Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified HIGH 7.5
CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.5
CVE-2025-36895

Information disclosure

No fix yet
Fix from $1,950 2025-09-04
Desk Phone 9841 Firmware HIGH 7.5
CVE-2025-20336

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could a…

Fix: 3.3 / 14.3+
Fix from $1,950 2025-09-03
Evolved Programmable Network Manager MEDIUM 6.5
CVE-2025-20270

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow…

Fix: 8.0.1 / 8.1.2+
Fix from $1,600 2025-09-03
Experience Commerce HIGH 7.5
CVE-2025-53694EPSS 6%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (…

Fix: 10.4+
Fix from $1,950 2025-09-03
Parking Management System HIGH 7.5
CVE-2025-9843

A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This mani…

Mitigation only
Fix from $1,950 2025-09-03
Parking Management System HIGH 7.5
CVE-2025-9842

A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. Th…

Mitigation only
Fix from $1,950 2025-09-03
Android MEDIUM 5.5
CVE-2025-22430

In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead…

Mitigation only
Fix from $1,600 2025-09-02
Unclassified MEDIUM 5.5
CVE-2025-58061

OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, p…

Mitigation only
Fix from $1,600 2025-08-28
Unclassified CRITICAL 9.1
CVE-2025-58059

Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to before 13.1.2.RELEASE, any admi…

Patch available
Fix from $2,300 2025-08-28
Contao MEDIUM 5.3
CVE-2025-57756

Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered …

Fix: 4.13.56 / 5.3.38+
Fix from $1,600 2025-08-28
Contao MEDIUM 5.3
CVE-2025-57757

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their n…

Fix: 5.3.38 / 5.6.1+
Fix from $1,600 2025-08-28
Unclassified HIGH 7.5
CVE-2024-13807

The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.0.5 via the backup funct…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified MEDIUM 5.5
CVE-2025-20290

A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone N…

Mitigation only
Fix from $1,600 2025-08-27
Mahara CRITICAL 9.1
CVE-2024-39335

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administra…

Fix: 23.04.6 / 24.04.1+
Fix from $2,300 2025-08-26
Mahara HIGH 7.5
CVE-2025-29992

Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily…

Fix: 24.04.9+
Fix from $1,950 2025-08-26
Bbs HIGH 7.5
CVE-2025-9461

A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePacka…

Fix: after 6.8
Fix from $1,950 2025-08-26
Mahara HIGH 7.5
CVE-2023-47799

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration inter…

Fix: 22.10.4 / 23.04.4+
Fix from $1,950 2025-08-25
Unclassified CRITICAL 9.3
CVE-2025-7426

Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated…

Mitigation only
Fix from $2,300 2025-08-25
Yifang HIGH 7.5
CVE-2025-9398

A security vulnerability has been detected in YiFang CMS up to 2.0.5. Affected by this vulnerability is the function exportInstallTable of the file a…

Fix: after 2.0.5
Fix from $1,950 2025-08-25
Unclassified HIGH 8.1
CVE-2025-57755

claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resou…

Mitigation only
Fix from $1,950 2025-08-21
Scada Lts MEDIUM 6.5
CVE-2025-9139

A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plain…

No fix yet
Fix from $1,600 2025-08-19
Unclassified HIGH 8.8
CVE-2025-7654

Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated…

Mitigation only
Fix from $1,950 2025-08-19
Nameless MEDIUM 5.3
CVE-2025-54118

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allo…

Fix: 2.2.4+
Fix from $1,600 2025-08-18
Unclassified MEDIUM 5.3
CVE-2024-12575

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, a…

Mitigation only
Fix from $1,600 2025-08-16
Music Classical MEDIUM 6.2
CVE-2025-43201

This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may be able to unexpectedly leak …

Fix: 2.3+
Fix from $1,600 2025-08-15
Unclassified MEDIUM 5.7
CVE-2025-26709

There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker ca…

Mitigation only
Fix from $1,600 2025-08-15
Unclassified MEDIUM 5.9
CVE-2025-50862

The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified CRITICAL 9.8
CVE-2025-27845

In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This al…

Mitigation only
Fix from $2,300 2025-08-14
Unclassified HIGH 8.5
CVE-2025-9036

A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a Web…

Mitigation only
Fix from $1,950 2025-08-14