Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2023-49068 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: befor… Dolphinscheduler 3.2.1+ Fix from $1,9502023-11-27 HIGH 7.5 CVE-2023-48796 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors … Dolphinscheduler 3.0.2+ Fix from $1,9502023-11-24 HIGH 7.5 CVE-2023-47244 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend.This issue affects E… Email Marketing For Woocommerce 1.13.9+ Fix from $1,9502023-11-23 HIGH 7.5 CVE-2023-47529 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud … Cloud Templates \& Patterns Collection 1.2.3+ Fix from $1,9502023-11-23 MEDIUM 6.5 CVE-2023-41786 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users… Pandora Fms 773+ Fix from $1,6002023-11-23 MEDIUM 5.5 CVE-2023-43123 On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set th… Storm 2.6.0+ Fix from $1,6002023-11-23 MEDIUM 6.5 CVE-2023-40002 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce plugin <= 7.1.1 versions. Booster For Woocommerce after 7.1.1 Fix from $1,6002023-11-23 HIGH 7.5 CVE-2023-47668 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions. Restrict Content after 3.2.7 Fix from $1,9502023-11-23 MEDIUM 6.5 CVE-2023-23978 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions. Wp Client Reports 1.0.17+ Fix from $1,6002023-11-23 MEDIUM 5.3 CVE-2023-6264 Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker to list the configured Devolut… Devolutions Server 2023.3.8.0+ Fix from $1,6002023-11-22 MEDIUM 6.5 CVE-2022-36777 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0could allow an authenticated us… Cloud Pak For Security 1.10.17.0+ Fix from $1,6002023-11-22 MEDIUM 6.5 CVE-2023-2446 The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1… Userpro 5.1.2+ Fix from $1,6002023-11-22 MEDIUM 5.3 CVE-2023-47392 An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order re… Mercedes Me after 1.34.0 Fix from $1,6002023-11-22 MEDIUM 5.3 CVE-2023-47393 An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of other users and access sensitive … Mercedes Me after 1.34.0 Fix from $1,6002023-11-22 HIGH 7.5 CVE-2023-49103 KEVEPSS 78% An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.… Graph Api Mitigation only Fix from $1,9502023-11-21 CRITICAL 9.8 CVE-2023-6248 The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex… Syrus 4g Iot Telematics Gateway Firmware Mitigation only Fix from $2,3002023-11-21 MEDIUM 5.3 CVE-2023-47643 SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentic… Suitecrm Patch available Fix from $1,6002023-11-21 MEDIUM 5.5 CVE-2023-6105 An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged O… Manageengine Analytics Plus 2.0.0 / 5.3+ Fix from $1,6002023-11-15 CRITICAL 9.1 CVE-2023-39337 A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access … Endpoint Manager Mobile 11.10.0.4 / 11.11.0.2+ Fix from $2,3002023-11-15 MEDIUM 5.3 CVE-2023-47126 TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone i… TYPO3 12.4.8+ Fix from $1,6002023-11-14 MEDIUM 5.5 CVE-2023-28723 Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user t… Aptio V Uefi Firmware Integrator Tools Mitigation only Fix from $1,6002023-11-14 MEDIUM 5.5 CVE-2022-46646 Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enable infor… Unison Software 20.14.2.3053 / 20.14.4244+ Fix from $1,6002023-11-14 MEDIUM 6.5 CVE-2023-41676 An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with acces… Fortisiem after 6.7.5 Fix from $1,6002023-11-14 MEDIUM 6.5 CVE-2023-36043 Open Management Infrastructure Information Disclosure Vulnerability System Center Operations Manager Patch available Fix from $1,6002023-11-14 HIGH 7.5 CVE-2023-47117 Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insec… Label Studio 1.9.2+ Fix from $1,9502023-11-13 MEDIUM 5.3 CVE-2023-6100 A vulnerability classified as problematic was found in Maiwei Safety Production Control Platform 4.1. This vulnerability affects unknown code of the … Maiwei Safety Production Control Platform Mitigation only Fix from $1,6002023-11-13 HIGH 7.5 CVE-2023-6101 A vulnerability, which was classified as problematic, has been found in Maiwei Safety Production Control Platform 4.1. This issue affects some unknow… Maiwei Safety Production Control Platform Mitigation only Fix from $1,9502023-11-13 MEDIUM 6.5 CVE-2023-42781 Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat… Airflow 2.7.3+ Fix from $1,6002023-11-12 HIGH 7.5 CVE-2023-6076 A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown f… Restaurant Table Booking System Mitigation only Fix from $1,9502023-11-10 HIGH 7.5 CVE-2018-8863 The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information. Encoreanywhere after 2.36.3.3 Fix from $1,9502023-11-09