Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2021-41124 Scrapy-splash is a library which provides Scrapy and JavaScript integration. In affected versions users who use [`HttpAuthMiddleware`](http://doc.scr… Scrapy Splash 0.8.0+ Fix from $1,9502021-10-05 MEDIUM 5.3 CVE-2021-41123 Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application publishes /metrics endpoint ava… Survey Solutions 21.09.1+ Fix from $1,6002021-10-04 HIGH 7.5 CVE-2021-41092 Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-r… Command Line Interface 20.10.9+ Fix from $1,9502021-10-04 HIGH 7.5 CVE-2021-23855 The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore al… Rexroth Indramotion Xlc Firmware Mitigation only Fix from $1,9502021-10-04 HIGH 7.5 CVE-2021-23858 Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can … Rexroth Indramotion Mlc L20 Firmware after 12 Fix from $1,9502021-10-04 HIGH 7.5 CVE-2021-41109 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.4, for regular (non-Liv… Parse Server 4.10.4+ Fix from $1,9502021-09-30 CRITICAL 9.8 CVE-2021-41301 ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. T… Ecs Router Controller Ecs Firmware Mitigation only Fix from $2,3002021-09-30 MEDIUM 6.5 CVE-2021-39855 Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected b… Acrobat after 21.005.20060 Fix from $1,6002021-09-29 MEDIUM 6.5 CVE-2021-39856 Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected b… Acrobat after 21.005.20060 Fix from $1,6002021-09-29 CRITICAL 9.4 CVE-2021-22272 The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer … Mybuildings 2021-05-03+ Fix from $2,3002021-09-27 MEDIUM 5.5 CVE-2021-22276 The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point. System Access Point 2.0 Firmware 2.6.4+ Fix from $1,6002021-09-23 MEDIUM 5.5 CVE-2021-26333 An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) … Chipset Driver 3.08.17.735 / 5.17.0.0+ Fix from $1,6002021-09-21 HIGH 7.5 CVE-2021-41082 Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user… Discourse 2021-09-14+ Fix from $1,9502021-09-20 MEDIUM 6.5 CVE-2021-24585 The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive da… Timetable And Event Schedule 2.4.0+ Fix from $1,6002021-09-20 HIGH 7.5 CVE-2021-40690EPSS 7% All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is… Santuario Xml Security For Java 2.1.7 / 2.2.3+ Fix from $1,9502021-09-19 MEDIUM 5.3 CVE-2021-39327EPSS 72% The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible … Bulletproof Security after 5.1 Fix from $1,6002021-09-17 HIGH 8.8 CVE-2021-40862 HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which c… Terraform Enterprise after 202108-1 Fix from $1,9502021-09-15 MEDIUM 5.3 CVE-2021-39211 GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI an… Glpi 9.5.6+ Fix from $1,6002021-09-15 MEDIUM 5.3 CVE-2021-20582 IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties… Security Secret Server 11.0+ Fix from $1,6002021-09-14 HIGH 7.5 CVE-2021-22527 Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 Access Manager 4.5.4 / 5.0.1+ Fix from $1,9502021-09-13 MEDIUM 5.3 CVE-2021-39200 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output… WordPress 5.8.1+ Fix from $1,6002021-09-09 MEDIUM 6.5 CVE-2021-39203 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authen… WordPress Mitigation only Fix from $1,6002021-09-09 MEDIUM 5.5 CVE-2021-25464 An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak. Capture 4.8.02+ Fix from $1,6002021-09-09 MEDIUM 5.5 CVE-2021-34771 A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow. T… Ios Xr 7.3.2+ Fix from $1,6002021-09-09 MEDIUM 5.3 CVE-2021-37629 Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS … Richdocuments 3.8.4 / 4.2.1+ Fix from $1,6002021-09-07 HIGH 7.5 CVE-2020-7819 A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL … Ntracker Usb Enterprise after 5 Fix from $1,9502021-09-07 MEDIUM 5.3 CVE-2021-36095 Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition… Otrs 7.0.29+ Fix from $1,6002021-09-06 HIGH 7.2 CVE-2021-39192 Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authen… Ghost 4.10.0+ Fix from $1,9502021-09-03 MEDIUM 5.3 CVE-2021-38314EPSS 29% The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in… Gutenberg Template Library \& Redux Framework after 4.2.11 Fix from $1,6002021-09-02 HIGH 7.2 CVE-2021-22793 A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and Accu… Accusine Pcsp Pfvp Firmware 001.006.007 / 002.002.004+ Fix from $1,9502021-09-02