Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Academia Student Information System HIGH 7.5
CVE-2025-25951

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information Syste…

Mitigation only
Fix from $1,950 2025-03-03
Better Messages HIGH 7.5
CVE-2024-13611

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Informa…

Fix: 2.7.0+
Fix from $1,950 2025-03-01
Unclassified HIGH 7.2
CVE-2024-13911

The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio…

Mitigation only
Fix from $1,950 2025-03-01
Fluent Support HIGH 7.5
CVE-2024-13568

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u…

Fix: 1.8.6+
Fix from $1,950 2025-03-01
Unclassified MEDIUM 5.1
CVE-2025-26263

GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to imp…

Mitigation only
Fix from $1,600 2025-02-28
Order Attachments For Woocommerce HIGH 7.5
CVE-2024-13638

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.…

Fix: after 2.5.1
Fix from $1,950 2025-02-28
Post Grid HIGH 7.5
CVE-2024-13796

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl…

Fix: 2.3.7+
Fix from $1,950 2025-02-28
Unclassified HIGH 7.5
CVE-2025-25729

An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attacker…

Mitigation only
Fix from $1,950 2025-02-28
Xiq Se MEDIUM 5.3
CVE-2024-38290

In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.

Fix: 24.2.11+
Fix from $1,600 2025-02-27
Mastodon MEDIUM 5.3
CVE-2025-27399

Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/re…

Fix: 4.1.23 / 4.2.16+
Fix from $1,600 2025-02-27
Unclassified HIGH 7.5
CVE-2025-25333

An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.

No fix yet
Fix from $1,950 2025-02-27
Unclassified MEDIUM 5.3
CVE-2024-12434

The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. T…

Mitigation only
Fix from $1,600 2025-02-26
Glpi MEDIUM 6.5
CVE-2025-25192

GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive i…

Fix: 10.0.18+
Fix from $1,600 2025-02-25
Glpi MEDIUM 6.5
CVE-2025-21626

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive…

Fix: 10.0.18+
Fix from $1,600 2025-02-25
Classified Listing MEDIUM 5.3
CVE-2025-1063

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi…

Fix: 4.0.5+
Fix from $1,600 2025-02-25
Best Employee Management System HIGH 7.5
CVE-2025-1606

A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of…

No fix yet
Fix from $1,950 2025-02-24
Unclassified MEDIUM 5.3
CVE-2025-1595

A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects un…

No fix yet
Fix from $1,600 2025-02-23
Qibocms X1 HIGH 7.5
CVE-2025-22973

An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. …

Mitigation only
Fix from $1,950 2025-02-20
Nagios Xi MEDIUM 6.5
CVE-2024-54961

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the username…

Mitigation only
Fix from $1,600 2025-02-20
Libming MEDIUM 6.5
CVE-2025-26309

A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to caus…

No fix yet
Fix from $1,600 2025-02-20
Libming MEDIUM 6.5
CVE-2025-26310

Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming …

No fix yet
Fix from $1,600 2025-02-20
Unclassified HIGH 7.5
CVE-2024-57716

An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.

Mitigation only
Fix from $1,950 2025-02-20
Bento4 MEDIUM 6.5
CVE-2025-25942

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specific…

No fix yet
Fix from $1,600 2025-02-19
Bento4 MEDIUM 6.5
CVE-2025-25945

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDesc…

No fix yet
Fix from $1,600 2025-02-19
Bento4 MEDIUM 5.5
CVE-2025-25946

An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncrypt…

No fix yet
Fix from $1,600 2025-02-19
Unclassified MEDIUM 6.1
CVE-2020-13481

Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information.

Mitigation only
Fix from $1,600 2025-02-19
Ffmpeg MEDIUM 6.5
CVE-2025-25468

FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.

Fix: 2025-01-13+
Fix from $1,600 2025-02-18
Unclassified HIGH 8.3
CVE-2025-26604

Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Beca…

Patch available
Fix from $1,950 2025-02-18
1 Click Migration MEDIUM 5.9
CVE-2024-13609

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver…

Fix: after 2.1
Fix from $1,600 2025-02-18
File Uploads Addon For Woocommerce HIGH 7.5
CVE-2024-13622

The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7…

Fix: after 1.7.1
Fix from $1,950 2025-02-18