Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2022-4543 A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via p… Linux Kernel No fix yet Fix from $1,6002023-01-11 HIGH 7.5 CVE-2022-46163 Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Ha… Travel Support Program 2022-11-29+ Fix from $1,9502023-01-10 MEDIUM 5.7 CVE-2023-0023 In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directl… Bank Account Management Mitigation only Fix from $1,6002023-01-10 MEDIUM 6.0 CVE-2022-23509 Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps r… Weave Gitops 0.12.0+ Fix from $1,6002023-01-09 HIGH 7.5 CVE-2023-0113 A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown func… Netcore Router Firmware Mitigation only Fix from $1,9502023-01-07 HIGH 8.8 CVE-2022-42979EPSS 24% Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an acc… Ryde Mitigation only Fix from $1,9502023-01-06 MEDIUM 5.3 CVE-2023-22453 Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-p… Discourse 2.8.14+ Fix from $1,6002023-01-05 MEDIUM 5.5 CVE-2022-23546 In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, poss… Discourse 2.9.0+ Fix from $1,6002023-01-05 MEDIUM 5.3 CVE-2022-43573 IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modifier of platform level object… Robotic Process Automation 21.0.7+ Fix from $1,6002023-01-05 HIGH 7.5 CVE-2022-4869 A vulnerability was found in Evolution Events Artaxerxes. It has been declared as problematic. This vulnerability affects unknown code of the file ar… Artaxerxes 2022-08-12+ Fix from $1,9502023-01-05 MEDIUM 5.5 CVE-2022-43540 A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensit… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,6002023-01-05 MEDIUM 6.5 CVE-2022-22337 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive information to an authenticated user. IBM X-Force ID: … Sterling B2b Integrator 6.0.3.7 / 6.1.0.6+ Fix from $1,6002023-01-04 HIGH 7.5 CVE-2022-46081 In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of private personal information. N… Connect No fix yet Fix from $1,9502023-01-04 HIGH 7.5 CVE-2013-10007 A vulnerability classified as problematic has been found in ethitter WP-Print-Friendly up to 0.5.2. This affects an unknown part of the file wp-print… Wp Print Friendly 0.5.3+ Fix from $1,9502023-01-03 HIGH 7.5 CVE-2022-3460 In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed in variab… Octopus Server 2022.3.10750 / 2022.4.8063+ Fix from $1,9502023-01-03 MEDIUM 6.1 CVE-2022-34674 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than … Gpu Display Driver 11.11 / 13.6+ Fix from $1,6002022-12-30 MEDIUM 5.3 CVE-2019-14802 HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GH… Nomad 0.9.5+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2019-18177 In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This aff… Application Delivery Controller Firmware 13.0-58.30+ Fix from $1,6002022-12-26 MEDIUM 5.3 CVE-2022-41767 An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are… Mediawiki 1.35.8 / 1.37.5+ Fix from $1,6002022-12-26 HIGH 8.1 CVE-2022-45414 If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER att… Thunderbird 102.5.1+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-31746 Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Fi… Firefox Mobile 102.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-29916 Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to pro… Firefox 91.9 / 100.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-22745 Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91… Firefox 91.5 / 96.0+ Fix from $1,6002022-12-22 MEDIUM 5.3 CVE-2022-25948 The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking pr… Liquidjs 10.0.0+ Fix from $1,6002022-12-22 MEDIUM 5.3 CVE-2022-3185 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning the devic… Iboot Pdu4 N20 Firmware 1.42.06162022+ Fix from $1,6002022-12-21 HIGH 7.5 CVE-2022-46310 The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality. Harmonyos 3.0.0+ Fix from $1,9502022-12-20 HIGH 7.5 CVE-2022-23488 BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Da… Bigbluebutton 2.4+ Fix from $1,9502022-12-17 MEDIUM 5.7 CVE-2022-41964 BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can st… Bigbluebutton Patch available Fix from $1,6002022-12-16 MEDIUM 5.5 CVE-2022-20591 In ppmpu_set of ppmpu.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure… Android Mitigation only Fix from $1,6002022-12-16 MEDIUM 5.5 CVE-2022-46702 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory. Ipados 16.2+ Fix from $1,6002022-12-15