Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
macOS MEDIUM 5.5
CVE-2025-24142

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, m…

Fix: 13.7.6 / 14.7.6+
Fix from $1,600 2025-05-12
Ipados MEDIUM 5.5
CVE-2025-24144

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS …

Fix: 2.3 / 11.3+
Fix from $1,600 2025-05-12
macOS MEDIUM 5.5
CVE-2025-24155

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app m…

Fix: 13.7.6 / 14.7.6+
Fix from $1,600 2025-05-12
Ipados MEDIUM 5.5
CVE-2025-24220

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may be able to…

Fix: 18.4+
Fix from $1,600 2025-05-12
Group Audio Visual Integrated Management MEDIUM 5.3
CVE-2025-4536

A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classified as critical. Affected by th…

No fix yet
Fix from $1,600 2025-05-11
Group Audio Visual Integrated Management MEDIUM 5.3
CVE-2025-4535

A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0. Affected…

No fix yet
Fix from $1,600 2025-05-11
Ngc Explorer MEDIUM 5.5
CVE-2025-4526

A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page…

Mitigation only
Fix from $1,600 2025-05-11
Ios Xe CRITICAL 9.1
CVE-2025-20221

A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 an…

Mitigation only
Fix from $2,300 2025-05-07
Unclassified MEDIUM 5.3
CVE-2025-47418

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible in…

Mitigation only
Fix from $1,600 2025-05-06
Unclassified MEDIUM 5.1
CVE-2025-47417

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. When Enable Debug Im…

Mitigation only
Fix from $1,600 2025-05-06
Unclassified HIGH 7.1
CVE-2025-46820

phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.y…

Patch available
Fix from $1,950 2025-05-06
Harmonyos MEDIUM 5.5
CVE-2024-58252

Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect ser…

No fix yet
Fix from $1,600 2025-05-06
Discourse HIGH 7.5
CVE-2025-46813

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d113…

Fix: 3.5.0+
Fix from $1,950 2025-05-05
A720r Firmware HIGH 7.5
CVE-2025-4270EPSS 13%

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/…

No fix yet
Fix from $1,950 2025-05-05
A720r Firmware MEDIUM 5.3
CVE-2025-4271

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functional…

No fix yet
Fix from $1,600 2025-05-05
Unclassified MEDIUM 5.9
CVE-2025-4222

The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup file…

Mitigation only
Fix from $1,600 2025-05-03
Unclassified MEDIUM 6.5
CVE-2025-46332

Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 and prior and @vercel/flags f…

Mitigation only
Fix from $1,600 2025-05-02
Unclassified MEDIUM 5.3
CVE-2025-2880

The Yame | Link In Bio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.9.0 through the p…

Mitigation only
Fix from $1,600 2025-05-02
Unclassified MEDIUM 5.7
CVE-2024-11994

APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this co…

Mitigation only
Fix from $1,600 2025-05-01
Elastic Agent HIGH 7.1
CVE-2023-46669

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and…

Fix: 8.15.0+
Fix from $1,950 2025-05-01
Unclassified MEDIUM 6.3
CVE-2025-46552

KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some comm…

Patch available
Fix from $1,600 2025-04-29
Ipados MEDIUM 5.7
CVE-2025-24270

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS S…

Fix: 2.4 / 13.7.5+
Fix from $1,600 2025-04-29
Lecms HIGH 7.5
CVE-2025-3978

A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file…

No fix yet
Fix from $1,950 2025-04-27
Ecommerce Website In Php MEDIUM 5.3
CVE-2025-3975

A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of…

No fix yet
Fix from $1,600 2025-04-27
Paicoding MEDIUM 5.3
CVE-2025-3966

A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file…

No fix yet
Fix from $1,600 2025-04-27
Ngeniusone HIGH 7.5
CVE-2025-32983

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

Fix: 6.4.0+
Fix from $1,950 2025-04-25
Ngeniusone HIGH 7.5
CVE-2025-32986

NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.

Fix: 6.4.0+
Fix from $1,950 2025-04-25
Moodle HIGH 7.5
CVE-2025-32044

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact infor…

Fix: 4.5.3+
Fix from $1,950 2025-04-25
Unclassified MEDIUM 5.3
CVE-2025-3923

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i…

Mitigation only
Fix from $1,600 2025-04-25
Memberpress HIGH 7.5
CVE-2024-11299

The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.37 via the WordPress …

Fix: after 1.11.37
Fix from $1,950 2025-04-22