Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Customer Email Verification For Woocommerce MEDIUM 6.5
CVE-2024-13525

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu…

Fix: 2.9.5+
Fix from $1,600 2025-02-15
Return Refund And Exchange For Woocommerce HIGH 7.5
CVE-2024-13641

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vul…

Fix: 4.4.6+
Fix from $1,950 2025-02-14
Unclassified HIGH 8.0
CVE-2025-22961

A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorr…

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 8.0
CVE-2025-22960

A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers …

Mitigation only
Fix from $1,950 2025-02-13
Mojave Inverter Oghi8048a Firmware HIGH 7.5
CVE-2025-25281

An attacker may modify the URL to discover sensitive information about the target network.

No fix yet
Fix from $1,950 2025-02-13
Js Help Desk HIGH 7.5
CVE-2024-13606

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to…

Fix: 2.8.9+
Fix from $1,950 2025-02-13
Unclassified HIGH 7.5
CVE-2024-51123

An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensitive information via the /com…

Mitigation only
Fix from $1,950 2025-02-12
Majestic Support HIGH 7.5
CVE-2024-13600

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in a…

Fix: 1.0.6+
Fix from $1,950 2025-02-12
Unclassified MEDIUM 5.3
CVE-2024-44336

An issue in AnkiDroid Android Application v2.17.6 allows attackers to retrieve internal files from the /data/data/com.ichi2.anki/ directory and save …

Mitigation only
Fix from $1,600 2025-02-11
Geonetwork MEDIUM 5.3
CVE-2024-32037

GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response he…

Fix: 4.2.10 / 4.4.5+
Fix from $1,600 2025-02-11
Commerce MEDIUM 6.5
CVE-2025-24408

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that …

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2025-02-11
Octopus Server HIGH 7.5
CVE-2025-0525

In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide a…

Fix: 2024.3.13007 / 2024.4.6995+
Fix from $1,950 2025-02-11
W18e Firmware MEDIUM 6.5
CVE-2024-46437

A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker t…

No fix yet
Fix from $1,600 2025-02-10
Rt Thread MEDIUM 5.5
CVE-2025-1115

A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the function sys_device_close/sys_dev…

Fix: after 5.1.0
Fix from $1,600 2025-02-08
Unclassified HIGH 7.5
CVE-2024-55272

An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.

No fix yet
Fix from $1,950 2025-02-07
Clearml Enterprise Server MEDIUM 6.5
CVE-2024-43779

An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP requ…

No fix yet
Fix from $1,600 2025-02-06
Unclassified MEDIUM 5.3
CVE-2024-13829

The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Sensitive Information Expos…

Mitigation only
Fix from $1,600 2025-02-05
Woocommerce Pdf Invoices\& Packing Slips MEDIUM 6.5
CVE-2025-24373

woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for Woo…

Fix: 4.0.0+
Fix from $1,600 2025-02-04
Unclassified HIGH 7.5
CVE-2025-22918

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions,…

Mitigation only
Fix from $1,950 2025-02-03
Rengine HIGH 7.5
CVE-2025-24899

reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with an…

Fix: 2.2.0+
Fix from $1,950 2025-02-03
Unclassified HIGH 7.5
CVE-2024-56902EPSS 23%

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information…

Mitigation only
Fix from $1,950 2025-02-03
Unclassified HIGH 7.5
CVE-2024-34897

Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

Mitigation only
Fix from $1,950 2025-02-03
Unclassified CRITICAL 9.3
CVE-2025-23215

PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar publish…

Patch available
Fix from $2,300 2025-01-31
Unclassified MEDIUM 5.9
CVE-2024-13623

The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via …

Mitigation only
Fix from $1,600 2025-01-31
Ilx F509 Firmware MEDIUM 5.3
CVE-2024-23962

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not…

Mitigation only
Fix from $1,600 2025-01-31
Unclassified HIGH 7.7
CVE-2025-24886

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on use…

Mitigation only
Fix from $1,950 2025-01-30
Argo Cd MEDIUM 6.8
CVE-2025-23216

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in err…

Fix: 2.11.13 / 2.12.10+
Fix from $1,600 2025-01-30
Website Builder MEDIUM 6.5
CVE-2024-8494

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 …

Fix: 3.25.11+
Fix from $1,600 2025-01-30
Unclassified MEDIUM 5.1
CVE-2025-24884

kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used fo…

Patch available
Fix from $1,600 2025-01-29
Unclassified HIGH 7.5
CVE-2024-48310

AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers may use these keys to access …

Mitigation only
Fix from $1,950 2025-01-28