Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Ipados MEDIUM 5.4
CVE-2025-43495

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to mo…

Fix: 26.1+
Fix from $1,600 2025-11-04
Ipados MEDIUM 5.5
CVE-2025-43455

A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. A…

Fix: 26.1+
Fix from $1,600 2025-11-04
Ipados HIGH 7.5
CVE-2025-43449

The issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious app may be able to track users…

Fix: 26.1+
Fix from $1,950 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43411

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An a…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
Ipados MEDIUM 5.5
CVE-2025-43391

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43378

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to …

Fix: 15.7.2+
Fix from $1,600 2025-11-04
Ipados MEDIUM 5.5
CVE-2025-43360

The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentionally revealed.

Fix: 26.0+
Fix from $1,600 2025-11-04
Ipados MEDIUM 5.5
CVE-2025-43345

A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, ma…

Fix: 14.8 / 15.7+
Fix from $1,600 2025-11-04
Ipados HIGH 8.1
CVE-2025-43323

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watch…

Fix: 26.0+
Fix from $1,950 2025-11-04
Unclassified MEDIUM 6.8
CVE-2025-60892

An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting u…

Mitigation only
Fix from $1,600 2025-11-03
News Portal MEDIUM 5.9
CVE-2025-12616

A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a m…

No fix yet
Fix from $1,600 2025-11-03
Unclassified CRITICAL 10.0
CVE-2025-29270

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the…

Mitigation only
Fix from $2,300 2025-10-31
Unclassified MEDIUM 5.3
CVE-2025-12521

The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify …

Mitigation only
Fix from $1,600 2025-10-31
Log Server MEDIUM 6.5
CVE-2025-34272

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back…

Fix: 2024+
Fix from $1,600 2025-10-30
Unclassified MEDIUM 6.8
CVE-2025-11998

The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing prior user identity to be inh…

Mitigation only
Fix from $1,600 2025-10-30
Unclassified MEDIUM 6.0
CVE-2025-12147

In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclu…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified MEDIUM 6.0
CVE-2025-12148

In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified MEDIUM 5.3
CVE-2023-7320

The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS ha…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified HIGH 7.5
CVE-2025-60805

An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-res…

Mitigation only
Fix from $1,950 2025-10-28
Unclassified HIGH 7.5
CVE-2025-60858

Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing…

Mitigation only
Fix from $1,950 2025-10-28
Pilos MEDIUM 5.3
CVE-2025-62524

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-B…

Fix: 4.8.0+
Fix from $1,600 2025-10-27
Blu Ic2 Firmware HIGH 7.5
CVE-2025-12363

Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Fix: 1.20+
Fix from $1,950 2025-10-27
Trufusion Enterprise HIGH 7.5
CVE-2025-27225EPSS 17%

TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpo…

Fix: after 7.10.4.0
Fix from $1,950 2025-10-27
Unclassified HIGH 7.5
CVE-2025-52268

StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tok…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.2
CVE-2025-61482

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to …

Mitigation only
Fix from $1,950 2025-10-27
Unclassified CRITICAL 10.0
CVE-2025-61481

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path at…

Mitigation only
Fix from $2,300 2025-10-27
Learnhouse HIGH 7.5
CVE-2025-12276

A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of th…

Fix: after 2025-09-21
Fix from $1,950 2025-10-27
Unclassified MEDIUM 5.3
CVE-2025-11760

The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information i…

Mitigation only
Fix from $1,600 2025-10-25
Unclassified HIGH 7.5
CVE-2025-11145

Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor…

Mitigation only
Fix from $1,950 2025-10-24
Unclassified HIGH 7.5
CVE-2025-6980

Captive Portal can expose sensitive information

No fix yet
Fix from $1,950 2025-10-23