Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2023-5545 H5P metadata automatically populated the author with the user's username, which could be sensitive information. Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 HIGH 8.8 CVE-2023-43791 Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within t… Label Studio 1.8.2+ Fix from $1,9502023-11-09 HIGH 7.5 CVE-2023-45875 An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster. Couchbase Server Mitigation only Fix from $1,9502023-11-08 HIGH 7.5 CVE-2023-46757 The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affec… Harmonyos No fix yet Fix from $1,9502023-11-08 HIGH 7.5 CVE-2023-44098 Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,9502023-11-08 HIGH 7.5 CVE-2023-44115 Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confiden… Harmonyos No fix yet Fix from $1,9502023-11-08 MEDIUM 6.5 CVE-2023-4061 A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from… Jboss Enterprise Application Platform 15.0.30+ Fix from $1,6002023-11-08 HIGH 7.5 CVE-2023-6001 Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment. Yugabytedb 2.18.4.0+ Fix from $1,9502023-11-08 MEDIUM 5.5 CVE-2023-4272 A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. Bifrost Gpu Kernel Driver Mitigation only Fix from $1,6002023-11-07 CRITICAL 9.8 CVE-2023-38547EPSS 19% A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configur… One Patch available Fix from $2,3002023-11-07 HIGH 7.5 CVE-2021-4430 A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaul… Coldbox Elixir Patch available Fix from $1,9502023-11-06 MEDIUM 6.5 CVE-2023-45189 A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 m… Robotic Process Automation For Cloud Pak after 23.0.10 Fix from $1,6002023-11-03 MEDIUM 5.3 CVE-2023-41354 Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit t… G 040w Q Firmware Mitigation only Fix from $1,6002023-11-03 HIGH 7.5 CVE-2023-45024 Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder. Request Tracker 5.0.5+ Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-41259 Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email … Request Tracker 4.4.7 / 5.0.5+ Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-41260 Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls. Request Tracker 4.4.7 / 5.0.5+ Fix from $1,9502023-11-03 MEDIUM 5.3 CVE-2023-34261EPSS 8% Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they lead to a… D Copia253mf Plus Firmware after 2vg_s000.002.561 Fix from $1,6002023-11-03 HIGH 7.5 CVE-2023-39057 An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted messages. Line Mini App No fix yet Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-39042 An information leak in Gyouza-newhushimi v13.6.1 allows attackers to obtain the channel access token and send crafted messages. Line Mini App No fix yet Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-39047 An information leak in shouzu sweets oz v13.6.1 allows attackers to obtain the channel access token and send crafted messages. Line Mini App Patch available Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-39048 An information leak in Tokudaya.honten v13.6.1 allows attackers to obtain the channel access token and send crafted messages. Line Mini App No fix yet Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-39050 An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages. Line Mini App No fix yet Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-39051 An information leak in VISION MEAT WORKS Track Diner 10/10mbl v13.6.1 allows attackers to obtain the channel access token and send crafted messages. Line Mini App No fix yet Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-39053 An information leak in Hattoriya v13.6.1 allows attackers to obtain the channel access token and send crafted messages. Line Mini App No fix yet Fix from $1,9502023-11-02 HIGH 7.5 CVE-2023-39054 An information leak in Tokudaya.ekimae_mc v13.6.1 allows attackers to obtain the channel access token and send crafted messages. Line Mini App No fix yet Fix from $1,9502023-11-02 MEDIUM 5.3 CVE-2023-5516 Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about th… Esoms after 6.3.13 Fix from $1,6002023-11-01 MEDIUM 5.3 CVE-2023-5515 The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure o… Esoms after 6.3.13 Fix from $1,6002023-11-01 MEDIUM 5.3 CVE-2023-43796 Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Syn… Fedora 1.95.1+ Fix from $1,6002023-10-31 HIGH 7.5 CVE-2022-3611 An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to … App Store App 11.8.0+ Fix from $1,9502023-10-27 HIGH 7.5 CVE-2023-33558 An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information… Ocomon 4.0.1+ Fix from $1,9502023-10-26