xweb 500 Firmware
Mitigation only
HIGH 7.5
CVE-2021-45421
Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to …
Dixell Xweb 500 Firmware
No fix yet
MEDIUM 5.9
CVE-2022-23634
Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails…
Puma
4.3.11 / 5.2.6.2+
MEDIUM 5.9
CVE-2022-23633
Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event …
Rails
5.2.6.2 / 6.0.4.6+
MEDIUM 5.3
CVE-2022-24003
Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision vi…
Bixby Vision
3.7.50.6+
HIGH 7.5
CVE-2021-22785
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when a…
Modicon M340 Bmxp342020 Firmware
3.40+
MEDIUM 6.5
CVE-2022-0018
An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the credentials of the local user…
Globalprotect
5.1.10 / 5.2.9+
MEDIUM 6.5
CVE-2022-20680
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitiv…
Prime Service Catalog
after 12.0
MEDIUM 6.5
CVE-2022-22542
S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for…
S\/4hana
Mitigation only
MEDIUM 6.7
CVE-2021-0166
Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some…
Amt Ac 8260 Firmware
11.8.90 / 12.0.85+
MEDIUM 5.5
CVE-2021-0170
Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some…
Amt Ac 8260 Firmware
11.8.90 / 12.0.85+
HIGH 7.5
CVE-2022-23619
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess …
Xwiki
12.10.9+
HIGH 8.8
CVE-2021-40360
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 …
Simatic Pcs 7
7.4+
HIGH 7.5
CVE-2022-21712
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following…
Debian Linux
22.1.0+
HIGH 7.5
CVE-2022-22680
Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 all…
Diskstation Manager
6.2.4-25556-3 / 7.0.1-42218-2+
MEDIUM 5.5
CVE-2021-36151
In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.…
Gobblin
after 0.15.0
HIGH 7.5
CVE-2021-38960
IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.
Power System Ac922 \(8335 Gtx\) Firmware
Mitigation only
MEDIUM 5.5
CVE-2020-12966
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure …
Epyc 7763 Firmware
Mitigation only
MEDIUM 6.5
CVE-2022-23607
treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq…
Debian Linux
22.1.0+
MEDIUM 6.8
CVE-2021-31567
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows a…
Download Monitor
after 4.4.6
HIGH 7.5
CVE-2021-40340
Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net info…
Linkone
Mitigation only
MEDIUM 5.3
CVE-2021-22815
A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninter…
Network Management Card 2 Firmware
after 6.9.8
HIGH 8.0
CVE-2021-22825
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with ele…
Rack Power Distribution Unit With Network Management Card 2 Firmware
1.2.0.2 / 7.0.6+