Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2024-1210 The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This mak… Learndash 4.10.2+ Fix from $1,6002024-02-05 MEDIUM 5.3 CVE-2024-1208EPSS 5% The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This mak… Learndash 4.10.3+ Fix from $1,6002024-02-05 HIGH 7.5 CVE-2024-0909 The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is du… Anonymous Restricted Content after 1.6.2 Fix from $1,9502024-02-03 MEDIUM 5.5 CVE-2024-23550 HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. Hcl Devops Deploy 7.0.5.20 / 7.1.2.16+ Fix from $1,6002024-02-03 MEDIUM 6.5 CVE-2024-1200 A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /template… Jspxcms No fix yet Fix from $1,6002024-02-03 CRITICAL 9.8 CVE-2024-24757 open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally uploaded when working with g… Open Irs 1.0.1+ Fix from $2,3002024-02-02 MEDIUM 5.3 CVE-2024-24755 discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-mem… Group Membership Ip Blocks Patch available Fix from $1,6002024-02-01 MEDIUM 6.5 CVE-2024-24548 Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise using Payme… Payment Ex after 1.1.5b Fix from $1,6002024-02-01 HIGH 8.6 CVE-2024-21626EPSS 18% runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal fi… Fedora 1.1.12+ Fix from $1,9502024-01-31 HIGH 7.5 CVE-2024-1098 A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file… Rebuild after 3.5.5 Fix from $1,9502024-01-31 HIGH 7.5 CVE-2023-44312 Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Cente… Servicecomb 2.2.0+ Fix from $1,9502024-01-31 MEDIUM 5.3 CVE-2024-22200 vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can… Vantage6 Ui 4.2.0+ Fix from $1,6002024-01-30 HIGH 7.5 CVE-2024-1033 A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is the function agent of the file … Openbi after 1.0.8 Fix from $1,9502024-01-30 HIGH 7.5 CVE-2023-52187 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Thomas Maier Image Source Control Lite – Show Image Credits and Captions.… Image Source Control after 2.17.0 Fix from $1,9502024-01-27 MEDIUM 5.4 CVE-2023-48129 An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. Line No fix yet Fix from $1,6002024-01-26 MEDIUM 5.4 CVE-2023-48132 An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of… Line No fix yet Fix from $1,6002024-01-26 MEDIUM 5.4 CVE-2023-48135 An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. Line No fix yet Fix from $1,6002024-01-26 MEDIUM 5.4 CVE-2023-48130 An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. Line No fix yet Fix from $1,6002024-01-26 MEDIUM 5.4 CVE-2023-48131 An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access toke… Line No fix yet Fix from $1,6002024-01-26 MEDIUM 6.5 CVE-2024-23649 Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, ev… Lemmy 0.19.1+ Fix from $1,6002024-01-24 HIGH 7.5 CVE-2024-22141 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: fr… Profile Builder after 3.10.0 Fix from $1,9502024-01-24 HIGH 7.5 CVE-2024-22154 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.… Salesking after 1.6.15 Fix from $1,9502024-01-24 HIGH 7.5 CVE-2024-22294 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Co… Country Blocker 2.33.4+ Fix from $1,9502024-01-24 HIGH 7.5 CVE-2024-22301 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On… Albo Pretorio Online after 4.6.6 Fix from $1,9502024-01-24 MEDIUM 5.4 CVE-2023-43996 An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. Line No fix yet Fix from $1,6002024-01-24 MEDIUM 5.4 CVE-2023-43997 An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access t… Line No fix yet Fix from $1,6002024-01-24 MEDIUM 5.4 CVE-2023-43998 An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. Line No fix yet Fix from $1,6002024-01-24 MEDIUM 5.4 CVE-2023-43992 An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. Line No fix yet Fix from $1,6002024-01-24 MEDIUM 5.4 CVE-2023-43993 An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access to… Line No fix yet Fix from $1,6002024-01-24 MEDIUM 5.4 CVE-2023-43994 An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tok… Line No fix yet Fix from $1,6002024-01-24