Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2023-1777 Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the con… Mattermost Server 7.1.6+ Fix from $1,6002023-03-31 HIGH 7.5 CVE-2023-1769 A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0. Affected is an unknown func… Grade Point Average \(gpa\) Calculator Mitigation only Fix from $1,9502023-03-31 MEDIUM 5.3 CVE-2023-1258 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) all… Flow X\/m Firmware after 3.2.6 Fix from $1,6002023-03-31 HIGH 7.5 CVE-2023-28732 Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access… Acymailing 8.3.0+ Fix from $1,9502023-03-30 HIGH 7.5 CVE-2023-0836 An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 … Haproxy 2.2.27+ Fix from $1,9502023-03-29 HIGH 7.5 CVE-2023-1680 A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayr… Xunruicms No fix yet Fix from $1,9502023-03-29 HIGH 7.5 CVE-2022-48430 In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview. Intellij Idea 2023.1+ Fix from $1,9502023-03-29 HIGH 7.5 CVE-2023-1683 A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown functionality of the file /dayrui/… Xunruicms No fix yet Fix from $1,9502023-03-29 HIGH 7.5 CVE-2023-1681 A vulnerability, which was classified as problematic, was found in Xunrui CMS 4.61. Affected is an unknown function of the file /config/myfield/test.… Xunruicms No fix yet Fix from $1,9502023-03-28 MEDIUM 5.5 CVE-2023-25722 A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured… Veracode 23.3.19.0+ Fix from $1,6002023-03-28 HIGH 7.5 CVE-2022-48346 The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,9502023-03-27 HIGH 7.5 CVE-2022-48347 The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,9502023-03-27 CRITICAL 9.1 CVE-2022-48348 The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and … Emui No fix yet Fix from $2,3002023-03-27 CRITICAL 9.8 CVE-2023-24838 HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the admini… Powerstation Firmware Mitigation only Fix from $2,3002023-03-27 HIGH 7.5 CVE-2023-28444 angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables.… Angular Server Side Configuration 15.1.0+ Fix from $1,9502023-03-24 HIGH 7.5 CVE-2023-21067 Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/A Android No fix yet Fix from $1,9502023-03-24 MEDIUM 5.3 CVE-2023-28442 GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Prior to versions 2.20.6, 2.19.6… Geonode 2.18.7 / 2.19.6+ Fix from $1,6002023-03-24 HIGH 8.8 CVE-2023-20055 A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the w… Catalyst Center 2.3.3.6+ Fix from $1,9502023-03-23 HIGH 7.5 CVE-2023-28432 KEVEPSS 84% Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T2… Minio 2023-03-20t20-16-18z+ Fix from $1,9502023-03-22 HIGH 7.5 CVE-2022-45124EPSS 13% An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted … Kinghistorian No fix yet Fix from $1,9502023-03-20 HIGH 7.5 CVE-2023-27591 Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instan… Miniflux 2.0.43+ Fix from $1,9502023-03-17 HIGH 7.5 CVE-2023-22880 Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 c… Rooms 5.13.1 / 5.13.3+ Fix from $1,9502023-03-16 MEDIUM 5.5 CVE-2023-21449 Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information with… Android Mitigation only Fix from $1,6002023-03-16 MEDIUM 6.5 CVE-2023-25680 IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obf… Robotic Process Automation 21.0.6+ Fix from $1,6002023-03-15 HIGH 8.2 CVE-2020-4927 A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary d… Spectrum Scale 5.1.7.0+ Fix from $1,9502023-03-15 MEDIUM 6.5 CVE-2023-22876 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive in… Sterling B2b Integrator 6.0.3.8 / 6.1.2.2+ Fix from $1,6002023-03-15 HIGH 7.5 CVE-2022-38456 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions. Ajax Search after 4.10.3 Fix from $1,9502023-03-15 MEDIUM 5.5 CVE-2023-24923 Microsoft OneDrive for Android Information Disclosure Vulnerability Onedrive 6.73+ Fix from $1,6002023-03-14 MEDIUM 5.5 CVE-2023-24882 Microsoft OneDrive for Android Information Disclosure Vulnerability Onedrive 6.73+ Fix from $1,6002023-03-14 MEDIUM 5.3 CVE-2023-27894 SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameter… Businessobjects Business Intelligence Mitigation only Fix from $1,6002023-03-14