Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2024-34005 In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore databa… Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 MEDIUM 6.5 CVE-2021-44534 Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure. Mitigation only Fix from $1,6002024-05-31 MEDIUM 5.3 CVE-2024-5524 Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal li… Astrotalks Mitigation only Fix from $1,6002024-05-31 MEDIUM 6.5 CVE-2024-35189 Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records a… Fides 2.37.0+ Fix from $1,6002024-05-30 HIGH 7.7 CVE-2024-36955 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node() The docum… Linux Kernel 5.15.159 / 6.1.91+ Fix from $1,9502024-05-30 HIGH 8.4 CVE-2024-36910 In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Don't free decrypted memory In CoCo VMs it is possible for the … Linux Kernel 6.1.91 / 6.6.31+ Fix from $1,9502024-05-30 HIGH 8.6 CVE-2024-24919 KEVEPSS 100% Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote … Quantum Spark Firmware Patch available Fix from $1,9502024-05-28 MEDIUM 5.3 CVE-2024-36107 MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` heade… Patch available Fix from $1,6002024-05-28 HIGH 7.5 CVE-2024-35341 Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFile.ini or … Mitigation only Fix from $1,9502024-05-28 CRITICAL 9.8 CVE-2024-35343 Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/… Mitigation only Fix from $2,3002024-05-28 MEDIUM 6.5 CVE-2024-5354 A vulnerability classified as problematic was found in anji-plus AJ-Report up to 1.4.1. This vulnerability affects unknown code of the file /reportSh… Aj Report after 1.4.1 Fix from $1,6002024-05-26 HIGH 7.7 CVE-2024-5202 Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservices Mitigation only Fix from $1,9502024-05-23 MEDIUM 5.3 CVE-2024-28188 Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-schedu… Patch available Fix from $1,6002024-05-23 MEDIUM 5.3 CVE-2024-35223 Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app in… Patch available Fix from $1,6002024-05-23 MEDIUM 5.3 CVE-2024-5230EPSS 19% A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functio… No fix yet Fix from $1,6002024-05-23 HIGH 8.1 CVE-2024-21902 An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploit… Qts Mitigation only Fix from $1,9502024-05-21 HIGH 7.1 CVE-2021-47403 In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix module reference leak A reference to the carrier module was… Linux Kernel 4.4.286 / 4.9.285+ Fix from $1,9502024-05-21 HIGH 7.5 CVE-2024-1968 In scrapy/scrapy, an issue was identified where the Authorization header is not removed during redirects that only change the scheme (e.g., HTTPS to … Scrapy 2.11.2+ Fix from $1,9502024-05-20 MEDIUM 5.3 CVE-2024-5096 A vulnerability classified as problematic was found in Hipcam Device up to 20240511. This vulnerability affects unknown code of the file /log/wifi.ma… Mitigation only Fix from $1,6002024-05-19 HIGH 7.5 CVE-2024-32131 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affe… Download Manager 3.2.83+ Fix from $1,9502024-05-17 MEDIUM 6.5 CVE-2024-3182 Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6… Mitigation only Fix from $1,6002024-05-15 MEDIUM 5.3 CVE-2024-4837 In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Se… Telerik Report Server 10.1.24.514+ Fix from $1,6002024-05-15 MEDIUM 5.3 CVE-2024-34717 PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by s… Prestashop Mitigation only Fix from $1,6002024-05-14 MEDIUM 5.3 CVE-2024-34358 TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS… TYPO3 9.5.48 / 10.4.45+ Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-33865 An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endp… Linqi 1.4.0.1+ Fix from $1,9502024-05-14 MEDIUM 5.3 CVE-2024-27947 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwarded to a s… Ruggedcom Crossbow 5.5+ Fix from $1,6002024-05-14 MEDIUM 6.0 CVE-2024-22270 VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor … Workstation 13.5.2 / 17.5.2+ Fix from $1,6002024-05-14 MEDIUM 6.0 CVE-2024-22269 VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative p… Workstation 13.5.2 / 17.5.2+ Fix from $1,6002024-05-14 MEDIUM 5.3 CVE-2024-35171 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.… Academy Lms 1.9.26+ Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-35166 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3. Filebird 5.6.4+ Fix from $1,9502024-05-14