Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 1507 MEDIUM 6.5
CVE-2025-59214

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-59209

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information lo…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-59211

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information lo…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows Server 2016 MEDIUM 5.5
CVE-2025-59186

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.7919 / 10.0.20348.4294+
Fix from $1,600 2025-10-14
Windows Server 2012 MEDIUM 5.5
CVE-2025-59188

Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8519 / 10.0.17763.7919+
Fix from $1,600 2025-10-14
Windows 10 1507 MEDIUM 6.5
CVE-2025-58739

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows Server 2016 MEDIUM 5.5
CVE-2025-59184

Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose informatio…

Fix: 10.0.17763.7919 / 10.0.20348.4294+
Fix from $1,600 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-55699

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows Server 2016 MEDIUM 5.5
CVE-2025-55683

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8519 / 10.0.17763.7919+
Fix from $1,600 2025-10-14
Windows 10 1809 MEDIUM 5.5
CVE-2025-55336

Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose inform…

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,600 2025-10-14
Fortiadc MEDIUM 6.5
CVE-2025-59921

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, ve…

Fix: 7.1.5 / 7.2.4+
Fix from $1,600 2025-10-14
Firefox CRITICAL 9.1
CVE-2025-11717

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the las…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11710

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the comprom…

Fix: 115.29.0 / 140.4.0+
Fix from $2,300 2025-10-14
Omni HIGH 7.5
CVE-2025-61688

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API.

Fix: 1.0.2 / 1.1.5+
Fix from $1,950 2025-10-13
Unclassified HIGH 8.7
CVE-2025-8915

Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-in-the-middle attack via the n…

Mitigation only
Fix from $1,950 2025-10-13
Furbo Mini Firmware MEDIUM 6.8
CVE-2025-11647

A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component GATT Service. This manipulatio…

Fix: after 074
Fix from $1,600 2025-10-12
Furbo Mini Firmware MEDIUM 5.5
CVE-2025-11639

A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file collect_logs.sh of the co…

Fix: after 074
Fix from $1,600 2025-10-12
Unclassified MEDIUM 5.3
CVE-2025-8484

The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files.…

Mitigation only
Fix from $1,600 2025-10-11
Unclassified MEDIUM 5.3
CVE-2025-9196

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure…

Mitigation only
Fix from $1,600 2025-10-11
Harmonyos MEDIUM 5.5
CVE-2025-58278

Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2025-10-11
Harmonyos MEDIUM 5.5
CVE-2025-58277

Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2025-10-11
Learning MEDIUM 5.3
CVE-2025-62158

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments upl…

Patch available
Fix from $1,600 2025-10-10
Rack MEDIUM 5.3
CVE-2025-61780

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in …

Fix: 2.2.20 / 3.1.18+
Fix from $1,600 2025-10-10
Unclassified MEDIUM 6.1
CVE-2025-8887

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in …

Mitigation only
Fix from $1,600 2025-10-10
Unclassified MEDIUM 6.7
CVE-2025-8886

Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect A…

Mitigation only
Fix from $1,600 2025-10-10
Aion HIGH 7.5
CVE-2025-52634

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

No fix yet
Fix from $1,950 2025-10-10
Aion HIGH 7.5
CVE-2025-52630

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

No fix yet
Fix from $1,950 2025-10-10
Opnform MEDIUM 5.9
CVE-2025-11443

A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forg…

Fix: after 1.9.3
Fix from $1,600 2025-10-08
Flagforge CRITICAL 9.1
CVE-2025-61777

Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/a…

Fix: 2.3.2+
Fix from $2,300 2025-10-06
Baggage Analytics MEDIUM 6.5
CVE-2025-58589

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other inter…

Mitigation only
Fix from $1,600 2025-10-06