Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2024-28340 An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attacker… Cbk40 Firmware No fix yet Fix from $1,9502024-03-12 MEDIUM 5.5 CVE-2024-26177 Windows Kernel Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20526 / 10.0.14393.6796+ Fix from $1,6002024-03-12 MEDIUM 5.5 CVE-2024-1302 Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application… Monitool 4.7+ Fix from $1,6002024-03-12 MEDIUM 6.2 CVE-2024-2371 Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol uses plaintext to transfer da… Mitigation only Fix from $1,6002024-03-12 MEDIUM 5.3 CVE-2024-0906 The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. T… F\(x\) Private Site after 1.2.1 Fix from $1,6002024-03-12 HIGH 7.5 CVE-2024-28120 codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check … Codeium No fix yet Fix from $1,9502024-03-11 MEDIUM 5.3 CVE-2024-25114 Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "K… Online 21.11.9.4 / 22.05.22+ Fix from $1,6002024-03-11 HIGH 7.5 CVE-2024-26309 Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could pote… Archer 6.14.0.2.2+ Fix from $1,9502024-03-08 MEDIUM 5.5 CVE-2023-28826 This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4… Ipados 12.7.4 / 13.6.5+ Fix from $1,6002024-03-08 CRITICAL 9.8 CVE-2024-24765 CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files … Casaos 0.4.7+ Fix from $2,3002024-03-06 MEDIUM 5.5 CVE-2024-20292 A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view s… Duo Authentication For Windows Logon And Rdp 4.3.0+ Fix from $1,6002024-03-06 MEDIUM 6.1 CVE-2023-48644 An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance module… Archibus Mitigation only Fix from $1,6002024-03-05 MEDIUM 5.3 CVE-2024-1769 The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14 via the meta description dat… Jm Twitter Cards 14.1.0+ Fix from $1,6002024-03-05 HIGH 7.5 CVE-2022-43890 IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att… Security Verify Privilege On Premises after 11.5 Fix from $1,9502024-03-04 MEDIUM 5.9 CVE-2024-20019 In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional execut… Software Package after 2023.11.10 Fix from $1,6002024-03-04 MEDIUM 6.5 CVE-2019-25210 An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is use… Helm Mitigation only Fix from $1,6002024-03-03 MEDIUM 6.5 CVE-2024-0765 As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and r… Anythingllm 1.0.0+ Fix from $1,6002024-03-03 HIGH 7.5 CVE-2024-25839 An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to es… Super Newsletter after 1.4.21 Fix from $1,9502024-03-03 MEDIUM 5.3 CVE-2024-27296 Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being… Directus 10.8.3+ Fix from $1,6002024-03-01 MEDIUM 5.3 CVE-2023-50324 IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information… Cognos Command Center Mitigation only Fix from $1,6002024-03-01 MEDIUM 6.5 CVE-2024-23493 Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a … Mattermost Server 8.1.9 / 9.2.5+ Fix from $1,6002024-02-29 HIGH 8.1 CVE-2024-26470 A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to lea… .net 9 Starter Kit No fix yet Fix from $1,9502024-02-29 HIGH 7.5 CVE-2024-23302 Couchbase Server before 7.2.4 has a private key leak in goxdcr.log. Couchbase Server 7.2.4+ Fix from $1,9502024-02-29 MEDIUM 5.3 CVE-2024-0616 The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… Passster 4.2.6.3+ Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-0620 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 vi… Password Protect Wordpress 1.9.0+ Fix from $1,6002024-02-29 MEDIUM 6.5 CVE-2023-6922 The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inc… Under Construction \/ Maintenance Mode after 2.6 Fix from $1,6002024-02-28 MEDIUM 5.3 CVE-2024-26144 Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By defau… Rails 6.1.7.7 / 7.1.0+ Fix from $1,6002024-02-27 CRITICAL 9.1 CVE-2024-27905 ** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte… Aurora Mitigation only Fix from $2,3002024-02-27 MEDIUM 5.3 CVE-2024-24720 An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists o… Innovaphone Pbx 14r1+ Fix from $1,6002024-02-27 HIGH 7.5 CVE-2024-27356EPSS 24% An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user infor… Mt6000 Firmware Mitigation only Fix from $1,9502024-02-27