Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2023-39289 A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to con… Mivoice Connect after 9.6.2208.101 Fix from $1,9502023-08-25 MEDIUM 6.5 CVE-2023-40580 Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet … Freighter 5.3.1+ Fix from $1,6002023-08-25 HIGH 7.5 CVE-2023-3705 The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthent… Cp Vnr 3104 Firmware Patch available Fix from $1,9502023-08-24 MEDIUM 5.3 CVE-2023-4230 A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate th… Iologik E4200 Firmware after 1.6 Fix from $1,6002023-08-24 HIGH 8.1 CVE-2023-37379 Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed… Airflow 2.7.0+ Fix from $1,9502023-08-23 HIGH 7.5 CVE-2023-25913 Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP ad… Ak Sm 800a Firmware after 3.3 Fix from $1,9502023-08-21 HIGH 7.5 CVE-2023-40735 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) … Butterfly Button after 2023-08-21 Fix from $1,9502023-08-21 MEDIUM 5.3 CVE-2023-39974 Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of sub… Acymailing 8.7.0+ Fix from $1,6002023-08-17 MEDIUM 5.3 CVE-2023-40348 The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its outp… Gogs after 1.0.15 Fix from $1,6002023-08-16 HIGH 7.8 CVE-2023-32495 Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker… Powerscale Onefs after 9.5.0.3 Fix from $1,9502023-08-16 MEDIUM 5.3 CVE-2023-2916EPSS 24% The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_no… Infinitewp Client 1.12.1+ Fix from $1,6002023-08-15 MEDIUM 5.5 CVE-2023-21267 In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the c… Android Mitigation only Fix from $1,6002023-08-14 HIGH 7.5 CVE-2023-40023 yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file inclusion (LFI) vulnerability. Th… Yaklang Patch available Fix from $1,9502023-08-14 HIGH 7.5 CVE-2023-39393 Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources… Emui Mitigation only Fix from $1,9502023-08-13 HIGH 7.5 CVE-2023-39383 Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' d… Emui No fix yet Fix from $1,9502023-08-13 HIGH 7.5 CVE-2023-32561 A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypa… Avalanche 6.4.1+ Fix from $1,9502023-08-10 MEDIUM 5.5 CVE-2023-38245 Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An u… Acrobat Dc 20.005.30514.10514 / 20.005.30516.10516+ Fix from $1,6002023-08-10 MEDIUM 6.5 CVE-2023-39951 OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumenta… Opentelemetry Instrumentation For Java 1.28.0+ Fix from $1,6002023-08-08 MEDIUM 6.5 CVE-2023-36908 Windows Hyper-V Information Disclosure Vulnerability Windows 10 10.0.10240.20107 / 10.0.14393.6167+ Fix from $1,6002023-08-08 MEDIUM 6.5 CVE-2023-36894 Microsoft SharePoint Server Information Disclosure Vulnerability Sharepoint Server Patch available Fix from $1,6002023-08-08 MEDIUM 5.7 CVE-2023-4177 A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknown processing of the component… Empowerid after 7.205.0.0 Fix from $1,6002023-08-06 HIGH 7.5 CVE-2023-4168EPSS 46% A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-… Adlisting No fix yet Fix from $1,9502023-08-05 HIGH 8.8 CVE-2023-39508 Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apach… Airflow 2.6.0+ Fix from $1,9502023-08-05 HIGH 7.5 CVE-2023-38494 MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not ha… Metersphere 2.10.4+ Fix from $1,9502023-08-04 HIGH 7.5 CVE-2023-4139 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction i… Wp Ultimate Csv Importer after 7.9.8 Fix from $1,9502023-08-04 MEDIUM 5.5 CVE-2023-26441 Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker wi… Open Xchange Appsuite Office 8.11+ Fix from $1,6002023-08-02 MEDIUM 5.3 CVE-2023-31927 An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c, could allow a remote unauth… Brocade Fabric Operating System 9.1.1c+ Fix from $1,6002023-08-02 MEDIUM 5.5 CVE-2023-28203 The issue was addressed with improved checks. This issue is fixed in Apple Music 4.2.0 for Android. An app may be able to access contacts. Music 4.2.0+ Fix from $1,6002023-07-28 MEDIUM 6.5 CVE-2023-38503 Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permissi… Directus 10.5.0+ Fix from $1,6002023-07-25 MEDIUM 5.3 CVE-2023-38499 TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42 ELTS, 10.4.39 ELTS, 11.5.30, … TYPO3 9.5.42 / 10.4.39+ Fix from $1,6002023-07-25