Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Veeam Backup \& Replication CRITICAL 9.0
CVE-2025-59469

This vulnerability allows a Backup or Tape Operator to write files as root.

Fix: 13.0.1.1071+
Fix from $2,300 2026-01-08
Kanboard MEDIUM 5.3
CVE-2026-21880

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP aut…

Fix: 1.2.49+
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.3
CVE-2026-20027

Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to…

Mitigation only
Fix from $1,600 2026-01-07
Ar8035 Firmware MEDIUM 5.5
CVE-2025-47369

Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.

Patch available
Fix from $1,600 2026-01-07
Unclassified HIGH 8.6
CVE-2025-13371

The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.9. This is due to the …

Mitigation only
Fix from $1,950 2026-01-07
Unclassified MEDIUM 5.3
CVE-2025-13215

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.…

Mitigation only
Fix from $1,600 2026-01-06
Aiohttp MEDIUM 5.3
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existen…

Fix: 3.13.3+
Fix from $1,600 2026-01-05
Craft Cms MEDIUM 6.5
CVE-2025-68436

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Cr…

Fix: 4.16.17 / 5.8.21+
Fix from $1,600 2026-01-05
Dify MEDIUM 6.5
CVE-2025-67732

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-admin…

Fix: 1.11.0+
Fix from $1,600 2026-01-05
Signal K Server MEDIUM 5.3
CVE-2025-68273

Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions pri…

Fix: 2.19.0+
Fix from $1,600 2026-01-01
Uri HIGH 7.5
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earl…

Fix: 0.12.5 / 0.13.3+
Fix from $1,950 2025-12-30
Dvp 12se11t Firmware CRITICAL 9.8
CVE-2025-15103

DVP-12SE11T - Authentication Bypass via Partial Password Disclosure

Fix: 2.16+
Fix from $2,300 2025-12-30
Unclassified MEDIUM 5.3
CVE-2025-14280

The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.1.5 through publicly …

Mitigation only
Fix from $1,600 2025-12-29
Web Fax MEDIUM 6.5
CVE-2025-15070

Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse. Thi…

Fix: 4.0+
Fix from $1,600 2025-12-29
Unclassified MEDIUM 6.3
CVE-2025-15065

Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties…

Mitigation only
Fix from $1,600 2025-12-29
Sciter MEDIUM 5.5
CVE-2024-29720

An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the S…

No fix yet
Fix from $1,600 2025-12-26
Zlt M30s Firmware HIGH 7.5
CVE-2025-15082

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Managemen…

Fix: after 1.47
Fix from $1,950 2025-12-25
Unclassified HIGH 7.5
CVE-2025-12491

Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio…

Mitigation only
Fix from $1,950 2025-12-23
Gt Edge Ai HIGH 7.5
CVE-2025-63662

Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive informatio…

Fix: 2.0.12+
Fix from $1,950 2025-12-22
Unclassified MEDIUM 6.5
CVE-2025-15033

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configurat…

Mitigation only
Fix from $1,600 2025-12-22
Unclassified MEDIUM 6.5
CVE-2025-8305

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being prin…

Mitigation only
Fix from $1,600 2025-12-22
Unclassified MEDIUM 6.5
CVE-2025-8304

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being acce…

Mitigation only
Fix from $1,600 2025-12-22
Unclassified MEDIUM 5.3
CVE-2025-12492

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Mitigation only
Fix from $1,600 2025-12-20
Delphix Continuous Compliance HIGH 7.5
CVE-2025-14591

In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EO…

Fix: after 2025.6.0.0
Fix from $1,950 2025-12-20
Weblate MEDIUM 6.5
CVE-2025-68279

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf…

Fix: 5.15.1+
Fix from $1,600 2025-12-18
Storybook MEDIUM 5.3
CVE-2025-68429

Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 an…

Fix: 7.6.21 / 8.6.15+
Fix from $1,600 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-68110

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the hos…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
macOS MEDIUM 5.5
CVE-2025-46278

The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data.

Fix: 26.2+
Fix from $1,600 2025-12-17
macOS MEDIUM 5.5
CVE-2025-46283

A logic issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access sens…

Fix: 26.2+
Fix from $1,600 2025-12-17
macOS MEDIUM 5.5
CVE-2025-43514

The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data.

Fix: 26.2+
Fix from $1,600 2025-12-17