Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2019-5640 Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an a… Nexpose 6.6.114+ Fix from $1,6002021-11-22 MEDIUM 5.3 CVE-2021-41532 In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access… Ozone 1.2.0+ Fix from $1,6002021-11-19 MEDIUM 6.5 CVE-2021-23193 Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrie… Command Centre 8.20.1291 / 8.30.1454+ Fix from $1,6002021-11-18 HIGH 7.5 CVE-2021-41277 KEVEPSS 97% Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->se… Metabase Patch available Fix from $1,9502021-11-17 MEDIUM 5.3 CVE-2021-41271 Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by in… Discourse after 2.7.9 Fix from $1,6002021-11-15 HIGH 8.8 CVE-2021-41263 rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails… Rails Multisite 4.0.0+ Fix from $1,9502021-11-15 CRITICAL 9.1 CVE-2021-30284 Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Comput… Apq8009 Firmware Mitigation only Fix from $2,3002021-11-12 MEDIUM 5.9 CVE-2021-41251 @sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform abstractions. This affects a… Cloud Sdk 1.52.0+ Fix from $1,6002021-11-05 MEDIUM 5.3 CVE-2021-39898 In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project whi… GitLab 14.1.7 / 14.2.5+ Fix from $1,6002021-11-05 HIGH 7.5 CVE-2021-22044 In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapp… Spring Cloud Openfeign after 3.0.4 Fix from $1,9502021-10-28 MEDIUM 5.3 CVE-2021-22047 In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a … Spring Data Rest after 3.5.5 Fix from $1,6002021-10-28 HIGH 7.5 CVE-2021-41158 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.10.7+ Fix from $1,9502021-10-26 MEDIUM 5.3 CVE-2021-39223 Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to versions 3.8.6 and 4.2.3 returned ve… Richdocuments 3.8.6 / 4.2.3+ Fix from $1,6002021-10-25 MEDIUM 5.3 CVE-2021-39224 Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version 1.1.1 returned verbatim excep… Officeonline 1.1.1+ Fix from $1,6002021-10-25 MEDIUM 5.3 CVE-2017-20007 Ingeteam INGEPAC DA AU AUC_1.13.0.28 (and before) web application allows access to a certain path that contains sensitive information that could be u… Ingepac Da Au Firmware Mitigation only Fix from $1,6002021-10-25 MEDIUM 6.5 CVE-2021-42536 The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables. Wireless 1410 Gateway Firmware 4.7.94+ Fix from $1,6002021-10-22 MEDIUM 5.3 CVE-2021-31380 A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a special… Session And Resource Control 4.12.0r5 / 4.13.0r3+ Fix from $1,6002021-10-19 CRITICAL 9.1 CVE-2021-31381 A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a special… Session And Resource Control 4.12.0r5 / 4.13.0r3+ Fix from $2,3002021-10-19 MEDIUM 5.3 CVE-2021-31371 Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing t… Junos after 17.2 Fix from $1,6002021-10-19 MEDIUM 5.3 CVE-2021-31352 An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers,… Session And Resource Control 4.130r6+ Fix from $1,6002021-10-19 MEDIUM 5.3 CVE-2021-41140 Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given … Discourse Reactions 0.2+ Fix from $1,6002021-10-19 MEDIUM 6.5 CVE-2021-22036 VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able… Vrealize Automation 8.6+ Fix from $1,6002021-10-13 MEDIUM 5.3 CVE-2021-20832 InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerability which may lead to inform… Inbody 2.2.90 / 2.3.30+ Fix from $1,6002021-10-13 MEDIUM 6.5 CVE-2021-33727 A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any… Sinec Nms 1.0+ Fix from $1,6002021-10-12 MEDIUM 6.5 CVE-2021-32028 A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user coul… PostgreSQL 9.6.22 / 10.17+ Fix from $1,6002021-10-11 MEDIUM 6.5 CVE-2021-32029 A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary… PostgreSQL 11.12 / 12.7+ Fix from $1,6002021-10-08 HIGH 7.5 CVE-2021-42089 An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information. Zammad 4.1.1+ Fix from $1,9502021-10-07 MEDIUM 6.5 CVE-2021-41125 Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a… Debian Linux 1.8.1 / 2.5.1+ Fix from $1,6002021-10-06 MEDIUM 5.5 CVE-2021-0644 In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permiss… Android Patch available Fix from $1,6002021-10-06 HIGH 7.5 CVE-2021-41120 sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was… Paypal 1.2.4 / 1.3.1+ Fix from $1,9502021-10-05