Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Idonate MEDIUM 6.5
CVE-2025-4523

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Fix: 2.1.10+
Fix from $1,600 2025-08-01
Gitproxy MEDIUM 6.5
CVE-2025-54586

GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commi…

Fix: 1.19.2+
Fix from $1,600 2025-07-30
Ptc310uv2 Firmware HIGH 8.1
CVE-2025-45620

An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request

No fix yet
Fix from $1,950 2025-07-30
W1a75a Firmware MEDIUM 5.3
CVE-2025-43018

Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book.

Fix: 002.2508a+
Fix from $1,600 2025-07-30
Umbraco Cms MEDIUM 5.3
CVE-2025-54425

Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the content delivery API can be restri…

Fix: 13.9.3 / 15.4.4+
Fix from $1,600 2025-07-30
Unclassified MEDIUM 6.0
CVE-2025-4426

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" w…

No fix yet
Fix from $1,600 2025-07-30
macOS MEDIUM 5.5
CVE-2025-43246

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to access sensitive…

Fix: 14.7.7 / 15.6+
Fix from $1,600 2025-07-30
macOS MEDIUM 5.5
CVE-2025-43215

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may result in disclos…

Fix: 15.6+
Fix from $1,600 2025-07-30
Ipados CRITICAL 9.8
CVE-2025-31279

A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS …

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43189

This issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able t…

Fix: 14.7.7 / 15.6+
Fix from $2,300 2025-07-30
Memos CRITICAL 9.8
CVE-2025-50738

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing su…

Fix: after 0.24.3
Fix from $2,300 2025-07-29
Chancms CRITICAL 9.8
CVE-2025-8226

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sy…

Fix: 3.1.3+
Fix from $2,300 2025-07-27
Opencast MEDIUM 6.5
CVE-2025-54380

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would inco…

Fix: 17.6+
Fix from $1,600 2025-07-26
Unclassified CRITICAL 9.4
CVE-2025-29628

A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobil…

Mitigation only
Fix from $2,300 2025-07-25
Unclassified CRITICAL 9.1
CVE-2025-29629

Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default crede…

Mitigation only
Fix from $2,300 2025-07-25
W3z72e Firmware MEDIUM 6.5
CVE-2025-3508

Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensi…

Mitigation only
Fix from $1,600 2025-07-25
Unclassified HIGH 8.7
CVE-2020-36850

An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one u…

Mitigation only
Fix from $1,950 2025-07-25
Dryice Iautomate MEDIUM 6.5
CVE-2025-31955

HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the s…

No fix yet
Fix from $1,600 2025-07-24
Unclassified MEDIUM 6.5
CVE-2025-7780

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeA…

Mitigation only
Fix from $1,600 2025-07-24
Firefox HIGH 8.1
CVE-2025-8039

In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Fir…

Fix: 140.1 / 141.0+
Fix from $1,950 2025-07-22
Unclassified MEDIUM 5.3
CVE-2025-6082

The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to in…

Mitigation only
Fix from $1,600 2025-07-22
Hmailserver MEDIUM 5.1
CVE-2025-52372

An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss…

No fix yet
Fix from $1,600 2025-07-21
Unclassified MEDIUM 6.5
CVE-2025-7919

WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitra…

Mitigation only
Fix from $1,600 2025-07-21
Unclassified MEDIUM 5.3
CVE-2025-46382

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,600 2025-07-20
Metacrm CRITICAL 9.1
CVE-2025-7874

A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown function…

Fix: after 6.4.2
Fix from $2,300 2025-07-20
Wolfssl CRITICAL 9.8
CVE-2025-7394

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable…

Fix: after 5.8.0
Fix from $2,300 2025-07-18
Unclassified HIGH 7.5
CVE-2025-50708

An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL

Mitigation only
Fix from $1,950 2025-07-18
Unclassified HIGH 8.7
CVE-2025-34130

An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified MEDIUM 6.1
CVE-2025-22227

In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must hav…

Mitigation only
Fix from $1,600 2025-07-16
Siebel Crm Deployment MEDIUM 5.3
CVE-2025-30758

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface). Supported versions that are affected are 25.0-25.…

Fix: after 25.5
Fix from $1,600 2025-07-15