Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Firefox HIGH 7.5
CVE-2025-10535

Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.

Fix: 143.0+
Fix from $1,950 2025-09-16
Firefox MEDIUM 6.2
CVE-2025-10536

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thund…

Fix: 140.3.0 / 143.0+
Fix from $1,600 2025-09-16
Unclassified MEDIUM 5.7
CVE-2025-26711

There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker …

Mitigation only
Fix from $1,600 2025-09-16
Unclassified MEDIUM 5.3
CVE-2025-9808

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint…

Mitigation only
Fix from $1,600 2025-09-16
Ipados CRITICAL 9.8
CVE-2025-43362

The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to monitor ke…

Fix: 18.7+
Fix from $2,300 2025-09-15
macOS MEDIUM 5.5
CVE-2025-43367

A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protec…

Fix: 14.8 / 26.0+
Fix from $1,600 2025-09-15
Safari MEDIUM 6.5
CVE-2025-43356

The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tah…

Fix: 18.7 / 26.0+
Fix from $1,600 2025-09-15
Wl Wn578w2 Firmware MEDIUM 5.3
CVE-2025-10321

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead t…

No fix yet
Fix from $1,600 2025-09-12
Unclassified MEDIUM 6.5
CVE-2025-56467

An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as acc…

Mitigation only
Fix from $1,600 2025-09-12
Hoverfly HIGH 7.5
CVE-2025-54376

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by…

Fix: 1.12.0+
Fix from $1,950 2025-09-10
Iwr 3000n Firmware HIGH 8.4
CVE-2025-55976

Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can d…

Fix: after 1.9.8
Fix from $1,950 2025-09-10
Unclassified HIGH 7.5
CVE-2025-56406

An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified HIGH 8.7
CVE-2025-36759

Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addre…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified HIGH 7.5
CVE-2025-29089

An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information

Mitigation only
Fix from $1,950 2025-09-09
Officeplus HIGH 7.5
CVE-2025-55243

Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a networ…

Fix: 3.10.0.26585+
Fix from $1,950 2025-09-09
Windows 10 1507 MEDIUM 5.5
CVE-2025-53804

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Sql Server 2016 MEDIUM 5.3
CVE-2025-47997

Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose i…

Fix: 13.0.6470.1 / 13.0.7065.1+
Fix from $1,600 2025-09-09
Aptio V MEDIUM 6.7
CVE-2025-33045

APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to …

Fix: 5.040+
Fix from $1,600 2025-09-09
TYPO3 MEDIUM 6.5
CVE-2025-59018

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑1…

Fix: 9.5.55 / 10.4.54+
Fix from $1,600 2025-09-09
Unclassified MEDIUM 5.3
CVE-2025-40757

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BA…

Mitigation only
Fix from $1,600 2025-09-09
Vite MEDIUM 5.3
CVE-2025-58751

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the pu…

Fix: 5.4.20 / 6.3.6+
Fix from $1,600 2025-09-08
Vite MEDIUM 5.3
CVE-2025-58752

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served reg…

Fix: 5.4.20 / 6.3.6+
Fix from $1,600 2025-09-08
Unclassified CRITICAL 9.8
CVE-2025-22956

OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if an…

Mitigation only
Fix from $2,300 2025-09-08
Dir 852 Firmware HIGH 7.5
CVE-2025-10093

A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php…

No fix yet
Fix from $1,950 2025-09-08
Atlantis HIGH 7.5
CVE-2025-58445

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose de…

Fix: after 0.35.1
Fix from $1,950 2025-09-06
Unclassified MEDIUM 5.3
CVE-2025-7368

The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information Exposure in all versions up t…

Mitigation only
Fix from $1,600 2025-09-06
Xbox Gaming Services HIGH 7.5
CVE-2025-55242

Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2025-09-04
Argo Cd CRITICAL 9.9
CVE-2025-55190EPSS 5%

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.…

Fix: 2.13.9 / 2.14.16+
Fix from $2,300 2025-09-04
Android MEDIUM 6.2
CVE-2025-48527

In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead to local i…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-26453

In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could l…

Patch available
Fix from $1,600 2025-09-04