Vulnerability index

Browse CVEs

90 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Debian Linux MEDIUM 6.5
CVE-2024-12426

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. …

Fix: 24.8.4+
Fix from $1,600 2025-01-07
Debian Linux MEDIUM 5.3
CVE-2023-26049

Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookie…

Fix: 9.4.51 / 10.0.14+
Fix from $1,600 2023-04-18
Debian Linux MEDIUM 5.5
CVE-2021-3800

A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivil…

Fix: 2.62.5 / 2.63.6+
Fix from $1,600 2022-08-23
Debian Linux HIGH 7.7
CVE-2022-31090

Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handle…

Fix: 6.5.8 / 7.4.5+
Fix from $1,950 2022-06-27
Debian Linux HIGH 7.7
CVE-2022-31091

Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a r…

Fix: 6.5.8 / 7.4.5+
Fix from $1,950 2022-06-27
Debian Linux MEDIUM 5.3
CVE-2022-26847

SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

Fix: 3.2.14 / 4.0.5+
Fix from $1,600 2022-03-10
Debian Linux HIGH 7.5
CVE-2022-23648EPSS 27%

containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.1…

Fix: 1.4.13 / 1.5.10+
Fix from $1,950 2022-03-03
Debian Linux MEDIUM 6.5
CVE-2022-0577

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.

Fix: 2.6.1+
Fix from $1,600 2022-03-02
Debian Linux HIGH 7.5
CVE-2022-21712

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following…

Fix: 22.1.0+
Fix from $1,950 2022-02-07
Debian Linux MEDIUM 6.5
CVE-2022-23607

treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq…

Fix: 22.1.0+
Fix from $1,600 2022-02-01
Debian Linux MEDIUM 5.3
CVE-2022-21296

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 6.1
CVE-2022-0235

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Fix: 1.0 / 2.6.7+
Fix from $1,600 2022-01-16
Debian Linux MEDIUM 6.5
CVE-2021-41125

Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a…

Fix: 1.8.1 / 2.5.1+
Fix from $1,600 2021-10-06
Debian Linux MEDIUM 5.5
CVE-2021-3566

Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that refer…

Fix: 4.3+
Fix from $1,600 2021-08-05
Debian Linux MEDIUM 5.3
CVE-2021-28169EPSS 78%

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access pro…

Fix: 9.4.41 / 10.0.3+
Fix from $1,600 2021-06-09
Debian Linux HIGH 7.5
CVE-2021-20313

A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. T…

Fix: 7.0.11-0+
Fix from $1,950 2021-05-11
Debian Linux MEDIUM 5.5
CVE-2020-15250

In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste…

Fix: 3.1.1 / 4.13.1+
Fix from $1,600 2020-10-12
Debian Linux MEDIUM 5.5
CVE-2012-0844

Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

Fix: after 2.8
Fix from $1,600 2020-02-21
Debian Linux MEDIUM 5.9
CVE-2014-6275

FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages a…

Fix: 5.3.2+
Fix from $1,600 2020-01-02
Debian Linux MEDIUM 5.5
CVE-2012-5476

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the adm…

Mitigation only
Fix from $1,600 2019-12-30
Debian Linux MEDIUM 5.5
CVE-2012-5644

libuser has information disclosure when moving user's home directory

Fix: 0.59+
Fix from $1,600 2019-11-25
Debian Linux HIGH 7.5
CVE-2013-1817

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive informatio…

Fix: 1.19.4 / 1.20.3+
Fix from $1,950 2019-11-20
Debian Linux MEDIUM 5.5
CVE-2012-0843

uzbl: Information disclosure via world-readable cookies storage file

Mitigation only
Fix from $1,600 2019-11-19
Debian Linux MEDIUM 5.5
CVE-2012-0842

surf: cookie jar has read access from other local user

Fix: 0.5+
Fix from $1,600 2019-11-19
Debian Linux HIGH 7.5
CVE-2013-7089

ClamAV before 0.97.7: dbg_printhex possible information leak

Fix: 0.97.7+
Fix from $1,950 2019-11-15
Debian Linux HIGH 7.5
CVE-2010-2450

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed …

Patch available
Fix from $1,950 2019-11-07
Debian Linux HIGH 7.5
CVE-2009-5045

Dump Servlet information leak in jetty before 6.1.22.

Fix: 6.1.22+
Fix from $1,950 2019-11-06
Debian Linux HIGH 7.5
CVE-2013-2600

MiniUPnPd has information disclosure use of snprintf()

No fix yet
Fix from $1,950 2019-11-01
Debian Linux MEDIUM 6.5
CVE-2019-12746

An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS…

Fix: after 6.0.19
Fix from $1,600 2019-08-21
Debian Linux MEDIUM 5.3
CVE-2019-12497

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x…

Fix: after 7.0.8
Fix from $1,600 2019-06-17