Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2023-31416 Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being a… Elastic Cloud On Kubernetes 2.8+ Fix from $1,6002023-10-26 HIGH 7.5 CVE-2023-38845 An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. Line No fix yet Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-38846 An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. Line No fix yet Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-38847 An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. Line No fix yet Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-38849 An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. Line No fix yet Fix from $1,9502023-10-25 MEDIUM 6.8 CVE-2023-41988 This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPad… Ipados 10.1 / 14.1+ Fix from $1,6002023-10-25 MEDIUM 5.3 CVE-2023-42846 This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, tvOS 17.1, iOS 17.1 and … Ipados 10.1 / 16.7.2+ Fix from $1,6002023-10-25 MEDIUM 6.5 CVE-2023-46125 Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem… Fides 2.22.1+ Fix from $1,6002023-10-25 MEDIUM 6.5 CVE-2023-46128 Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobo… Nautobot 2.0.3+ Fix from $1,6002023-10-25 HIGH 7.5 CVE-2023-42490 EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Eisbaer Scada after 3.0.6433.1964 Fix from $1,9502023-10-25 HIGH 8.2 CVE-2023-39735 The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mess… Uomasa Saiji New No fix yet Fix from $1,9502023-10-25 HIGH 8.2 CVE-2023-39736 The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast m… Fukunaga Memberscard No fix yet Fix from $1,9502023-10-25 HIGH 8.2 CVE-2023-39737 The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. Matsuya No fix yet Fix from $1,9502023-10-25 HIGH 8.2 CVE-2023-39739 The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast m… Regina Sweets\&bakery No fix yet Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-46315 The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion w… Stable Diffusion Webui Infinite Image Browsing 5.0+ Fix from $1,9502023-10-22 MEDIUM 6.5 CVE-2023-5070 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inc… Social Media Share Buttons \& Social Sharing Icons 2.8.6+ Fix from $1,6002023-10-20 CRITICAL 9.3 CVE-2023-5576 The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.9… Migration\, Backup\, Staging after 0.9.91 Fix from $2,3002023-10-20 MEDIUM 5.4 CVE-2023-41893 Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logg… Home Assistant 2023.9.0+ Fix from $1,6002023-10-20 MEDIUM 5.5 CVE-2023-46115 Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base it… Tauri 2.0.0+ Fix from $1,6002023-10-20 MEDIUM 5.3 CVE-2023-42666 The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnerability, which may allow an attacker to cre… Dexgate Mitigation only Fix from $1,6002023-10-19 MEDIUM 5.3 CVE-2023-5254 The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_chec… Wpbot 4.9.1+ Fix from $1,6002023-10-19 HIGH 7.5 CVE-2023-34437 Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could a… Bentley Nevada 3500 System Firmware Mitigation only Fix from $1,9502023-10-19 HIGH 7.5 CVE-2023-45912 WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underl… Comscale No fix yet Fix from $1,9502023-10-18 CRITICAL 9.8 CVE-2023-5642EPSS 17% Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa… R Seenet No fix yet Fix from $2,3002023-10-18 HIGH 7.5 CVE-2023-5552 A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewa… Firewall after 19.5.3 Fix from $1,9502023-10-18 HIGH 7.5 CVE-2023-22086 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Patch available Fix from $1,9502023-10-17 HIGH 7.5 CVE-2023-22019 Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12… HTTP Server Patch available Fix from $1,9502023-10-17 MEDIUM 5.5 CVE-2023-5339 Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including pa… Mattermost Desktop after 5.4.0 Fix from $1,6002023-10-17 HIGH 7.5 CVE-2023-41752 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.… Traffic Server 8.1.9 / 9.2.3+ Fix from $1,9502023-10-17 MEDIUM 5.3 CVE-2021-38859 IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that co… Security Verify Privilege On Premises 11.5+ Fix from $1,6002023-10-17