Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2024-8461 A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discover… Dns 320 Firmware No fix yet Fix from $1,6002024-09-05 MEDIUM 5.9 CVE-2024-8460 A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue is some unknown functionality … Dns 320 Firmware No fix yet Fix from $1,6002024-09-05 MEDIUM 5.3 CVE-2024-6835 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via… Ivory Search 5.5.7+ Fix from $1,6002024-09-05 MEDIUM 5.5 CVE-2024-20503 A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affect… Duo Authentication For Epic Mitigation only Fix from $1,6002024-09-04 MEDIUM 6.1 CVE-2024-44820 A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When ac… Zzcms after 2023 Fix from $1,6002024-09-04 MEDIUM 6.5 CVE-2024-8106 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… Wp Extended 3.0.9+ Fix from $1,6002024-09-04 MEDIUM 5.5 CVE-2024-45447 Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,6002024-09-04 HIGH 7.5 CVE-2024-45450 Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidential… Emui No fix yet Fix from $1,9502024-09-04 HIGH 7.5 CVE-2024-45391 Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a… Tinacms\/cli 1.6.2+ Fix from $1,9502024-09-03 HIGH 7.5 CVE-2024-45388EPSS 56% Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler… Hoverfly 1.10.3+ Fix from $1,9502024-09-02 MEDIUM 5.4 CVE-2024-43801 Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack again… Jellyfin after 10.9.10 Fix from $1,6002024-09-02 HIGH 7.5 CVE-2024-2541 The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscriber… Popup Builder after 4.3.3 Fix from $1,9502024-08-29 HIGH 7.5 CVE-2024-3679 The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.0… Wp Seo Plugin after 1.6.001 Fix from $1,9502024-08-29 MEDIUM 5.3 CVE-2024-6551 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including… Givewp 3.16.0+ Fix from $1,6002024-08-29 MEDIUM 5.3 CVE-2024-45043 The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream messages and parsing the records … Patch available Fix from $1,6002024-08-28 MEDIUM 6.7 CVE-2024-45054 Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resources. If a malicious user can ac… Hwameistor 0.14.6+ Fix from $1,6002024-08-28 MEDIUM 5.5 CVE-2021-22529 A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication v… Netiq Advanced Authentication 6.3+ Fix from $1,6002024-08-28 MEDIUM 5.3 CVE-2024-6448 The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 7.7.0. This is d… Mollie Payments For Woocommerce 7.8.0+ Fix from $1,6002024-08-28 CRITICAL 9.8 CVE-2024-6633 The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of the… Filecatalyst Workflow 5.1.7+ Fix from $2,3002024-08-27 MEDIUM 6.5 CVE-2024-43251 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit Form Pro: from n/a through 2… Bit Form after 2.6.4 Fix from $1,6002024-08-26 MEDIUM 6.5 CVE-2024-43257 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - … Leopard after 2.0.36 Fix from $1,6002024-08-26 HIGH 7.5 CVE-2024-43258 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a throug… Store Locator Plus after 2311.17.01 Fix from $1,9502024-08-26 HIGH 7.5 CVE-2024-43289 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a thro… Wpforo Forum 2.3.5+ Fix from $1,9502024-08-26 MEDIUM 5.3 CVE-2023-48957 PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP o… Purevpn No fix yet Fix from $1,6002024-08-25 MEDIUM 6.5 CVE-2024-42337 CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Identity No fix yet Fix from $1,6002024-08-25 MEDIUM 5.3 CVE-2024-6499 The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This m… Maxbuttons 9.8.0+ Fix from $1,6002024-08-24 MEDIUM 5.3 CVE-2024-8072 Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users Mage Ai No fix yet Fix from $1,6002024-08-22 HIGH 8.1 CVE-2024-39344 An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via … Mitigation only Fix from $1,9502024-08-21 MEDIUM 5.1 CVE-2022-26327 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive… Mitigation only Fix from $1,6002024-08-21 MEDIUM 5.3 CVE-2024-6568 The Flamix: Bitrix24 and Contact Form 7 integrations plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including,… Mitigation only Fix from $1,6002024-08-21