Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
CRITICAL 9.1 CVE-2024-42049 TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection. Mitigation only Fix from $2,3002024-07-28 MEDIUM 5.3 CVE-2024-5614 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 vi… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-6569 The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is d… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-6573 The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not p… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-6546 The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to t… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-6547 The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin … Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-6548 The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to the plu… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-6549 The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to the pl… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-6566 The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due … Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-6545 The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to the p… Mitigation only Fix from $1,6002024-07-27 MEDIUM 5.3 CVE-2024-7128 A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions.… Mitigation only Fix from $1,6002024-07-26 MEDIUM 5.0 CVE-2024-7091 An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting f… GitLab 17.0.5 / 17.1.3+ Fix from $1,6002024-07-24 MEDIUM 6.5 CVE-2024-7060 An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1… GitLab 17.0.5 / 17.1.3+ Fix from $1,6002024-07-24 HIGH 7.5 CVE-2024-41672 DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with… Duckdb 1.1.0+ Fix from $1,9502024-07-24 HIGH 7.5 CVE-2024-39676 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. U… Pinot 1.0.0+ Fix from $1,9502024-07-24 MEDIUM 5.3 CVE-2024-6553 The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.3… Wp Meteor 3.4.4+ Fix from $1,6002024-07-24 MEDIUM 5.3 CVE-2024-6571 The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and… Optimize Images Alt Text \(alt Tag\) \& Names For Seo Using Ai 3.1.2+ Fix from $1,6002024-07-24 HIGH 8.8 CVE-2024-23321 For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i… Rocketmq 5.3.0+ Fix from $1,9502024-07-22 MEDIUM 5.3 CVE-2024-6560 The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. Th… Mitigation only Fix from $1,6002024-07-20 MEDIUM 5.3 CVE-2024-6455 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a miss… Elements Kit Elementor Addons 3.2.1+ Fix from $1,6002024-07-18 MEDIUM 5.3 CVE-2024-40647 sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocess… Patch available Fix from $1,6002024-07-18 MEDIUM 5.3 CVE-2024-40633 Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, whi… Mitigation only Fix from $1,6002024-07-17 MEDIUM 6.5 CVE-2024-20396 A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. … Webex Teams Mitigation only Fix from $1,6002024-07-17 HIGH 8.1 CVE-2024-21152 Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Allocation Rules). Supported versions th… Process Manufacturing Financials after 12.2.13 Fix from $1,9502024-07-16 HIGH 7.4 CVE-2024-21147 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo… Active Iq Unified Manager Mitigation only Fix from $1,9502024-07-16 HIGH 8.6 CVE-2024-21136 Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected a… Retail Xstore Office Mitigation only Fix from $1,9502024-07-16 MEDIUM 5.3 CVE-2024-6395 An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories… Enterprise Server 3.9.17 / 3.10.14+ Fix from $1,6002024-07-16 MEDIUM 5.3 CVE-2024-6336 A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterp… Enterprise Server 3.9.17 / 3.10.14+ Fix from $1,6002024-07-16 MEDIUM 6.3 CVE-2020-25836 Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects … Mitigation only Fix from $1,6002024-07-16 MEDIUM 6.5 CVE-2022-45449 Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15… Cyber Protect 15+ Fix from $1,6002024-07-16