Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified HIGH 7.7
CVE-2025-61679

Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even wi…

Patch available
Fix from $1,950 2025-10-03
Unclassified CRITICAL 9.8
CVE-2025-9209

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due t…

Mitigation only
Fix from $2,300 2025-10-03
Cursor MEDIUM 5.9
CVE-2025-61589

Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then g…

Fix: 1.7+
Fix from $1,600 2025-10-03
Wegia HIGH 7.5
CVE-2025-61665

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability,…

Fix: 3.5.0+
Fix from $1,950 2025-10-02
Flock Safety HIGH 7.5
CVE-2025-59405

The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers …

No fix yet
Fix from $1,950 2025-10-02
Firefly Mall HIGH 7.5
CVE-2025-56161

YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the rela…

No fix yet
Fix from $1,950 2025-10-02
Lxd MEDIUM 5.3
CVE-2025-54290

Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence wi…

Fix: 5.21.4 / 6.5+
Fix from $1,600 2025-10-02
Energy Crm MEDIUM 5.4
CVE-2025-40646

Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by interceptin…

Mitigation only
Fix from $1,600 2025-10-02
Unclassified HIGH 8.7
CVE-2025-40645

Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensitive information about customer…

Mitigation only
Fix from $1,950 2025-10-02
Unclassified MEDIUM 5.9
CVE-2025-10744

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and…

Mitigation only
Fix from $1,600 2025-10-01
Virtual Appliance Application MEDIUM 5.3
CVE-2025-34220

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,600 2025-09-29
Automate HIGH 8.8
CVE-2025-8868EPSS 23%

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restrict…

Fix: 4.13.295+
Fix from $1,950 2025-09-29
Farm Management System CRITICAL 9.8
CVE-2025-11079

A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation r…

Mitigation only
Fix from $2,300 2025-09-27
Passrecovery HIGH 7.5
CVE-2025-45994

An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /use…

No fix yet
Fix from $1,950 2025-09-26
Vvveb HIGH 7.5
CVE-2025-11028

A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image Handler. Performing manipulati…

Fix: after 1.0.7.2
Fix from $1,950 2025-09-26
Mw305r Firmware MEDIUM 6.8
CVE-2025-56463

Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.

Fix: after 3.30
Fix from $1,600 2025-09-26
Vvveb HIGH 7.5
CVE-2025-11026

A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configurati…

Fix: after 1.0.7.2
Fix from $1,950 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-10952

A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream…

Mitigation only
Fix from $1,600 2025-09-25
Powerscale Onefs HIGH 7.5
CVE-2025-36601

Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An un…

Fix: 9.5.1.4 / 9.7.1.10+
Fix from $1,950 2025-09-25
Flagforge HIGH 7.5
CVE-2025-59833

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hin…

Fix: 2.3+
Fix from $1,950 2025-09-24
Dotnetnuke MEDIUM 6.5
CVE-2025-59535

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary them…

Fix: 10.1.0+
Fix from $1,600 2025-09-22
Unclassified CRITICAL 9.6
CVE-2025-59434

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated …

Mitigation only
Fix from $2,300 2025-09-22
Web Presenter Hd Firmware CRITICAL 9.8
CVE-2025-57437

The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected…

Mitigation only
Fix from $2,300 2025-09-22
Atem Mini Pro Firmware CRITICAL 9.8
CVE-2025-57441

The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Up…

Mitigation only
Fix from $2,300 2025-09-22
Creabox Manager HIGH 7.5
CVE-2025-57430

Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns int…

No fix yet
Fix from $1,950 2025-09-22
Ip 4c Firmware MEDIUM 6.5
CVE-2025-57433

The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a specific endpo…

No fix yet
Fix from $1,600 2025-09-22
Unclassified HIGH 8.8
CVE-2023-49367

An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by…

Mitigation only
Fix from $1,950 2025-09-18
Unclassified MEDIUM 5.3
CVE-2024-25011

Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remed…

Mitigation only
Fix from $1,600 2025-09-18
I Educar MEDIUM 6.5
CVE-2025-10607

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi…

Fix: after 2.10.0
Fix from $1,600 2025-09-17
Eve X1 Server Firmware HIGH 7.5
CVE-2025-34185

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote atta…

Fix: after 4.7.18.0
Fix from $1,950 2025-09-16