Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
macOS CRITICAL 9.8
CVE-2025-24246

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An a…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS CRITICAL 9.8
CVE-2025-24232

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A m…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
Ipados MEDIUM 5.5
CVE-2025-24217

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS …

Fix: 15.4 / 18.4+
Fix from $1,600 2025-03-31
Xcode MEDIUM 5.5
CVE-2025-24226

The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.

Fix: 16.3+
Fix from $1,600 2025-03-31
macOS CRITICAL 9.8
CVE-2025-24204

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

Fix: 15.4+
Fix from $2,300 2025-03-31
macOS MEDIUM 5.5
CVE-2025-24164

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be…

Fix: 13.7.5 / 14.7.5+
Fix from $1,600 2025-03-31
Zitadel MEDIUM 5.3
CVE-2025-31124

Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps …

Fix: 2.63.9 / 2.64.6+
Fix from $1,600 2025-03-31
Vite HIGH 7.5
CVE-2025-31125 KEVEPSS 59%

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explici…

Fix: 4.5.11 / 5.4.16+
Fix from $1,950 2025-03-31
Unclassified MEDIUM 5.3
CVE-2025-2840

The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.…

Mitigation only
Fix from $1,600 2025-03-29
Satech Bcu Firmware MEDIUM 5.3
CVE-2025-2860

SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials that users have within the web…

Mitigation only
Fix from $1,600 2025-03-28
Fortimail MEDIUM 5.3
CVE-2021-24008

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and b…

Fix: 5.4.3 / 6.0.4+
Fix from $1,600 2025-03-28
Unclassified MEDIUM 5.3
CVE-2025-2578

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and…

Mitigation only
Fix from $1,600 2025-03-28
Libming MEDIUM 6.5
CVE-2025-29497

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.

No fix yet
Fix from $1,600 2025-03-27
Libming MEDIUM 6.5
CVE-2025-29488

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.

No fix yet
Fix from $1,600 2025-03-27
Libming MEDIUM 6.5
CVE-2025-29489

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.

No fix yet
Fix from $1,600 2025-03-27
Libming MEDIUM 6.5
CVE-2025-29486

libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.

No fix yet
Fix from $1,600 2025-03-27
Splunk MEDIUM 5.7
CVE-2025-20232

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.23…

Fix: 9.1.8 / 9.1.2308.212+
Fix from $1,600 2025-03-26
Splunk MEDIUM 5.7
CVE-2025-20226

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.111, and 9.1.2308.…

Fix: 9.1.8 / 9.1.2308.214+
Fix from $1,600 2025-03-26
Tlr 2005ksh Firmware HIGH 7.5
CVE-2025-26009

Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.

Mitigation only
Fix from $1,950 2025-03-26
Tlr 2005ksh Firmware HIGH 7.5
CVE-2025-26001

Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.

Mitigation only
Fix from $1,950 2025-03-26
Directus MEDIUM 5.3
CVE-2025-30352

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `…

Fix: 11.5.0+
Fix from $1,600 2025-03-26
Directus HIGH 7.5
CVE-2025-30353

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow …

Fix: 11.5.0+
Fix from $1,950 2025-03-26
Unclassified MEDIUM 5.5
CVE-2025-23203

Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4…

Patch available
Fix from $1,600 2025-03-26
Responsive Addons For Elementor MEDIUM 5.7
CVE-2025-2228

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Sensitive Informatio…

Fix: 1.6.9+
Fix from $1,600 2025-03-26
Frappe HIGH 7.5
CVE-2025-30214

Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure…

Fix: 14.89.0 / 15.51.0+
Fix from $1,950 2025-03-25
Easy Digital Downloads MEDIUM 5.3
CVE-2025-2252

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in a…

Fix: 3.3.7+
Fix from $1,600 2025-03-25
Vite HIGH 7.5
CVE-2025-30208EPSS 75%

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies acc…

Fix: 4.5.10 / 5.4.15+
Fix from $1,950 2025-03-24
Commons Vfs MEDIUM 5.0
CVE-2025-30474

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when …

Fix: 2.10.0+
Fix from $1,600 2025-03-23
Givewp MEDIUM 6.5
CVE-2025-2331

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and…

Fix: 3.22.2+
Fix from $1,600 2025-03-22
Applio HIGH 7.5
CVE-2025-27784

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This is…

Fix: after 3.2.8-bugfix
Fix from $1,950 2025-03-19