Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified HIGH 7.5
CVE-2025-60805

An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-res…

Mitigation only
Fix from $1,950 2025-10-28
Unclassified HIGH 7.5
CVE-2025-60858

Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing…

Mitigation only
Fix from $1,950 2025-10-28
Pilos MEDIUM 5.3
CVE-2025-62524

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-B…

Fix: 4.8.0+
Fix from $1,600 2025-10-27
Blu Ic2 Firmware HIGH 7.5
CVE-2025-12363

Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Fix: 1.20+
Fix from $1,950 2025-10-27
Trufusion Enterprise HIGH 7.5
CVE-2025-27225EPSS 17%

TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpo…

Fix: after 7.10.4.0
Fix from $1,950 2025-10-27
Unclassified HIGH 7.5
CVE-2025-52268

StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tok…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.2
CVE-2025-61482

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to …

Mitigation only
Fix from $1,950 2025-10-27
Unclassified CRITICAL 10.0
CVE-2025-61481

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path at…

Mitigation only
Fix from $2,300 2025-10-27
Learnhouse HIGH 7.5
CVE-2025-12276

A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of th…

Fix: after 2025-09-21
Fix from $1,950 2025-10-27
Unclassified MEDIUM 5.3
CVE-2025-11760

The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information i…

Mitigation only
Fix from $1,600 2025-10-25
Unclassified HIGH 7.5
CVE-2025-11145

Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor…

Mitigation only
Fix from $1,950 2025-10-24
Unclassified HIGH 7.5
CVE-2025-6980

Captive Portal can expose sensitive information

No fix yet
Fix from $1,950 2025-10-23
Moodle MEDIUM 6.5
CVE-2025-62400

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal priv…

Fix: 4.1.21 / 4.4.11+
Fix from $1,600 2025-10-23
Metersphere HIGH 7.5
CVE-2025-62604

MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval of arbitrary user information.…

Fix: 2.10.25+
Fix from $1,950 2025-10-22
Weblogic Server MEDIUM 5.3
CVE-2025-61764

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,600 2025-10-21
Graalvm HIGH 7.5
CVE-2025-53066

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supporte…

Mitigation only
Fix from $1,950 2025-10-21
Database Server MEDIUM 5.8
CVE-2025-53047

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and …

Fix: after 23.9
Fix from $1,600 2025-10-21
Product Hub HIGH 8.1
CVE-2025-53043

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.…

Fix: after 12.2.14
Fix from $1,950 2025-10-21
Financial Services Analytical Applications Infrastructure HIGH 8.6
CVE-2025-53036

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P…

Mitigation only
Fix from $1,950 2025-10-21
Unclassified HIGH 7.5
CVE-2025-61220

The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other users and gain unauthorized …

Mitigation only
Fix from $1,950 2025-10-21
Unclassified HIGH 8.6
CVE-2025-60344EPSS 10%

A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input paramet…

Mitigation only
Fix from $1,950 2025-10-21
Unclassified HIGH 8.2
CVE-2025-11151

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability …

Mitigation only
Fix from $1,950 2025-10-21
Manageengine Applications Manager MEDIUM 6.5
CVE-2025-6239

Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

Fix: 17.6+
Fix from $1,600 2025-10-21
Unclassified MEDIUM 6.9
CVE-2025-62699

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Translate Extension allows Footprint…

Mitigation only
Fix from $1,600 2025-10-21
Unclassified MEDIUM 5.3
CVE-2025-10750

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is…

Mitigation only
Fix from $1,600 2025-10-18
Unclassified MEDIUM 6.9
CVE-2025-62669

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resourc…

No fix yet
Fix from $1,600 2025-10-18
Icinga MEDIUM 6.5
CVE-2025-61907

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoin…

Fix: 2.13.13 / 2.14.7+
Fix from $1,600 2025-10-16
Strapi MEDIUM 6.5
CVE-2025-53092

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default…

Fix: 5.20.0+
Fix from $1,600 2025-10-16
Windows 11 22h2 MEDIUM 5.5
CVE-2025-59284

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

Fix: 10.0.22621.6060 / 10.0.22631.6060+
Fix from $1,600 2025-10-14
Windows Server 2016 MEDIUM 5.5
CVE-2025-59260

Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose inf…

Fix: 10.0.17763.7919 / 10.0.20348.4294+
Fix from $1,600 2025-10-14