Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2023-37239 Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the … Emui No fix yet Fix from $1,9502023-07-06 CRITICAL 9.8 CVE-2021-46891 Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect servic… Emui No fix yet Fix from $2,3002023-07-05 CRITICAL 9.1 CVE-2023-3455 Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity. Emui No fix yet Fix from $2,3002023-07-05 MEDIUM 5.5 CVE-2023-21624 Information disclosure in DSP Services while loading dynamic module. Fastconnect 6700 Firmware No fix yet Fix from $1,6002023-07-04 CRITICAL 9.1 CVE-2023-36817 `tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repos… The King\'s Temple Church Website Mitigation only Fix from $2,3002023-07-03 HIGH 7.5 CVE-2023-36539 Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. Meetings No fix yet Fix from $1,9502023-06-30 MEDIUM 5.5 CVE-2023-36476 calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions versio… Calamares Nixos Extensions 0.3.13+ Fix from $1,6002023-06-29 MEDIUM 5.5 CVE-2023-21237 KEV In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insuffic… Android Mitigation only Fix from $1,6002023-06-28 HIGH 7.5 CVE-2023-30993 IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another ten… Cloud Pak For Security after 1.9.2.0 Fix from $1,9502023-06-27 HIGH 7.5 CVE-2023-28857 Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X50… Central Authentication Service 6.5.9.1 / 6.6.6+ Fix from $1,9502023-06-27 MEDIUM 6.5 CVE-2022-34352 IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned t… Qradar Security Information And Event Manager Patch available Fix from $1,6002023-06-27 MEDIUM 5.3 CVE-2023-34098 Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript c… Shopware 5.7.18+ Fix from $1,6002023-06-27 HIGH 7.5 CVE-2023-3132 The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient c… Mainwp Child after 4.4.1.1 Fix from $1,9502023-06-27 MEDIUM 5.3 CVE-2023-2991 Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Glo… Eft Server after 8.1.0.14 Fix from $1,6002023-06-22 MEDIUM 6.5 CVE-2023-25499 When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0,… Vaadin 10.0.23 / 14.10.1+ Fix from $1,6002023-06-22 MEDIUM 6.5 CVE-2023-35005 In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact… Airflow 2.6.2+ Fix from $1,6002023-06-19 MEDIUM 6.5 CVE-2023-2792 Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg com… Mattermost after 7.9.3 Fix from $1,6002023-06-16 MEDIUM 5.3 CVE-2023-34242 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to version 1.13.4, when Gateway API is enabled in Ci… Cilium 1.13.4+ Fix from $1,6002023-06-15 MEDIUM 5.3 CVE-2023-29287 Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Information Exposure vulnerability … Commerce Mitigation only Fix from $1,6002023-06-15 HIGH 7.7 CVE-2023-28175 Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted … Video Management System after 11.1.1 Fix from $1,9502023-06-15 MEDIUM 6.5 CVE-2022-33159 IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X… Security Directory Suite Va after 8.0.1.19 Fix from $1,6002023-06-15 HIGH 7.5 CVE-2023-25683 IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could all… Powervm Hypervisor Mitigation only Fix from $1,9502023-06-15 MEDIUM 6.8 CVE-2023-2820 An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an… Threat Response Auto Pull 5.10.0+ Fix from $1,6002023-06-14 HIGH 7.5 CVE-2023-33933 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach… Traffic Server 8.1.7 / 9.2.1+ Fix from $1,9502023-06-14 HIGH 7.5 CVE-2022-47184 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach… Traffic Server 8.1.7 / 9.2.1+ Fix from $1,9502023-06-14 MEDIUM 6.5 CVE-2023-3231 A vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown code of the component ZIP Packa… Ujcms after 6.0.2 Fix from $1,6002023-06-14 MEDIUM 5.3 CVE-2023-34250 Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passe… Discourse 3.0.4+ Fix from $1,6002023-06-13 MEDIUM 6.5 CVE-2022-43684 ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional… Servicenow No fix yet Fix from $1,6002023-06-13 HIGH 7.5 CVE-2023-22586 The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter. Ak Em100 Firmware 2.2.0.12+ Fix from $1,9502023-06-11 MEDIUM 5.3 CVE-2023-25912 The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information s… Ak Em100 Firmware 2.2.0.12+ Fix from $1,6002023-06-11