Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Directus MEDIUM 5.3
CVE-2025-53887

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Dir…

Fix: 11.9.0+
Fix from $1,600 2025-07-15
Indico MEDIUM 6.5
CVE-2025-53640

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to…

Fix: 3.3.7+
Fix from $1,600 2025-07-14
Autopass License Server HIGH 7.5
CVE-2024-51769

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Fix: 9.17+
Fix from $1,950 2025-07-14
Unclassified MEDIUM 5.3
CVE-2025-7573

A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000…

No fix yet
Fix from $1,600 2025-07-14
Unclassified MEDIUM 5.3
CVE-2025-7572

A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. …

No fix yet
Fix from $1,600 2025-07-14
Bl Ac3600 Firmware HIGH 7.5
CVE-2025-7565

A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi…

Fix: after 1.0.22
Fix from $1,950 2025-07-14
Total Upkeep HIGH 7.5
CVE-2020-36848

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in…

Fix: 1.14.10+
Fix from $1,950 2025-07-12
Unclassified MEDIUM 5.3
CVE-2025-6745

The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_que…

Mitigation only
Fix from $1,600 2025-07-11
Unclassified MEDIUM 6.5
CVE-2025-4593

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6…

Mitigation only
Fix from $1,600 2025-07-11
Unclassified HIGH 7.1
CVE-2025-34098

A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper input validation in the log …

No fix yet
Fix from $1,950 2025-07-10
Liboqs MEDIUM 5.5
CVE-2025-52473

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branche…

Fix: 0.14.0+
Fix from $1,600 2025-07-10
Unclassified CRITICAL 10.0
CVE-2025-53624

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists ve…

Patch available
Fix from $2,300 2025-07-09
Juju MEDIUM 6.5
CVE-2025-53512

The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contai…

Fix: 2.9.52 / 3.6.8+
Fix from $1,600 2025-07-08
Windows Server 2008 MEDIUM 6.5
CVE-2025-49671

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis…

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,600 2025-07-08
Windows 10 1507 MEDIUM 5.5
CVE-2025-49664

Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose infor…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,600 2025-07-08
Windows 10 1507 MEDIUM 5.5
CVE-2025-48808

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,600 2025-07-08
Windows 10 1507 MEDIUM 6.2
CVE-2025-47980

Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information local…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,600 2025-07-08
Splunk MEDIUM 5.3
CVE-2025-20325

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.113, and 9.2.240…

Fix: 9.1.10 / 9.2.7+
Fix from $1,600 2025-07-07
Unclassified CRITICAL 9.3
CVE-2025-34072

A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI…

Mitigation only
Fix from $2,300 2025-07-02
Bit Form HIGH 7.5
CVE-2024-13451

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is v…

Fix: 2.17.6+
Fix from $1,950 2025-07-02
Edge Chromium HIGH 7.5
CVE-2025-49741

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Fix: 135.0.3179.98+
Fix from $1,950 2025-07-01
Unclassified CRITICAL 9.0
CVE-2025-34064

A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-productio…

Mitigation only
Fix from $2,300 2025-07-01
Unclassified HIGH 8.7
CVE-2025-34059

An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/…

Mitigation only
Fix from $1,950 2025-07-01
Unclassified MEDIUM 5.7
CVE-2025-34062

An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attack…

Mitigation only
Fix from $1,600 2025-07-01
Unclassified MEDIUM 6.9
CVE-2025-34051

A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?ac…

No fix yet
Fix from $1,600 2025-07-01
Unclassified HIGH 8.2
CVE-2025-53003

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without s…

Patch available
Fix from $1,950 2025-07-01
Frappe HIGH 8.8
CVE-2025-52898

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor …

Fix: 14.94.3 / 15.58.0+
Fix from $1,950 2025-06-30
Discourse HIGH 7.5
CVE-2025-49845

Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers_allowed_groups` site setting…

Fix: 3.4.6+
Fix from $1,950 2025-06-25
Unclassified HIGH 7.1
CVE-2025-27827

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to conduct a…

Mitigation only
Fix from $1,950 2025-06-24
Firefox HIGH 8.6
CVE-2025-6432

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not…

Fix: 140.0+
Fix from $1,950 2025-06-24