Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2024-20991 Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12… HTTP Server Mitigation only Fix from $1,6002024-04-16 MEDIUM 5.3 CVE-2024-20990 Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: Templates). Supported versions that are affected … Applications Technology Stack after 12.2.13 Fix from $1,6002024-04-16 HIGH 7.5 CVE-2024-32086 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AitThemes Citadela Listing.This issue affects Citadela Listing: from n/a … Mitigation only Fix from $1,9502024-04-16 HIGH 7.5 CVE-2023-50872 The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about ce… Mitigation only Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-3574 In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a th… Scrapy 2.11.1+ Fix from $1,9502024-04-16 MEDIUM 6.0 CVE-2024-24891 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerabili… Mitigation only Fix from $1,6002024-04-15 MEDIUM 6.0 CVE-2024-24898 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerabili… Mitigation only Fix from $1,6002024-04-15 HIGH 7.8 CVE-2024-3780 A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerability allows a local attacker … Mitigation only Fix from $1,9502024-04-15 HIGH 8.3 CVE-2024-22435 A potential security vulnerability has been identified in Web ViewPoint Enterprise software. This vulnerability could be exploited to allow unauthori… No fix yet Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29842 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_A… Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29843 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, … Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29839 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_C… Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29840 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_P… Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29841 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_K… Evolution after 2.04.560 Fix from $1,9502024-04-15 HIGH 7.2 CVE-2024-29023 Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. Session tokens are exposed … Patch available Fix from $1,9502024-04-12 MEDIUM 5.9 CVE-2024-3689 A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown fun… O2oa after 2024-04-03 Fix from $1,6002024-04-12 HIGH 8.4 CVE-2024-30381 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Juniper Networks Paragon Active Assurance Control Center allows a netw… Paragon Active Assurance Control Center Mitigation only Fix from $1,9502024-04-12 HIGH 7.5 CVE-2024-3706 Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to view a php backup file (c… Opengnsys Mitigation only Fix from $1,9502024-04-12 HIGH 7.5 CVE-2024-29400 An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter. Ruoyi No fix yet Fix from $1,9502024-04-12 MEDIUM 6.2 CVE-2024-22734 An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive infor… Trux Waste Management 7.19.0018.26912+ Fix from $1,6002024-04-12 HIGH 7.5 CVE-2024-2966 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sen… Element Pack 5.6.0+ Fix from $1,9502024-04-11 HIGH 7.7 CVE-2024-2740 Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacke… Mitigation only Fix from $1,9502024-04-11 HIGH 7.5 CVE-2023-51142 An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information. Biotime No fix yet Fix from $1,9502024-04-11 CRITICAL 9.1 CVE-2024-1643 By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within tha… Patch available Fix from $2,3002024-04-10 MEDIUM 5.3 CVE-2024-31302 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from… Contact Form Email 1.3.44+ Fix from $1,6002024-04-10 MEDIUM 5.3 CVE-2024-2974 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive I… Essential Addons For Elementor 5.9.14+ Fix from $1,6002024-04-09 MEDIUM 5.3 CVE-2024-2093 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 … Vk All In One Expansion Unit 9.96.0.0+ Fix from $1,6002024-04-09 HIGH 7.5 CVE-2023-7046 The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is vulnerable to Sensitive I… Mitigation only Fix from $1,9502024-04-09 MEDIUM 6.5 CVE-2023-6777 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9… Wp Go Maps 9.0.35+ Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-28235 Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links… Contao 4.13.40 / 5.3.4+ Fix from $1,6002024-04-09