Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified HIGH 7.0
CVE-2025-14553

Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo cameras, allowing attackers to br…

Mitigation only
Fix from $1,950 2025-12-16
Filemaker Server MEDIUM 5.3
CVE-2025-46294

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8do…

Fix: 22.0.4+
Fix from $1,600 2025-12-16
Unclassified MEDIUM 5.9
CVE-2025-13439

The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including…

Mitigation only
Fix from $1,600 2025-12-16
Hi3120 Firmware MEDIUM 5.5
CVE-2025-66963

An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html

No fix yet
Fix from $1,600 2025-12-15
Unclassified CRITICAL 9.8
CVE-2025-11693

The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.…

Mitigation only
Fix from $2,300 2025-12-13
macOS MEDIUM 5.5
CVE-2025-43523

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to …

Fix: 15.7.3+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43530

This issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS …

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43538

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sono…

Fix: 14.8.3+
Fix from $1,600 2025-12-12
macOS HIGH 7.5
CVE-2025-43542

This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia…

Fix: 15.7.3+
Fix from $1,950 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43473

This issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

Fix: 26.1+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43509

This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app ma…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
Unclassified MEDIUM 5.3
CVE-2025-12408

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified MEDIUM 5.3
CVE-2025-13660

The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. This is due to the plugin expo…

Mitigation only
Fix from $1,600 2025-12-12
Dir 803 Firmware HIGH 7.5
CVE-2025-14528

A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Han…

Fix: after 1.04
Fix from $1,950 2025-12-11
Unclassified HIGH 8.7
CVE-2025-67718

Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path…

Patch available
Fix from $1,950 2025-12-11
Meatmeet CRITICAL 9.8
CVE-2025-65820

An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application which opens a…

Mitigation only
Fix from $2,300 2025-12-10
Xiangshan HIGH 7.5
CVE-2025-63094

XiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackers to acces…

No fix yet
Fix from $1,950 2025-12-10
Runbook Automation MEDIUM 6.5
CVE-2025-52493

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear mask…

Fix: after 2025-06-12
Fix from $1,600 2025-12-10
Windows 10 21h2 MEDIUM 6.5
CVE-2025-64670

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over…

Fix: 10.0.19044.6691 / 10.0.19045.6691+
Fix from $1,600 2025-12-09
Ac9 Firmware HIGH 7.5
CVE-2025-14286

A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/Downlo…

No fix yet
Fix from $1,950 2025-12-09
Unclassified MEDIUM 5.8
CVE-2024-38798

EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Succe…

No fix yet
Fix from $1,600 2025-12-09
Harmonyos MEDIUM 5.5
CVE-2025-66330

App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect service confi…

No fix yet
Fix from $1,600 2025-12-08
Harmonyos MEDIUM 5.5
CVE-2025-58279

Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentialit…

No fix yet
Fix from $1,600 2025-12-08
Verysync MEDIUM 5.3
CVE-2025-14198

A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummyt…

Fix: after 2.21.3
Fix from $1,600 2025-12-07
Unclassified MEDIUM 5.3
CVE-2025-14197

A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/res…

Mitigation only
Fix from $1,600 2025-12-07
Strimzi HIGH 7.4
CVE-2025-66623

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.…

Fix: 0.49.1+
Fix from $1,950 2025-12-05
Unclassified MEDIUM 5.3
CVE-2025-13494

The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the pl…

Mitigation only
Fix from $1,600 2025-12-05
Unclassified MEDIUM 5.3
CVE-2025-13006

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ…

Mitigation only
Fix from $1,600 2025-12-05
Unclassified HIGH 7.4
CVE-2025-10285

The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker coul…

Mitigation only
Fix from $1,950 2025-12-04
Composio HIGH 7.5
CVE-2025-56427

Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir funct…

No fix yet
Fix from $1,950 2025-12-04