Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2022-32836 This issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sen… Music Mitigation only Fix from $1,9502023-02-27 MEDIUM 5.5 CVE-2022-32855 A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted co… Ipados 15.6+ Fix from $1,6002023-02-27 HIGH 7.5 CVE-2023-0994 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2. Rosariosis 10.8.2+ Fix from $1,9502023-02-24 MEDIUM 5.5 CVE-2023-0597 A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location o… Linux Kernel Patch available Fix from $1,6002023-02-23 HIGH 7.5 CVE-2017-20178 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function s… Codiad Patch available Fix from $1,9502023-02-21 MEDIUM 5.5 CVE-2022-48319 Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0… Checkmk Mitigation only Fix from $1,6002023-02-20 MEDIUM 5.3 CVE-2023-0901 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4. Pixelfed 0.11.4+ Fix from $1,6002023-02-18 HIGH 7.5 CVE-2022-34351 IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see … Qradar Security Information And Event Manager 7.4.3+ Fix from $1,9502023-02-17 HIGH 7.5 CVE-2022-41734 IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message… Maximo Application Suite Patch available Fix from $1,9502023-02-17 HIGH 7.5 CVE-2022-43930 IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log… Db2 Patch available Fix from $1,9502023-02-17 HIGH 7.5 CVE-2022-43927 IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a speciall… Db2 Patch available Fix from $1,9502023-02-17 MEDIUM 5.3 CVE-2022-27891 Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have… Gotham 3.22.10.4+ Fix from $1,6002023-02-16 HIGH 7.5 CVE-2023-22580 Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure. Sequelize 6.28.1+ Fix from $1,9502023-02-16 MEDIUM 6.5 CVE-2023-23458 Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request. Sn Xvr3804e1 Firmware No fix yet Fix from $1,6002023-02-15 HIGH 7.1 CVE-2023-0020 SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is oth… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502023-02-14 MEDIUM 6.5 CVE-2023-0814 The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_met… Profile Builder after 3.9.0 Fix from $1,6002023-02-14 HIGH 7.5 CVE-2022-45454 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161,… Agent Mitigation only Fix from $1,9502023-02-13 MEDIUM 5.5 CVE-2022-47367 In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges nee… Android Mitigation only Fix from $1,6002023-02-12 MEDIUM 5.5 CVE-2022-47324 In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. Android Mitigation only Fix from $1,6002023-02-12 MEDIUM 5.5 CVE-2022-47325 In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. Android No fix yet Fix from $1,6002023-02-12 MEDIUM 5.5 CVE-2022-47326 In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. Android Mitigation only Fix from $1,6002023-02-12 MEDIUM 5.5 CVE-2022-47328 In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. Android No fix yet Fix from $1,6002023-02-12 MEDIUM 5.5 CVE-2022-47329 In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. Android No fix yet Fix from $1,6002023-02-12 MEDIUM 5.5 CVE-2022-38686 In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. Android Mitigation only Fix from $1,6002023-02-12 HIGH 7.5 CVE-2023-23592 WALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information. Bastion Access Manager 3.0.16 / 4.0.3+ Fix from $1,9502023-02-09 MEDIUM 5.5 CVE-2023-21435 Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address infor… Android Mitigation only Fix from $1,6002023-02-09 HIGH 7.5 CVE-2023-25164 Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 w… Tinacms\/cli 1.0.9+ Fix from $1,9502023-02-08 MEDIUM 5.3 CVE-2022-40691 An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A special… Sds 3008 Firmware after 2.1 Fix from $1,6002023-02-07 HIGH 7.5 CVE-2023-24827 syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure f… Syft Patch available Fix from $1,9502023-02-07 MEDIUM 6.5 CVE-2022-44268EPSS 90% ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded … Imagemagick No fix yet Fix from $1,6002023-02-06