Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified CRITICAL 9.8
CVE-2025-32958

Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to up…

Patch available
Fix from $2,300 2025-04-21
Unclassified HIGH 7.5
CVE-2025-23174

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,950 2025-04-21
Unclassified HIGH 8.7
CVE-2025-32953

z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubuntu.yml` workflow file uses `ac…

Patch available
Fix from $1,950 2025-04-18
Unclassified HIGH 7.5
CVE-2025-28235

An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and …

Mitigation only
Fix from $1,950 2025-04-18
Unclassified MEDIUM 6.2
CVE-2025-29316

An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive informatio…

Mitigation only
Fix from $1,600 2025-04-17
Unclassified MEDIUM 5.3
CVE-2025-3104

The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 6.1.2 due to missi…

Mitigation only
Fix from $1,600 2025-04-16
Bi Publisher HIGH 7.5
CVE-2025-30724

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.6.0.0.0 a…

Patch available
Fix from $1,950 2025-04-15
Fleet Patching And Provisioning MEDIUM 5.3
CVE-2025-30702

Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.3-19.26. …

Fix: after 19.26
Fix from $1,600 2025-04-15
Cashbook MEDIUM 6.5
CVE-2025-27980

cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.

No fix yet
Fix from $1,600 2025-04-15
Autogpt Platform HIGH 8.6
CVE-2025-31491

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.1+
Fix from $1,950 2025-04-15
Unclassified MEDIUM 5.3
CVE-2025-2881

The Developer Toolbar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.3 through the pu…

Mitigation only
Fix from $1,600 2025-04-12
Unclassified MEDIUM 5.3
CVE-2025-2841

The Cart66 Cloud plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.7 through the publicl…

Mitigation only
Fix from $1,600 2025-04-12
Unclassified MEDIUM 6.9
CVE-2025-32080

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Mobile Frontend Extension allows Sha…

Mitigation only
Fix from $1,600 2025-04-11
Unclassified HIGH 7.7
CVE-2024-52280

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowe…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified MEDIUM 5.3
CVE-2025-23387

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authenticati…

Mitigation only
Fix from $1,600 2025-04-11
Unclassified MEDIUM 6.2
CVE-2024-52282

A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager…

Mitigation only
Fix from $1,600 2025-04-11
Unclassified MEDIUM 6.0
CVE-2025-32395

Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be return…

Patch available
Fix from $1,600 2025-04-10
Junos MEDIUM 5.5
CVE-2025-30654

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evol…

Fix: 21.4+
Fix from $1,600 2025-04-09
Coldfusion MEDIUM 5.5
CVE-2025-30291

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security featur…

Mitigation only
Fix from $1,600 2025-04-08
Outlook HIGH 7.5
CVE-2025-29805

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a netw…

Fix: 4.2509.0+
Fix from $1,950 2025-04-08
Windows 10 1607 MEDIUM 5.5
CVE-2025-27736

Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose informat…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,600 2025-04-08
Windows Server 2008 MEDIUM 6.5
CVE-2025-26667

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,600 2025-04-08
Unclassified MEDIUM 5.3
CVE-2025-2883

The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl…

Mitigation only
Fix from $1,600 2025-04-08
Unclassified MEDIUM 5.3
CVE-2025-2882

The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between 3.0.0 and 3.0.9 through the …

Mitigation only
Fix from $1,600 2025-04-08
Unclassified MEDIUM 5.3
CVE-2024-13820

The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.15.11 via the 'run' fun…

Mitigation only
Fix from $1,600 2025-04-08
Csr8811 Firmware MEDIUM 5.5
CVE-2024-43046

There may be information disclosure during memory re-allocation in TZ Secure OS.

No fix yet
Fix from $1,600 2025-04-07
Unclassified HIGH 8.2
CVE-2025-31492

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Rel…

Patch available
Fix from $1,950 2025-04-06
Unclassified HIGH 7.5
CVE-2024-13604

The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposur…

Mitigation only
Fix from $1,950 2025-04-05
Unclassified MEDIUM 5.3
CVE-2025-31486EPSS 41%

Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init…

Patch available
Fix from $1,600 2025-04-03
Unclassified MEDIUM 5.3
CVE-2025-31127

Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25.03.3, the entity in control …

Mitigation only
Fix from $1,600 2025-04-03