Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.2 CVE-2023-28762 SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the log… Businessobjects Business Intelligence Mitigation only Fix from $1,9502023-05-09 HIGH 7.5 CVE-2023-31133EPSS 46% Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Pri… Ghost 5.46.1+ Fix from $1,9502023-05-08 HIGH 7.5 CVE-2023-24505 Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request. Ncr\/camera Firmware No fix yet Fix from $1,9502023-05-08 MEDIUM 5.3 CVE-2023-26268 Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design d… Couchdb 3.2.3 / 3.3.2+ Fix from $1,6002023-05-02 MEDIUM 5.3 CVE-2023-22503 Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a pr… Confluence Data Center 7.13.15 / 7.19.7+ Fix from $1,6002023-05-01 MEDIUM 6.5 CVE-2023-30853 Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradl… Build Action 2.4.2+ Fix from $1,6002023-04-28 HIGH 7.5 CVE-2023-28770EPSS 58% The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(AB… Dx5401 B0 Firmware 5.17+ Fix from $1,9502023-04-27 MEDIUM 6.5 CVE-2023-30843 Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access to documents that contain hidd… Payload 1.7.0+ Fix from $1,6002023-04-26 MEDIUM 5.5 CVE-2023-30841 Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed w… Baremetal Operator 0.3.0+ Fix from $1,6002023-04-26 HIGH 7.5 CVE-2023-1387 Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a J… Grafana 9.2.17 / 9.3.13+ Fix from $1,9502023-04-26 MEDIUM 6.5 CVE-2023-23839 The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCo… Solarwinds Platform 2023.2.0+ Fix from $1,6002023-04-25 HIGH 7.5 CVE-2023-22577 Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community … White Rabbit Switch Firmware after 6.0.1 Fix from $1,9502023-04-24 MEDIUM 5.3 CVE-2023-30611 Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data ab… Reactions Patch available Fix from $1,6002023-04-19 HIGH 7.5 CVE-2023-29517 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office document viewer macro was allowin… Xwiki 13.10.11 / 14.4.8+ Fix from $1,9502023-04-19 MEDIUM 5.3 CVE-2023-26049 Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookie… Debian Linux 9.4.51 / 10.0.14+ Fix from $1,6002023-04-18 MEDIUM 5.5 CVE-2023-22307 Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files. Checkmk Appliance Firmware 1.6.4+ Fix from $1,6002023-04-18 HIGH 7.5 CVE-2023-1831 Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental … Mattermost Server 7.7.3 / 7.8.2+ Fix from $1,9502023-04-17 MEDIUM 6.5 CVE-2022-34125 front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in th… Cmdb 3.0.3+ Fix from $1,6002023-04-16 MEDIUM 6.5 CVE-2023-20866 In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to thos… Spring Session Mitigation only Fix from $1,6002023-04-13 MEDIUM 5.5 CVE-2023-28271 Windows Kernel Memory Information Disclosure Vulnerability Windows 10 1507 10.0.10240.19869 / 10.0.14393.5850+ Fix from $1,6002023-04-11 HIGH 7.0 CVE-2023-28221 Windows Error Reporting Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19869 / 10.0.14393.5850+ Fix from $1,9502023-04-11 HIGH 7.5 CVE-2022-43951 An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, … Fortinac 7.2.0 / 9.4.2+ Fix from $1,9502023-04-11 MEDIUM 6.3 CVE-2023-23588 A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on… Simatic Ipc647d Firmware 4.09.00.25611+ Fix from $1,6002023-04-11 CRITICAL 9.8 CVE-2023-28765EPSS 15% An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to… Businessobjects Business Intelligence Mitigation only Fix from $2,3002023-04-11 HIGH 7.5 CVE-2013-10024 A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this vulnerability is an unknown … Exit Strategy Patch available Fix from $1,9502023-04-08 MEDIUM 5.3 CVE-2023-1710 A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior to 15.9.4 and 15.10 prior to … GitLab 15.8.5 / 15.9.4+ Fix from $1,6002023-04-05 HIGH 7.5 CVE-2023-1858 A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part… Earnings And Expense Tracker App Mitigation only Fix from $1,9502023-04-05 MEDIUM 6.5 CVE-2023-0614 The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may b… Samba 4.16.10 / 4.17.7+ Fix from $1,6002023-04-03 HIGH 7.5 CVE-2023-1790 A vulnerability, which was classified as problematic, was found in SourceCodester Simple Task Allocation System 1.0. Affected is an unknown function … Simple Task Allocation System Mitigation only Fix from $1,9502023-04-01 MEDIUM 6.5 CVE-2023-1775 When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all use… Mattermost Server 7.1.6+ Fix from $1,6002023-03-31