Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Microscada X Sys600 MEDIUM 6.5
CVE-2025-39204

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returni…

Fix: 10.7+
Fix from $1,600 2025-06-24
Terminal Handler CRITICAL 9.8
CVE-2023-47029

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST reque…

Mitigation only
Fix from $2,300 2025-06-23
Unclassified HIGH 7.4
CVE-2025-27387

OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.

Mitigation only
Fix from $1,950 2025-06-23
Dotnetnuke HIGH 8.6
CVE-2025-52488EPSS 33%

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN…

Fix: 10.0.1+
Fix from $1,950 2025-06-21
Unclassified CRITICAL 9.3
CVE-2025-25037

An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp…

No fix yet
Fix from $2,300 2025-06-20
Unclassified CRITICAL 9.1
CVE-2025-52467

pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to commit 8eb3567, the pgai repos…

Patch available
Fix from $2,300 2025-06-19
Unclassified HIGH 7.5
CVE-2025-23173

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the …

Mitigation only
Fix from $1,950 2025-06-19
Unclassified MEDIUM 6.8
CVE-2025-49593

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Patch available
Fix from $1,600 2025-06-17
Unclassified MEDIUM 6.1
CVE-2025-49177

A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read u…

Mitigation only
Fix from $1,600 2025-06-17
Field Analytics HIGH 7.5
CVE-2025-49200

The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the …

Mitigation only
Fix from $1,950 2025-06-12
Baggage Analytics HIGH 7.5
CVE-2025-49184

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the pro…

Mitigation only
Fix from $1,950 2025-06-12
Unclassified MEDIUM 5.9
CVE-2025-49150

Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enable was set to True. This mean…

Mitigation only
Fix from $1,600 2025-06-11
Cloudstack HIGH 8.1
CVE-2025-26521

When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Acrobat Dc MEDIUM 5.5
CVE-2025-43579

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result …

Fix: 20.005.30774 / 24.001.30254+
Fix from $1,600 2025-06-10
Nautobot MEDIUM 5.9
CVE-2025-49143

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROO…

Fix: 1.6.32 / 2.4.10+
Fix from $1,600 2025-06-10
Geoserver HIGH 8.2
CVE-2024-34711

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables …

Fix: 2.25.0+
Fix from $1,950 2025-06-10
Geoserver HIGH 7.5
CVE-2024-38524

GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpSer…

Fix: 2.25.6 / 2.26.2+
Fix from $1,950 2025-06-10
Dm Corporative Cms HIGH 7.5
CVE-2025-40662

Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigati…

Fix: 2025.01+
Fix from $1,950 2025-06-10
Unclassified HIGH 8.0
CVE-2025-49653

Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.

Mitigation only
Fix from $1,950 2025-06-09
Unclassified MEDIUM 5.7
CVE-2025-25209

The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the k…

Mitigation only
Fix from $1,600 2025-06-09
Power Automate For Desktop CRITICAL 9.8
CVE-2025-47966

Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-06-05
Unclassified MEDIUM 6.5
CVE-2025-5690

PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the ori…

Mitigation only
Fix from $1,600 2025-06-04
Socialminer MEDIUM 5.4
CVE-2025-20129

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenti…

Mitigation only
Fix from $1,600 2025-06-04
Unclassified MEDIUM 5.3
CVE-2025-5436

A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic. This issue affects some unknown processing of the file…

Mitigation only
Fix from $1,600 2025-06-02
Unclassified MEDIUM 5.3
CVE-2025-4659

The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclo…

No fix yet
Fix from $1,600 2025-05-30
macOS MEDIUM 5.5
CVE-2025-31231

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitive locat…

Fix: 15.4+
Fix from $1,600 2025-05-29
Remote Desktop Manager HIGH 7.5
CVE-2025-5334

Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authen…

Fix: 2025.1.37.0 / 2025.2.0.0+
Fix from $1,950 2025-05-29
Chrome MEDIUM 5.4
CVE-2025-5281

Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via …

Fix: 137.0.7151.55+
Fix from $1,600 2025-05-27
Chrome MEDIUM 5.4
CVE-2025-5064

Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via …

Fix: 137.0.7151.55+
Fix from $1,600 2025-05-27
Android MEDIUM 5.1
CVE-2024-56193

There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no addi…

Mitigation only
Fix from $1,600 2025-05-27