Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2021-25375 Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when … Email 6.1.14.0+ Fix from $1,6002021-04-09 MEDIUM 5.3 CVE-2021-25376 An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotia… Email 6.1.41.0+ Fix from $1,6002021-04-09 MEDIUM 5.5 CVE-2021-25357 A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), an… Android Mitigation only Fix from $1,6002021-04-09 MEDIUM 6.3 CVE-2021-3413 A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Az… Satellite 2.2.0+ Fix from $1,6002021-04-08 HIGH 8.8 CVE-2021-24163 The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, ther… Ninja Forms 3.4.34+ Fix from $1,9502021-04-05 HIGH 7.5 CVE-2021-24167 When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send an XMLHttpRequest request to … Web Stat 1.4.1+ Fix from $1,9502021-04-05 HIGH 7.5 CVE-2021-24170 The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functio… User Profile Picture 2.5.0+ Fix from $1,9502021-04-05 MEDIUM 6.5 CVE-2021-21400 wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being … Wire Webapp after 2019-07-11-13-18 Fix from $1,6002021-04-02 MEDIUM 6.5 CVE-2021-21421 node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer… Node Etsy Client after 0.3.0 Fix from $1,6002021-04-01 MEDIUM 5.3 CVE-2021-22876EPSS 5% curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in … Fedora after 7.75.0 Fix from $1,6002021-04-01 MEDIUM 5.3 CVE-2021-28164EPSS 82% In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to a… Jetty after 11.70.1 Fix from $1,6002021-04-01 MEDIUM 6.5 CVE-2021-21396 wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16 and before version 2021-03-0… Wire Server 2021-03-02+ Fix from $1,6002021-03-26 MEDIUM 5.5 CVE-2021-25369 KEV An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. Android Mitigation only Fix from $1,6002021-03-26 MEDIUM 5.3 CVE-2020-35518 When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an un… 389 Directory Server 1.4.3.19 / 1.4.4.13+ Fix from $1,6002021-03-26 MEDIUM 6.5 CVE-2021-23890 Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to do… Epolicy Orchestrator 5.9.1+ Fix from $1,6002021-03-26 MEDIUM 6.5 CVE-2021-21376 OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the cu… Omero.web 5.9.0+ Fix from $1,6002021-03-23 MEDIUM 5.5 CVE-2020-11199 HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, S… Apq8009 Firmware Mitigation only Fix from $1,6002021-03-17 MEDIUM 5.5 CVE-2020-11221 Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the… Apq8009 Firmware Mitigation only Fix from $1,6002021-03-17 MEDIUM 5.3 CVE-2021-20281 It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5,… Moodle 3.5.17 / 3.8.8+ Fix from $1,6002021-03-15 HIGH 7.5 CVE-2021-26923 An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is … Argo Cd 1.7.12 / 1.8.4+ Fix from $1,9502021-03-15 MEDIUM 5.5 CVE-2021-21364 swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen… Swagger Codegen 2.4.19+ Fix from $1,6002021-03-11 MEDIUM 5.3 CVE-2021-21360 Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSet… Products.genericsetup 2.1.1+ Fix from $1,6002021-03-09 MEDIUM 6.5 CVE-2021-21336 Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t… Products.pluggableauthservice 2.6.0+ Fix from $1,6002021-03-08 HIGH 7.5 CVE-2021-25122EPSS 18% When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate re… Tomcat 21.3.0+ Fix from $1,9502021-03-01 CRITICAL 9.0 CVE-2021-26566 Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-i… Diskstation Manager 6.2.3-25426-3+ Fix from $2,3002021-02-26 CRITICAL 9.1 CVE-2020-28199 best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor. Amazon Pay 9.4.2+ Fix from $2,3002021-02-26 MEDIUM 5.3 CVE-2021-21621 Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details onl… Support Core after 2.72 Fix from $1,6002021-02-24 MEDIUM 5.3 CVE-2021-20256 A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts perm… Satellite Mitigation only Fix from $1,6002021-02-23 MEDIUM 5.3 CVE-2021-21323 Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME adblocking feature added in B… Brave after 1.20.103 Fix from $1,6002021-02-23 HIGH 7.5 CVE-2021-26593 In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of infor… Directus after 8.8.1 Fix from $1,9502021-02-23