Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2024-11291 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive … Membership \& Content Restriction Paid Member Subscriptions 2.13.5+ Fix from $1,6002024-12-18 MEDIUM 5.3 CVE-2024-11295 The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 … Mitigation only Fix from $1,6002024-12-18 MEDIUM 5.3 CVE-2024-12250 The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includin… Mitigation only Fix from $1,6002024-12-18 MEDIUM 5.3 CVE-2024-11280 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 vi… Mitigation only Fix from $1,6002024-12-17 HIGH 8.8 CVE-2024-8326 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable … Mitigation only Fix from $1,9502024-12-17 MEDIUM 5.3 CVE-2024-11294 The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress cor… Mitigation only Fix from $1,6002024-12-17 MEDIUM 5.5 CVE-2021-26281 Some parameters of the alarm clock module are improperly stored, leaking some sensitive information. No fix yet Fix from $1,6002024-12-17 MEDIUM 5.9 CVE-2021-26279 Some parameters of the weather module are improperly stored, leaking some sensitive information. No fix yet Fix from $1,6002024-12-17 MEDIUM 5.3 CVE-2024-35230 GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and… Geoserver 2.25.1+ Fix from $1,6002024-12-16 MEDIUM 5.3 CVE-2024-12578 The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via … Mitigation only Fix from $1,6002024-12-14 HIGH 8.7 CVE-2024-55946 Playloom Engine is an open-source, high-performance game development engine. Engine Beta v0.0.1 has a security vulnerability related to data storage,… Mitigation only Fix from $1,9502024-12-13 MEDIUM 5.3 CVE-2024-9945 An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resou… Mitigation only Fix from $1,6002024-12-13 CRITICAL 9.8 CVE-2024-55875 http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vuln… Patch available Fix from $2,3002024-12-12 HIGH 7.5 CVE-2024-54119 Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confident… Harmonyos No fix yet Fix from $1,9502024-12-12 HIGH 7.5 CVE-2024-54117 Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confident… Harmonyos No fix yet Fix from $1,9502024-12-12 MEDIUM 6.9 CVE-2024-12564 Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installi… Mitigation only Fix from $1,6002024-12-12 MEDIUM 5.3 CVE-2024-12255 The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 … Accept Stripe Payments Using Contact Form 7 2.6+ Fix from $1,6002024-12-12 MEDIUM 5.3 CVE-2024-11351 The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Expos… Mitigation only Fix from $1,6002024-12-11 MEDIUM 5.3 CVE-2024-11008 The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… Mitigation only Fix from $1,6002024-12-11 MEDIUM 5.7 CVE-2024-53244 In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a … Splunk 9.1.7 / 9.1.2312.206+ Fix from $1,6002024-12-10 MEDIUM 5.3 CVE-2024-11106 The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPres… Mitigation only Fix from $1,6002024-12-10 HIGH 7.5 CVE-2024-54151 Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting… Directus 11.3.0+ Fix from $1,9502024-12-09 HIGH 7.5 CVE-2024-54137 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been iden… Liboqs 0.12.0+ Fix from $1,9502024-12-06 MEDIUM 5.3 CVE-2024-11292 The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the … Mitigation only Fix from $1,6002024-12-06 HIGH 8.3 CVE-2024-54134 A publish-access account was compromised for `@solana/web3.js`, a JavaScript library that is commonly used by Solana dapps. This allowed an attacker … Mitigation only Fix from $1,9502024-12-04 HIGH 7.5 CVE-2024-53862 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When using `--auth-mode=client`, Arc… Argo Workflows 3.5.13 / 3.6.2+ Fix from $1,9502024-12-02 HIGH 7.5 CVE-2024-11961 A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function pre… Jeewms No fix yet Fix from $1,9502024-11-28 MEDIUM 6.5 CVE-2024-53858 The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that could leak authentication toke… Mitigation only Fix from $1,6002024-11-27 HIGH 7.5 CVE-2024-53859 go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerability has been identified in … Go Gh 2.11.1+ Fix from $1,9502024-11-27 HIGH 8.1 CVE-2024-52323 Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve s… Manageengine Analytics Plus 6.1+ Fix from $1,9502024-11-27