Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.4 CVE-2023-43995 An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. Line No fix yet Fix from $1,6002024-01-24 MEDIUM 5.5 CVE-2024-23224 The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive … macOS 13.6.4 / 14.3+ Fix from $1,6002024-01-23 MEDIUM 6.5 CVE-2024-23206 An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadO… Safari 10.3 / 14.3+ Fix from $1,6002024-01-23 MEDIUM 5.5 CVE-2024-23207 This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, ma… Ipados 10.3 / 12.7.3+ Fix from $1,6002024-01-23 MEDIUM 5.5 CVE-2023-42888 The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 1… Ipados 10.2 / 12.7.3+ Fix from $1,6002024-01-23 HIGH 7.8 CVE-2020-36771 CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view… Cagefs 7.1.2-2+ Fix from $1,9502024-01-22 MEDIUM 6.5 CVE-2024-22421 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterL… Fedora 3.6.7 / 4.0.11+ Fix from $1,6002024-01-19 HIGH 7.5 CVE-2024-23331 Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems usi… Vite 2.9.17 / 3.2.8+ Fix from $1,9502024-01-19 MEDIUM 5.3 CVE-2024-0717EPSS 18% A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DI… Dir 825acg1 Firmware after 2024-01-12 Fix from $1,6002024-01-19 MEDIUM 5.3 CVE-2024-0716 A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affects an unknown part of the file… Smart S150 Firmware No fix yet Fix from $1,6002024-01-19 MEDIUM 6.5 CVE-2022-47160 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp S… Wp Social Login And Register Social Counter 2.0.0+ Fix from $1,6002024-01-19 MEDIUM 5.3 CVE-2023-28901 The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fue… Skoda Connect Mitigation only Fix from $1,6002024-01-18 MEDIUM 5.3 CVE-2023-28900 The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect s… Skoda Connect Mitigation only Fix from $1,6002024-01-18 MEDIUM 5.3 CVE-2023-50950 IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709. Qradar Security Information And Event Manager Patch available Fix from $1,6002024-01-17 MEDIUM 5.0 CVE-2024-20904 Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are… Business Intelligence Patch available Fix from $1,6002024-01-16 HIGH 7.5 CVE-2023-45236 EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unaut… Edk2 after 202311 Fix from $1,9502024-01-16 CRITICAL 9.1 CVE-2024-0569 A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /… T8 Firmware No fix yet Fix from $2,3002024-01-16 CRITICAL 9.1 CVE-2023-52101 Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity. Emui No fix yet Fix from $2,3002024-01-16 HIGH 7.5 CVE-2023-44112 Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,9502024-01-16 MEDIUM 6.5 CVE-2023-50290EPSS 68% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment v… Solr 9.3.0+ Fix from $1,6002024-01-15 HIGH 7.5 CVE-2024-0490 A vulnerability was found in Huaxia ERP up to 3.1. It has been rated as problematic. This issue affects some unknown processing of the file /user/get… Huaxia Erp after 3.1 Fix from $1,9502024-01-13 HIGH 7.5 CVE-2024-0472 A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue affects some unknown process… Dormitory Management System Mitigation only Fix from $1,9502024-01-12 HIGH 7.5 CVE-2023-49261 The "tokenKey" value used in user authorization is visible in the HTML source of the login page. H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 HIGH 7.5 CVE-2023-6266 The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP… Backup Migration after 1.3.6 Fix from $1,9502024-01-11 MEDIUM 5.5 CVE-2023-41987 This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data. macOS 14.0+ Fix from $1,6002024-01-10 MEDIUM 5.5 CVE-2023-42829 The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey … macOS 11.7.9 / 12.6.8+ Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2023-40385 This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker … Safari 14.0 / 17.0+ Fix from $1,6002024-01-10 MEDIUM 5.5 CVE-2023-40411 This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive data. macOS 14.0+ Fix from $1,6002024-01-10 MEDIUM 5.5 CVE-2022-32931 This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access pr… macOS 13.0+ Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2024-21320EPSS 23% Windows Themes Spoofing Vulnerability Windows 10 1507 10.0.10240.20402 / 10.0.14393.6614+ Fix from $1,6002024-01-09