Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2023-38344 An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed… Endpoint Manager 2022+ Fix from $1,6002023-09-21 HIGH 7.5 CVE-2023-39677EPSS 31% MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vuln… Product Catalog \(csv\, Excel\) Import No fix yet Fix from $1,9502023-09-20 MEDIUM 5.3 CVE-2023-38718 IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. … Robotic Process Automation after 23.0.8 Fix from $1,6002023-09-20 MEDIUM 6.5 CVE-2023-39045 An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send crafted messages. Kokoroe Members Card No fix yet Fix from $1,6002023-09-20 MEDIUM 6.5 CVE-2023-39052 An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted messages. Earthgarden Waiting No fix yet Fix from $1,6002023-09-20 MEDIUM 5.3 CVE-2023-43617 An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an un… Croc after 9.6.5 Fix from $1,6002023-09-20 HIGH 7.5 CVE-2022-47554 Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml fil… Ekorrci Firmware Mitigation only Fix from $1,9502023-09-19 CRITICAL 9.1 CVE-2023-42454 SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database con… Sqlpage 0.11.1+ Fix from $2,3002023-09-18 HIGH 7.5 CVE-2023-42387 An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via get_db_info function in instal… Tdsql Chitu No fix yet Fix from $1,9502023-09-18 MEDIUM 5.7 CVE-2023-36472 Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tok… Strapi 4.11.7+ Fix from $1,6002023-09-15 MEDIUM 5.3 CVE-2023-36551 A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclos… Fortisiem 6.7.6+ Fix from $1,6002023-09-13 MEDIUM 5.3 CVE-2021-44172 An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7… Forticlient Endpoint Management Server after 7.0.7 Fix from $1,6002023-09-13 MEDIUM 6.5 CVE-2023-4917 The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_a… Leyka after 3.30.3 Fix from $1,6002023-09-13 HIGH 7.5 CVE-2023-36763 Microsoft Outlook Information Disclosure Vulnerability 365 Apps Patch available Fix from $1,9502023-09-12 MEDIUM 6.5 CVE-2023-40712 Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, … Airflow 2.7.1+ Fix from $1,6002023-09-12 HIGH 7.5 CVE-2023-4876 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92. Inure Patch available Fix from $1,9502023-09-10 HIGH 7.5 CVE-2023-4877 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92. Inure Patch available Fix from $1,9502023-09-10 MEDIUM 5.3 CVE-2022-22409 IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration.… Aspera Faspex after 5.0.5 Fix from $1,6002023-09-08 MEDIUM 5.3 CVE-2023-28010 In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target future attacks. Domino Mitigation only Fix from $1,6002023-09-08 HIGH 7.5 CVE-2023-39620 An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via the guest a… Terastation Nas 5410r Firmware No fix yet Fix from $1,9502023-09-08 CRITICAL 9.6 CVE-2023-40029 Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. … Argo Cd 2.6.15 / 2.7.14+ Fix from $2,3002023-09-07 HIGH 7.7 CVE-2023-41050 AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone controlling the format string to … Accesscontrol 4.4 / 4.8.9+ Fix from $1,9502023-09-06 MEDIUM 6.5 CVE-2023-32271 An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.… Oas Platform No fix yet Fix from $1,6002023-09-05 HIGH 7.5 CVE-2023-4714EPSS 5% A vulnerability was found in PlayTube 3.0.1 and classified as problematic. This issue affects some unknown processing of the component Redirect Handl… Playtube No fix yet Fix from $1,9502023-09-01 MEDIUM 5.3 CVE-2023-23763 An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access … Enterprise Server 3.6.18 / 3.7.16+ Fix from $1,6002023-09-01 HIGH 7.5 CVE-2023-41749 Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Windows) befo… Agent Mitigation only Fix from $1,9502023-08-31 MEDIUM 5.5 CVE-2023-41745 Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS,… Agent Mitigation only Fix from $1,6002023-08-31 HIGH 7.5 CVE-2021-32050 Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The pu… C\+\+ 1.1.1 / 1.9.2+ Fix from $1,9502023-08-29 MEDIUM 5.5 CVE-2023-0238 Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability which allowed a malicious app ins… Warp 6.29+ Fix from $1,6002023-08-29 HIGH 7.5 CVE-2023-24959 IBM InfoSphere Information Systems 11.7 could expose information about the host system and environment configuration. IBM X-Force ID: 246332. Infosphere Information Server 11.7.1.0 / 11.7.1.4+ Fix from $1,9502023-08-28