Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2022-43889 IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further att… Security Verify Privilege On Premises 11.5+ Fix from $1,6002023-10-17 HIGH 7.5 CVE-2012-10016 A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPress. Affected is an unknown f… Simple Download Button Shortcode Patch available Fix from $1,9502023-10-17 MEDIUM 5.3 CVE-2023-44391 Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_p… Discourse after 3.1.1 Fix from $1,6002023-10-16 HIGH 7.5 CVE-2023-45131 Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus.… Discourse after 3.1.1 Fix from $1,9502023-10-16 MEDIUM 5.3 CVE-2023-38059 The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to ret… Otrs 7.0.47 / 8.0.37+ Fix from $1,6002023-10-16 MEDIUM 5.3 CVE-2022-43868 IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-… Security Verify Access Oidc Provider Patch available Fix from $1,6002023-10-14 MEDIUM 6.5 CVE-2023-5579 A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file … Sandbox No fix yet Fix from $1,6002023-10-14 MEDIUM 6.5 CVE-2023-42780 Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, … Airflow 2.7.2+ Fix from $1,6002023-10-14 MEDIUM 6.5 CVE-2023-42663 Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat… Airflow 2.7.2+ Fix from $1,6002023-10-14 MEDIUM 5.5 CVE-2023-44187 An Exposure of Sensitive Information vulnerability in the 'file copy' command of Junos OS Evolved allows a local, authenticated attacker with shell a… Junos Os Evolved 20.4+ Fix from $1,6002023-10-11 HIGH 7.5 CVE-2023-44097 Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerability may affect service confid… Harmonyos No fix yet Fix from $1,9502023-10-11 HIGH 7.5 CVE-2023-44093 Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect servic… Harmonyos No fix yet Fix from $1,9502023-10-11 HIGH 7.5 CVE-2023-29348 Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability Windows Server 2008 Patch available Fix from $1,9502023-10-10 MEDIUM 6.5 CVE-2023-30804EPSS 13% The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authentica… Next Gen Application Firewall No fix yet Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2022-34355 IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a us… Collaborative Lifecycle Management Mitigation only Fix from $1,6002023-10-06 HIGH 8.1 CVE-2023-43804 urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing… Urllib3 1.26.17 / 2.0.6+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-3361 A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads… Openshift Data Science 1.28.1+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-1584 A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, w… Quarkus 2.13.8+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2022-22447 IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclose unintended information. I… Disconnected Log Collector 1.8.3+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-3349 Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, … Ibermatica Rps Mitigation only Fix from $1,9502023-10-03 HIGH 7.5 CVE-2022-47892 All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credenti… Netman 204 Firmware Mitigation only Fix from $1,9502023-10-03 HIGH 7.5 CVE-2023-5256 In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cac… Drupal 9.5.11 / 10.0.11+ Fix from $1,9502023-09-28 HIGH 8.2 CVE-2023-42820EPSS 5% JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly… Jumpserver 2.28.19 / 3.6.5+ Fix from $1,9502023-09-27 MEDIUM 6.5 CVE-2023-41321 GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.10+ Fix from $1,6002023-09-27 MEDIUM 5.3 CVE-2023-41323EPSS 34% GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.10+ Fix from $1,6002023-09-27 MEDIUM 5.3 CVE-2023-40049 In WS_FTP Server version prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing. Ws Ftp Server 8.8.2+ Fix from $1,6002023-09-27 MEDIUM 6.5 CVE-2023-23958 Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability. Protection Engine 9.1.0+ Fix from $1,6002023-09-27 MEDIUM 6.5 CVE-2023-5166 Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0. Docker Desktop 4.23.0+ Fix from $1,6002023-09-25 HIGH 7.5 CVE-2023-41293 Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,9502023-09-25 MEDIUM 5.5 CVE-2023-1633 A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce… Openstack Platform Mitigation only Fix from $1,6002023-09-24