Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2023-34235 Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fields if one is using the `t(nu… Strapi 4.10.8+ Fix from $1,9502023-07-25 HIGH 7.1 CVE-2023-34093 Strapi is an open-source headless content management system. Prior to version 4.10.8, anyone (Strapi developers, users, plugins) can make every attri… Strapi 4.10.8+ Fix from $1,9502023-07-25 HIGH 7.5 CVE-2023-37916 KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 leak password hash of any user (… Kubepi 1.6.5+ Fix from $1,9502023-07-21 MEDIUM 6.5 CVE-2023-3819 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4. Pimcore 10.6.4+ Fix from $1,6002023-07-21 MEDIUM 5.5 CVE-2023-32476 Dell Hybrid Client version 2.0 contains a Sensitive Data Exposure vulnerability. An unauthenticated malicious user on the device can access hard code… Hybrid Client Mitigation only Fix from $1,6002023-07-20 MEDIUM 5.3 CVE-2023-3779 The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 d… Essential Addons For Elementor after 5.8.1 Fix from $1,6002023-07-20 HIGH 7.5 CVE-2023-26026 Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil… Cloud Pak For Data Patch available Fix from $1,9502023-07-19 HIGH 7.5 CVE-2023-27877 IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the … Cloud Pak For Data Patch available Fix from $1,9502023-07-19 MEDIUM 6.5 CVE-2023-35898 IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in… Infosphere Information Server Patch available Fix from $1,6002023-07-19 MEDIUM 5.3 CVE-2023-35900 IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information… Robotic Process Automation after 23.0.5 Fix from $1,6002023-07-19 HIGH 7.5 CVE-2021-4428EPSS 16% A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. Affected by this vulnerabilit… Autosuggest 4.0.1+ Fix from $1,9502023-07-18 MEDIUM 5.3 CVE-2023-3709 The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to t… Royal Elementor Addons after 1.3.70 Fix from $1,6002023-07-18 MEDIUM 5.3 CVE-2023-33857 IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in f… Infosphere Information Server Patch available Fix from $1,6002023-07-17 MEDIUM 6.5 CVE-2023-34236 Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerabilit… Gitops Terraform Controller 0.14.4+ Fix from $1,6002023-07-14 HIGH 7.5 CVE-2023-29450 JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix S… Zabbix after 6.4.4 Fix from $1,9502023-07-13 MEDIUM 5.3 CVE-2023-34131 Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access… Analytics 9.3.2+ Fix from $1,6002023-07-13 MEDIUM 6.5 CVE-2023-34134 Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to read adminis… Analytics 9.3.2+ Fix from $1,6002023-07-13 MEDIUM 6.5 CVE-2023-38062 In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations Teamcity 2023.05.1+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2022-46651 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Co… Airflow 2.6.3+ Fix from $1,6002023-07-12 HIGH 7.5 CVE-2023-34090 Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p… Decidim 0.27.3+ Fix from $1,9502023-07-11 HIGH 7.5 CVE-2023-33165 Microsoft SharePoint Server Security Feature Bypass Vulnerability Sharepoint Server Patch available Fix from $1,9502023-07-11 MEDIUM 5.5 CVE-2023-33174 Windows Cryptographic Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20048 / 10.0.14393.6085+ Fix from $1,6002023-07-11 MEDIUM 6.5 CVE-2023-24881 Microsoft Teams Information Disclosure Vulnerability Teams 2.10.1+ Fix from $1,6002023-07-11 HIGH 7.5 CVE-2023-3553 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Teampass 3.0.10+ Fix from $1,9502023-07-08 HIGH 8.2 CVE-2023-35934 yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs m… Fedora 2023.07.06 / 2023.07.06.185519+ Fix from $1,9502023-07-06 CRITICAL 9.8 CVE-2022-48510 Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations. Emui No fix yet Fix from $2,3002023-07-06 HIGH 7.5 CVE-2022-48514 The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiali… Harmonyos No fix yet Fix from $1,9502023-07-06 HIGH 7.5 CVE-2022-48516 Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will aff… Emui Mitigation only Fix from $1,9502023-07-06 HIGH 7.5 CVE-2022-48519 Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,9502023-07-06 HIGH 7.5 CVE-2022-48520 Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,9502023-07-06