Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Robot Operating System CRITICAL 9.8
CVE-2024-39780

A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting…

Patch available
Fix from $2,300 2025-04-02
Chrome HIGH 8.8
CVE-2025-3068

Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation …

Fix: 135.0.7049.52+
Fix from $1,950 2025-04-02
Chrome MEDIUM 6.5
CVE-2025-3070

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escal…

Fix: 135.0.7049.52+
Fix from $1,600 2025-04-02
Unclassified MEDIUM 5.3
CVE-2025-31135

Go-Guerrilla SMTP Daemon is a lightweight SMTP server written in Go. Prior to 1.6.7, when ProxyOn is enabled, the PROXY command will be accepted mult…

Patch available
Fix from $1,600 2025-04-01
Unclassified HIGH 8.1
CVE-2025-31132

Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fix…

Mitigation only
Fix from $1,950 2025-04-01
Ipados HIGH 7.5
CVE-2025-30471

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonom…

Fix: 2.4 / 13.7.5+
Fix from $1,950 2025-03-31
macOS CRITICAL 9.8
CVE-2025-30452

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An input validati…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS HIGH 8.4
CVE-2025-24255

A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.…

Fix: 13.7.5 / 14.7.5+
Fix from $1,950 2025-03-31
macOS MEDIUM 5.5
CVE-2025-24191

The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify pr…

Fix: 15.4+
Fix from $1,600 2025-03-31
Linux Bluefield HIGH 7.5
CVE-2023-0881

Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subseq…

Fix: 5.4.0-1058.64+
Fix from $1,950 2025-03-31
PHP MEDIUM 5.3
CVE-2025-1734

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server…

Fix: 8.1.32 / 8.2.28+
Fix from $1,600 2025-03-30
PHP HIGH 7.3
CVE-2025-1736

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, th…

Fix: 8.1.32 / 8.2.28+
Fix from $1,950 2025-03-30
Eladmin HIGH 7.2
CVE-2025-2855

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of…

Fix: after 2.7
Fix from $1,950 2025-03-27
Synapse HIGH 7.5
CVE-2025-30355

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1…

Fix: 1.127.1+
Fix from $1,950 2025-03-27
Advanced Iframe MEDIUM 5.3
CVE-2025-1440

The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all ve…

Fix: 2025.0+
Fix from $1,600 2025-03-26
Unclassified HIGH 7.3
CVE-2025-1514

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to…

Mitigation only
Fix from $1,950 2025-03-26
Frappe HIGH 8.8
CVE-2025-30213

Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a spec…

Fix: 14.91.0 / 15.52.0+
Fix from $1,950 2025-03-25
Unclassified HIGH 8.8
CVE-2025-24514EPSS 33%

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to…

No fix yet
Fix from $1,950 2025-03-25
Unclassified HIGH 8.8
CVE-2025-1098EPSS 83%

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress an…

No fix yet
Fix from $1,950 2025-03-25
Unclassified HIGH 8.8
CVE-2025-1097EPSS 36%

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can b…

No fix yet
Fix from $1,950 2025-03-25
Yii CRITICAL 9.8
CVE-2025-2690

A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src…

Fix: after 2.0.39
Fix from $2,300 2025-03-24
Yii CRITICAL 9.8
CVE-2025-2689

A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of…

Fix: after 2.0.45
Fix from $2,300 2025-03-24
Snail Job HIGH 8.8
CVE-2025-2622

A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/w…

No fix yet
Fix from $1,950 2025-03-22
Unclassified MEDIUM 5.3
CVE-2024-13666

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing …

Mitigation only
Fix from $1,600 2025-03-22
Partner Center HIGH 8.8
CVE-2025-29814

Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-03-21
Unclassified HIGH 7.5
CVE-2025-1385

When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamica…

Mitigation only
Fix from $1,950 2025-03-20
Unclassified HIGH 7.3
CVE-2025-2376

A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCo…

Mitigation only
Fix from $1,950 2025-03-17
Unclassified MEDIUM 6.5
CVE-2025-1767

This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Sin…

Patch available
Fix from $1,600 2025-03-13
Unclassified MEDIUM 5.9
CVE-2024-9042

This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.

No fix yet
Fix from $1,600 2025-03-13
Unclassified HIGH 8.7
CVE-2024-26290

Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid …

Mitigation only
Fix from $1,950 2025-03-12