Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
CRITICAL 9.0 CVE-2025-59469 This vulnerability allows a Backup or Tape Operator to write files as root. Veeam Backup \& Replication 13.0.1.1071+ Fix from $2,3002026-01-08 MEDIUM 5.3 CVE-2026-21880 Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP aut… Kanboard 1.2.49+ Fix from $1,6002026-01-08 MEDIUM 5.3 CVE-2026-20027 Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to… Mitigation only Fix from $1,6002026-01-07 MEDIUM 5.5 CVE-2025-47369 Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. Ar8035 Firmware Patch available Fix from $1,6002026-01-07 HIGH 8.6 CVE-2025-13371 The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.9. This is due to the … Mitigation only Fix from $1,9502026-01-07 MEDIUM 5.3 CVE-2025-13215 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.… Mitigation only Fix from $1,6002026-01-06 MEDIUM 5.3 CVE-2025-69226 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existen… Aiohttp 3.13.3+ Fix from $1,6002026-01-05 MEDIUM 6.5 CVE-2025-68436 Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Cr… Craft Cms 4.16.17 / 5.8.21+ Fix from $1,6002026-01-05 MEDIUM 6.5 CVE-2025-67732 Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-admin… Dify 1.11.0+ Fix from $1,6002026-01-05 MEDIUM 5.3 CVE-2025-68273 Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions pri… Signal K Server 2.19.0+ Fix from $1,6002026-01-01 HIGH 7.5 CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earl… Uri 0.12.5 / 0.13.3+ Fix from $1,9502025-12-30 CRITICAL 9.8 CVE-2025-15103 DVP-12SE11T - Authentication Bypass via Partial Password Disclosure Dvp 12se11t Firmware 2.16+ Fix from $2,3002025-12-30 MEDIUM 5.3 CVE-2025-14280 The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.1.5 through publicly … Mitigation only Fix from $1,6002025-12-29 MEDIUM 6.5 CVE-2025-15070 Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse. Thi… Web Fax 4.0+ Fix from $1,6002025-12-29 MEDIUM 6.3 CVE-2025-15065 Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties… Mitigation only Fix from $1,6002025-12-29 MEDIUM 5.5 CVE-2024-29720 An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the S… Sciter No fix yet Fix from $1,6002025-12-26 HIGH 7.5 CVE-2025-15082 A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Managemen… Zlt M30s Firmware after 1.47 Fix from $1,9502025-12-25 HIGH 7.5 CVE-2025-12491 Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio… Mitigation only Fix from $1,9502025-12-23 HIGH 7.5 CVE-2025-63662 Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive informatio… Gt Edge Ai 2.0.12+ Fix from $1,9502025-12-22 MEDIUM 6.5 CVE-2025-15033 A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configurat… Mitigation only Fix from $1,6002025-12-22 MEDIUM 6.5 CVE-2025-8305 An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being prin… Mitigation only Fix from $1,6002025-12-22 MEDIUM 6.5 CVE-2025-8304 An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being acce… Mitigation only Fix from $1,6002025-12-22 MEDIUM 5.3 CVE-2025-12492 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable… Mitigation only Fix from $1,6002025-12-20 HIGH 7.5 CVE-2025-14591 In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EO… Delphix Continuous Compliance after 2025.6.0.0 Fix from $1,9502025-12-20 MEDIUM 6.5 CVE-2025-68279 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf… Weblate 5.15.1+ Fix from $1,6002025-12-18 MEDIUM 5.3 CVE-2025-68429 Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 an… Storybook 7.6.21 / 8.6.15+ Fix from $1,6002025-12-17 HIGH 8.8 CVE-2025-68110 ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the hos… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 MEDIUM 5.5 CVE-2025-46278 The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data. macOS 26.2+ Fix from $1,6002025-12-17 MEDIUM 5.5 CVE-2025-46283 A logic issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access sens… macOS 26.2+ Fix from $1,6002025-12-17 MEDIUM 5.5 CVE-2025-43514 The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data. macOS 26.2+ Fix from $1,6002025-12-17