Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2025-12770

The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficie…

Mitigation only
Fix from $1,600 2025-11-19
Kubevirt HIGH 7.7
CVE-2025-64324

KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by …

Fix: 1.6.1+
Fix from $1,950 2025-11-18
Arubaos Cx MEDIUM 6.5
CVE-2025-37160

A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to…

Fix: 10.10.1170 / 10.13.1101+
Fix from $1,600 2025-11-18
Fortiadc MEDIUM 6.5
CVE-2025-54971

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all v…

Fix: 7.4.3+
Fix from $1,600 2025-11-18
Unclassified MEDIUM 5.3
CVE-2025-12545

The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Information Ex…

Mitigation only
Fix from $1,600 2025-11-18
Simple Online Book Store System HIGH 7.5
CVE-2025-63891

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to di…

No fix yet
Fix from $1,950 2025-11-14
Pingalert Application Server HIGH 7.5
CVE-2025-54345

An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Information is exposed to an Unauthori…

Fix: 6.1.1.4+
Fix from $1,950 2025-11-14
Unclassified MEDIUM 6.0
CVE-2025-12149

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered fro…

Mitigation only
Fix from $1,600 2025-11-14
W1y47a Firmware HIGH 7.5
CVE-2025-12785

Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination add…

Fix: 002.2539e+
Fix from $1,950 2025-11-13
Maxkb MEDIUM 6.5
CVE-2025-64703

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations by Python code in tool module,…

Fix: 2.3.1+
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-12681

The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ…

Mitigation only
Fix from $1,600 2025-11-13
Dynamics 365 MEDIUM 6.5
CVE-2025-62206

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose inform…

Fix: 9.1.41.07+
Fix from $1,600 2025-11-11
365 Apps MEDIUM 5.5
CVE-2025-59240

Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $1,600 2025-11-11
Unclassified HIGH 8.9
CVE-2025-11697

A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the…

Mitigation only
Fix from $1,950 2025-11-11
Photo Station CRITICAL 9.8
CVE-2017-20210

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.

Mitigation only
Fix from $2,300 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-11997

The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 6.5
CVE-2025-12010

The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbit…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-12098

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve…

Mitigation only
Fix from $1,600 2025-11-08
Unclassified MEDIUM 5.3
CVE-2025-64179

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in th…

Patch available
Fix from $1,600 2025-11-06
Quipux MEDIUM 5.3
CVE-2025-55342

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Adm…

Mitigation only
Fix from $1,600 2025-11-05
Guests MEDIUM 5.3
CVE-2025-59716

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient…

Fix: after 0.12.4
Fix from $1,600 2025-11-05
Funnelkit Automations MEDIUM 5.3
CVE-2025-12468

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Informatio…

Fix: 3.6.4.2+
Fix from $1,600 2025-11-05
Unclassified MEDIUM 5.3
CVE-2025-12677

The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the register_a…

Mitigation only
Fix from $1,600 2025-11-05
Unclassified HIGH 7.5
CVE-2025-12139

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all…

Mitigation only
Fix from $1,950 2025-11-05
Unclassified CRITICAL 9.8
CVE-2025-11749EPSS 75%

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST …

Mitigation only
Fix from $2,300 2025-11-05
Linkace MEDIUM 6.5
CVE-2025-62721

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class …

Fix: 2.4.0+
Fix from $1,600 2025-11-04
Linkace MEDIUM 6.5
CVE-2025-62720

LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of lin…

Fix: 2.4.0+
Fix from $1,600 2025-11-04
Codeshare MEDIUM 5.3
CVE-2025-60925

codeshare v1.0.0 was discovered to contain an information leakage vulnerability.

No fix yet
Fix from $1,600 2025-11-04
Exynos 1080 Firmware HIGH 7.5
CVE-2025-54323

An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. Imp…

Mitigation only
Fix from $1,950 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43479

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04