Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2021-20585 IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system… Security Verify Access Mitigation only Fix from $1,6002021-06-01 HIGH 7.5 CVE-2021-22892 An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed … Rocket.chat 3.11.3 / 3.12.2+ Fix from $1,9502021-05-27 MEDIUM 5.9 CVE-2021-22739 Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when… Spacelynk Firmware after 2.6.0 Fix from $1,6002021-05-26 MEDIUM 6.5 CVE-2021-22740 Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when … Spacelynk Firmware after 2.6.0 Fix from $1,6002021-05-26 HIGH 7.5 CVE-2021-23937 A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups fro… Wicket after 9.2.0 Fix from $1,9502021-05-25 MEDIUM 5.3 CVE-2021-32624 Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly discovered capability in our query… Keystone 5 after 19.3.2 Fix from $1,6002021-05-24 HIGH 7.5 CVE-2021-27434 Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions onl… .net Based Opc Ua Client\/server Sdk after 3.0.7 Fix from $1,9502021-05-20 MEDIUM 5.7 CVE-2021-3426 There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc… Python 2.7.18 / 3.6.13+ Fix from $1,6002021-05-20 MEDIUM 6.8 CVE-2021-32817 express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express rend… Express Handlebars after 5.3.2 Fix from $1,6002021-05-14 HIGH 8.8 CVE-2021-32819EPSS 60% Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine c… Squirrelly Patch available Fix from $1,9502021-05-14 HIGH 8.6 CVE-2021-32820EPSS 18% Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the… Express Handlebars after 5.3.2 Fix from $1,9502021-05-14 MEDIUM 5.3 CVE-2021-22137 In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries… Elasticsearch 6.8.15 / 7.11.2+ Fix from $1,6002021-05-13 MEDIUM 5.3 CVE-2021-22135 Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Docu… Elasticsearch 6.8.15 / 7.11.2+ Fix from $1,6002021-05-13 MEDIUM 5.3 CVE-2021-21424 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without… Symfony 3.4.48 / 4.4.23+ Fix from $1,6002021-05-13 MEDIUM 5.3 CVE-2021-20993 In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources locat… 0852 0303 Firmware after 1.2.3.s0 Fix from $1,6002021-05-13 HIGH 7.5 CVE-2021-20313 A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. T… Debian Linux 7.0.11-0+ Fix from $1,9502021-05-11 MEDIUM 5.3 CVE-2021-31173 Microsoft SharePoint Server Information Disclosure Vulnerability Sharepoint Foundation Patch available Fix from $1,6002021-05-11 HIGH 7.5 CVE-2021-31918 A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a… Openstack Mitigation only Fix from $1,9502021-05-06 MEDIUM 5.5 CVE-2021-21536 Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerabili… Hybrid Client 1.5+ Fix from $1,6002021-04-30 MEDIUM 5.5 CVE-2021-21537 Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerabili… Hybrid Client 1.5+ Fix from $1,6002021-04-30 HIGH 7.5 CVE-2021-20228 A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using th… Ansible Engine Patch available Fix from $1,9502021-04-29 HIGH 7.5 CVE-2021-29483 ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' API leaked the value of private configuration variables set through the ManageW… Managewiki 2021-04-28+ Fix from $1,9502021-04-28 CRITICAL 9.8 CVE-2021-30168 The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and furth… P2r8852e2 Firmware 7.1.94.8908+ Fix from $2,3002021-04-28 HIGH 7.5 CVE-2021-30169 The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential. P2r8852e2 Firmware 7.1.94.8908+ Fix from $1,9502021-04-28 HIGH 7.5 CVE-2021-30638EPSS 7% Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia… Tapestry 5.6.4 / 5.7.2+ Fix from $1,9502021-04-27 MEDIUM 6.5 CVE-2020-36319 Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensi… Flow 3.0.6 / 15.0.5+ Fix from $1,6002021-04-23 MEDIUM 5.3 CVE-2021-31545 An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked the existence of certain delet… Mediawiki after 1.35.2 Fix from $1,6002021-04-22 CRITICAL 9.8 CVE-2021-27850EPSS 94% A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,… Tapestry 5.6.2 / 5.7.1+ Fix from $2,3002021-04-15 HIGH 7.5 CVE-2021-24226EPSS 5% In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_for… Accessally 3.5.7+ Fix from $1,9502021-04-12 HIGH 7.5 CVE-2021-24227EPSS 6% The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone vi… Patreon Wordpress 1.7.0+ Fix from $1,9502021-04-12