Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2024-42006 Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure. Aws Orchestrator 2.01+ Fix from $1,9502024-08-20 HIGH 7.5 CVE-2024-41700 Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor Sip Client Firmware No fix yet Fix from $1,9502024-08-20 HIGH 7.5 CVE-2024-41698 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Priority 24.0+ Fix from $1,9502024-08-20 HIGH 7.5 CVE-2024-7925 A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/e… Zzcms No fix yet Fix from $1,9502024-08-19 CRITICAL 9.8 CVE-2024-42658 An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter Ntpl Xpon1gfevn Firmware Mitigation only Fix from $2,3002024-08-19 HIGH 7.5 CVE-2024-42657 An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption dur… Ntpl Xpon1gfevn Firmware Mitigation only Fix from $1,9502024-08-19 HIGH 7.2 CVE-2024-42486 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1… Cilium after 1.15.8 Fix from $1,9502024-08-16 HIGH 7.5 CVE-2024-7630 The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2… Relevanssi 4.23.0+ Fix from $1,9502024-08-16 HIGH 7.5 CVE-2024-7843 A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function … Online Graduate Tracer System No fix yet Fix from $1,9502024-08-15 HIGH 7.5 CVE-2024-7842 A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unk… Online Graduate Tracer System No fix yet Fix from $1,9502024-08-15 MEDIUM 6.1 CVE-2024-27731 Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filterin… Friendica Patch available Fix from $1,6002024-08-15 MEDIUM 5.3 CVE-2024-7411 The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not pr… Mitigation only Fix from $1,6002024-08-15 HIGH 7.5 CVE-2024-27120 A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacke… Comfortkey 24.1.2+ Fix from $1,9502024-08-14 MEDIUM 6.5 CVE-2024-39822 Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an … Workplace Desktop 6.0.12 / 6.1.0+ Fix from $1,6002024-08-14 HIGH 7.5 CVE-2024-38749 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality N… Olive One Click Demo Import after 1.1.2 Fix from $1,9502024-08-13 MEDIUM 5.3 CVE-2024-38756 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrai… Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.3 CVE-2024-38760 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properl… Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.3 CVE-2024-38742 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Accessing Functionality Not Properl… Mitigation only Fix from $1,6002024-08-13 HIGH 7.5 CVE-2024-38747 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce a… Mitigation only Fix from $1,9502024-08-13 MEDIUM 5.3 CVE-2024-41733 In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to lear… Commerce Mitigation only Fix from $1,6002024-08-13 CRITICAL 9.1 CVE-2024-33003 Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile number… Commerce Cloud Mitigation only Fix from $2,3002024-08-13 MEDIUM 5.3 CVE-2024-37924 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Cons… Mitigation only Fix from $1,6002024-08-12 HIGH 7.5 CVE-2024-7704 A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/… E Cology No fix yet Fix from $1,9502024-08-12 HIGH 7.5 CVE-2024-7697 Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks. Carlcare No fix yet Fix from $1,9502024-08-12 MEDIUM 5.3 CVE-2024-7412 The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin … No Update Nag after 1.4.12 Fix from $1,6002024-08-12 MEDIUM 5.3 CVE-2024-7413 The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin… Mitigation only Fix from $1,6002024-08-12 MEDIUM 5.3 CVE-2024-7414 The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.116. This is due to … Mitigation only Fix from $1,6002024-08-12 MEDIUM 5.3 CVE-2024-7416 The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7. This is due to the plugin a… Mitigation only Fix from $1,6002024-08-12 MEDIUM 5.3 CVE-2024-7382 The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the plugin ut… Mitigation only Fix from $1,6002024-08-12 MEDIUM 5.3 CVE-2024-7410 The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.3. This is due the plu… Mitigation only Fix from $1,6002024-08-12