Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2024-11083 The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress… Profilepress 4.15.19+ Fix from $1,6002024-11-27 MEDIUM 5.5 CVE-2017-18306 Information disclosure due to uninitialized variable. Sd 450 Firmware No fix yet Fix from $1,6002024-11-26 MEDIUM 5.5 CVE-2017-18307 Information disclosure possible while audio playback. Sd 450 Firmware No fix yet Fix from $1,6002024-11-26 MEDIUM 5.7 CVE-2024-7391 ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sen… Home Flex Firmware Mitigation only Fix from $1,6002024-11-22 HIGH 7.5 CVE-2024-38647 An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attac… Ai Core Mitigation only Fix from $1,9502024-11-22 MEDIUM 5.8 CVE-2024-8929 In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of… PHP 8.1.31 / 8.2.26+ Fix from $1,6002024-11-22 HIGH 7.5 CVE-2024-11088 The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPr… Simple Membership 4.5.6+ Fix from $1,9502024-11-21 MEDIUM 5.3 CVE-2024-11089 The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via… Anonymous Restricted Content 1.6.6+ Fix from $1,6002024-11-21 HIGH 7.5 CVE-2024-51163 A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive informati… Mitigation only Fix from $1,9502024-11-20 MEDIUM 6.5 CVE-2024-52506 Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and scheduling of reports which contai… Graylog 6.1.2+ Fix from $1,6002024-11-18 MEDIUM 5.3 CVE-2024-43416 GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unauthenticated user can use an ap… Glpi 10.0.17+ Fix from $1,6002024-11-18 HIGH 7.5 CVE-2024-45791 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Us… Hertzbeat 1.6.1+ Fix from $1,9502024-11-18 HIGH 8.1 CVE-2024-52508 Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an email addre… Mail 1.14.6 / 1.15.4+ Fix from $1,9502024-11-15 MEDIUM 6.5 CVE-2024-52523 Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, th… Nextcloud Server 25.0.13.14 / 26.0.13.10+ Fix from $1,6002024-11-15 MEDIUM 5.9 CVE-2024-52517 Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into th… Nextcloud Server 25.0.13.13 / 26.0.13.9+ Fix from $1,6002024-11-15 MEDIUM 5.3 CVE-2022-20648 A vulnerability in a debug function for Cisco&nbsp;RCM for Cisco&nbsp;StarOS Software could allow an unauthenticated, remote attacker to perform debu… Mitigation only Fix from $1,6002024-11-15 MEDIUM 5.7 CVE-2024-8979 The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sens… Essential Addons For Elementor 6.0.10+ Fix from $1,6002024-11-15 MEDIUM 5.7 CVE-2024-8978 The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sens… Essential Addons For Elementor 6.0.10+ Fix from $1,6002024-11-15 HIGH 7.5 CVE-2024-47915 VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor No fix yet Fix from $1,9502024-11-14 HIGH 7.5 CVE-2024-52297 Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed… Tolgee Patch available Fix from $1,9502024-11-12 MEDIUM 5.4 CVE-2024-46894 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorizatio… Sinec Ins after 1.0 Fix from $1,6002024-11-12 MEDIUM 5.3 CVE-2024-8756 The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0… Mitigation only Fix from $1,6002024-11-09 HIGH 7.5 CVE-2024-10285 The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions up to, and including, 2.2.0.… Ce21 Suite after 2.2.0 Fix from $1,9502024-11-09 MEDIUM 6.5 CVE-2024-48011 Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privile… Data Domain Operating System 7.7.5.50+ Fix from $1,6002024-11-08 MEDIUM 6.5 CVE-2024-10965 A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the fi… Neuron after 2.10.0 Fix from $1,6002024-11-07 MEDIUM 6.5 CVE-2024-20507 A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in c… Meeting Management 3.10.0+ Fix from $1,6002024-11-06 MEDIUM 6.5 CVE-2024-20457 A vulnerability in the logging component of Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an authe… Unified Communications Manager Im And Presence Service Mitigation only Fix from $1,6002024-11-06 MEDIUM 5.3 CVE-2024-20445 A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthe… Desk Phone 9841 Firmware 14.3+ Fix from $1,6002024-11-06 HIGH 7.5 CVE-2024-6861 A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for atta… Mitigation only Fix from $1,9502024-11-06 MEDIUM 5.3 CVE-2024-10916 A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown p… Dns 320 Firmware No fix yet Fix from $1,6002024-11-06