Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Recipes MEDIUM 6.5
CVE-2025-23212

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to …

Fix: 1.5.28+
Fix from $1,600 2025-01-28
Unclassified HIGH 7.0
CVE-2025-0659

A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in …

Mitigation only
Fix from $1,950 2025-01-28
macOS HIGH 7.7
CVE-2025-24174

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be abl…

Fix: 13.7.3 / 14.7.3+
Fix from $1,950 2025-01-27
macOS CRITICAL 9.8
CVE-2025-24146

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Vent…

Fix: 13.7.3 / 14.7.3+
Fix from $2,300 2025-01-27
macOS MEDIUM 5.5
CVE-2025-24134

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3. An app may be able to access…

Fix: 15.3+
Fix from $1,600 2025-01-27
macOS MEDIUM 5.5
CVE-2025-24138

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A m…

Fix: 13.7.3 / 14.7.3+
Fix from $1,600 2025-01-27
macOS MEDIUM 5.5
CVE-2025-24109

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Vent…

Fix: 13.7.3 / 14.7.3+
Fix from $1,600 2025-01-27
Ipados CRITICAL 9.8
CVE-2025-24102

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An…

Fix: 13.7.3 / 14.7.3+
Fix from $2,300 2025-01-27
macOS MEDIUM 5.5
CVE-2024-54547

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be abl…

Fix: 13.7.2 / 14.7.2+
Fix from $1,600 2025-01-27
Restrict Content HIGH 7.5
CVE-2024-11090

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3…

Fix: 3.2.14+
Fix from $1,950 2025-01-26
Import Wp HIGH 7.5
CVE-2024-13562

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions…

Fix: 2.14.6+
Fix from $1,950 2025-01-25
Unclassified MEDIUM 5.3
CVE-2025-24360

Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt allows any websites to send …

Patch available
Fix from $1,600 2025-01-25
Coolify CRITICAL 10.0
CVE-2025-22612

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing auth…

Fix: 4.0.0+
Fix from $2,300 2025-01-24
Coolify MEDIUM 5.5
CVE-2025-22607

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth…

Fix: 4.0.0+
Fix from $1,600 2025-01-24
Unclassified CRITICAL 9.0
CVE-2024-52975

An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The n…

Mitigation only
Fix from $2,300 2025-01-23
Kibana MEDIUM 6.5
CVE-2024-43707

An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The …

Fix: 8.15.0+
Fix from $1,600 2025-01-23
Cilium MEDIUM 6.5
CVE-2025-23047

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header v…

Fix: 1.14.19 / 1.15.13+
Fix from $1,600 2025-01-22
Android MEDIUM 5.5
CVE-2024-49733

In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in the code. Th…

Mitigation only
Fix from $1,600 2025-01-21
Android HIGH 7.5
CVE-2024-49734

In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a …

Mitigation only
Fix from $1,950 2025-01-21
Android MEDIUM 5.5
CVE-2023-40108

In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead t…

Mitigation only
Fix from $1,600 2025-01-21
Umbraco Cms MEDIUM 5.3
CVE-2025-24011

Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible t…

Fix: 14.3.2 / 15.1.2+
Fix from $1,600 2025-01-21
Ultimate Member MEDIUM 5.3
CVE-2025-0318

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Fix: 2.9.2+
Fix from $1,600 2025-01-18
Android MEDIUM 5.5
CVE-2018-9379

In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could le…

Patch available
Fix from $1,600 2025-01-17
Unclassified HIGH 8.6
CVE-2024-12142

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure of restricted web pa…

No fix yet
Fix from $1,950 2025-01-17
Unclassified MEDIUM 5.3
CVE-2024-12637

The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.05 via the export funct…

Mitigation only
Fix from $1,600 2025-01-17
Zulip Server MEDIUM 5.3
CVE-2024-56136

Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an informat…

Fix: 9.4+
Fix from $1,600 2025-01-16
Pmb HIGH 7.5
CVE-2025-0472

Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environ…

Fix: after 4.2.13
Fix from $1,950 2025-01-16
Unclassified HIGH 7.5
CVE-2024-48125

An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via crafted GIOP protocol requests.

Mitigation only
Fix from $1,950 2025-01-15
Dir 878 Firmware HIGH 7.5
CVE-2025-0481

A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the compon…

Mitigation only
Fix from $1,950 2025-01-15
Chrome MEDIUM 6.5
CVE-2025-0441

Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive infor…

Fix: 132.0.6834.83+
Fix from $1,600 2025-01-15