Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 8.8 CVE-2022-23498 Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including … Grafana 9.2.10 / 9.3.4+ Fix from $1,9502023-02-03 HIGH 7.5 CVE-2022-47070 NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the second packag… Nvs 365 V01 Firmware No fix yet Fix from $1,9502023-02-03 HIGH 7.5 CVE-2023-0659 A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of… 1704 Wgl Firmware Mitigation only Fix from $1,9502023-02-03 HIGH 7.5 CVE-2023-0658 A vulnerability, which was classified as critical, was found in Multilaser RE057 and RE170 2.1/2.2. This affects an unknown part of the file /param.f… Re057 Firmware Mitigation only Fix from $1,9502023-02-03 HIGH 7.5 CVE-2021-22786 A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller wh… Modicon M340 Bmxp341000 Firmware 3.40+ Fix from $1,9502023-02-01 MEDIUM 6.5 CVE-2022-4206 A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization h… Dast Api Scanner 2.0.102+ Fix from $1,6002023-02-01 HIGH 7.5 CVE-2022-32984 BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive … Btcpay Server after 1.5.3 Fix from $1,9502023-01-31 HIGH 7.5 CVE-2023-22611 A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific mess… Ecostruxure Geo Scada Expert 2019 Patch available Fix from $1,9502023-01-31 MEDIUM 6.3 CVE-2023-23629 Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashbo… Metabase 0.43.7.1 / 0.44.6.1+ Fix from $1,6002023-01-28 MEDIUM 5.3 CVE-2023-23620 Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branc… Discourse 3.0.1+ Fix from $1,6002023-01-28 MEDIUM 5.3 CVE-2023-23624 Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passe… Discourse 3.0.1+ Fix from $1,6002023-01-28 MEDIUM 5.3 CVE-2023-0557 The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unau… Contentstudio 1.2.6+ Fix from $1,6002023-01-27 MEDIUM 6.5 CVE-2023-23613 OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implementation of field-level secur… Opensearch 1.3.8 / 2.5.0+ Fix from $1,6002023-01-26 CRITICAL 9.1 CVE-2023-0321 Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensiti… Cr6 Firmware No fix yet Fix from $2,3002023-01-26 MEDIUM 5.5 CVE-2022-4054 An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all ver… GitLab 15.4.6 / 15.5.5+ Fix from $1,6002023-01-26 MEDIUM 5.3 CVE-2022-31711EPSS 22% VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and applicatio… Vrealize Log Insight 8.10.2+ Fix from $1,6002023-01-26 MEDIUM 5.3 CVE-2022-39193 An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the p… Mediawiki Patch available Fix from $1,6002023-01-20 MEDIUM 6.5 CVE-2021-39089 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafte… Cloud Pak For Security after 1.10.6.0 Fix from $1,6002023-01-20 MEDIUM 5.9 CVE-2022-39167 IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-t… Spectrum Virtualize Patch available Fix from $1,6002023-01-19 HIGH 7.5 CVE-2022-45925EPSS 17% An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this pa… Opentext Extended Ecm after 22.3 Fix from $1,9502023-01-18 MEDIUM 6.5 CVE-2022-45103 Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A lo… Emc Solutions Enabler Virtual Appliance 9.2.3.6 / 9.2.3.12+ Fix from $1,6002023-01-18 MEDIUM 6.5 CVE-2022-2907 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, … GitLab 15.1.6 / 15.2.4+ Fix from $1,6002023-01-17 HIGH 7.5 CVE-2023-22875 IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do … Qradar Security Information And Event Manager Mitigation only Fix from $1,9502023-01-17 HIGH 7.5 CVE-2022-41859 In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce … Freeradius 3.0.0+ Fix from $1,9502023-01-17 HIGH 7.5 CVE-2022-3091 RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an a… Equipment Predictive Maintenance Mitigation only Fix from $1,9502023-01-17 MEDIUM 5.3 CVE-2022-48258 In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles. Eternal Terminal Patch available Fix from $1,6002023-01-13 MEDIUM 5.3 CVE-2022-46371 Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name. Ar7088h A Firmware after 16.10.3 Fix from $1,6002023-01-12 MEDIUM 5.3 CVE-2022-3870 An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, … GitLab 15.5.7 / 15.6.4+ Fix from $1,6002023-01-12 MEDIUM 5.5 CVE-2022-4457 Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker coul… Warp 6.20+ Fix from $1,6002023-01-11 MEDIUM 5.5 CVE-2022-4415 A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpab… Systemd 253+ Fix from $1,6002023-01-11