Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2024-29199 Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to u… Nautobot 1.6.16 / 2.1.9+ Fix from $1,6002024-03-26 MEDIUM 5.3 CVE-2022-32751 IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-For… Security Verify Directory Mitigation only Fix from $1,6002024-03-22 HIGH 7.5 CVE-2024-2725 Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all … Ciges Mitigation only Fix from $1,9502024-03-22 MEDIUM 5.5 CVE-2024-2728 Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of pro… Ciges Mitigation only Fix from $1,6002024-03-22 MEDIUM 5.5 CVE-2024-27277 The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certific… Storage Protect Plus after 10.1.6 Fix from $1,6002024-03-21 HIGH 7.5 CVE-2023-49981 A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the applicati… School Fees Management System No fix yet Fix from $1,9502024-03-21 MEDIUM 6.5 CVE-2024-29036 Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authentica… React Storefront 1.0.2+ Fix from $1,6002024-03-20 MEDIUM 6.5 CVE-2024-27286 Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only… Zulip Server 8.3+ Fix from $1,6002024-03-20 MEDIUM 5.3 CVE-2024-1477 The Easy Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the RE… Mitigation only Fix from $1,6002024-03-20 HIGH 7.5 CVE-2024-2632 A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot of information about the appli… Mitigation only Fix from $1,9502024-03-19 HIGH 7.5 CVE-2023-40278 An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp compone… Openclinic Ga No fix yet Fix from $1,9502024-03-19 CRITICAL 9.1 CVE-2023-40275 An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchBy… Openclinic Ga Mitigation only Fix from $2,3002024-03-19 CRITICAL 9.1 CVE-2023-40276 An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp. Openclinic Ga No fix yet Fix from $2,3002024-03-19 MEDIUM 5.3 CVE-2024-26119 Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature by… Experience Manager 6.5.20.0 / 2024.3.0+ Fix from $1,6002024-03-18 MEDIUM 5.3 CVE-2024-26063 Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature by… Experience Manager 6.5.20.0 / 2024.3.0+ Fix from $1,6002024-03-18 HIGH 8.8 CVE-2024-27769 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking O… Unilogic 1.35.227+ Fix from $1,9502024-03-18 HIGH 7.5 CVE-2024-25591 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Benjamin Rojas WP Editor.This issue affects WP Editor: from n/a through 1… Wp Editor 1.2.8+ Fix from $1,9502024-03-17 HIGH 7.5 CVE-2024-25903 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: f… Frontend File Manager 22.8+ Fix from $1,9502024-03-17 HIGH 7.5 CVE-2024-24867 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Osamaesh WP Visitor Statistics (Real Time Traffic).This issue affects WP … Visitor Statistics after 6.9.4 Fix from $1,9502024-03-17 HIGH 7.5 CVE-2024-25933 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ul… Peprodev Ultimate Invoice 1.9.8+ Fix from $1,9502024-03-17 MEDIUM 6.5 CVE-2024-23523 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Elementor Pro.This issue affects Elementor Pro: from n/a through 3.19.2. No fix yet Fix from $1,6002024-03-16 MEDIUM 5.3 CVE-2024-24845 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sewpafly Post Thumbnail Editor.This issue affects Post Thumbnail Editor: … No fix yet Fix from $1,6002024-03-16 HIGH 7.5 CVE-2024-28242 Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have… Discourse 3.2.0 / 3.3.0+ Fix from $1,9502024-03-15 MEDIUM 5.3 CVE-2024-24748 Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a pu… Discourse after 3.2.0 Fix from $1,6002024-03-15 MEDIUM 6.5 CVE-2024-28849 follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versi… Follow Redirects 1.15.6+ Fix from $1,6002024-03-14 MEDIUM 6.5 CVE-2024-28193 your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to create a public token in the setti… Your Spotify 1.8.0+ Fix from $1,6002024-03-13 HIGH 7.5 CVE-2024-2106 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to,… Masterstudy Lms 3.2.11+ Fix from $1,9502024-03-13 MEDIUM 5.3 CVE-2024-1083 The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.6 via the REST API… Simple Restrict 1.2.7+ Fix from $1,6002024-03-13 MEDIUM 6.5 CVE-2024-28236 Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution c… Worker 0.23.2+ Fix from $1,6002024-03-12 MEDIUM 5.4 CVE-2024-28339 An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to … Cbk40 Firmware No fix yet Fix from $1,6002024-03-12