Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.0 CVE-2025-14553 Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo cameras, allowing attackers to br… Mitigation only Fix from $1,9502025-12-16 MEDIUM 5.3 CVE-2025-46294 To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8do… Filemaker Server 22.0.4+ Fix from $1,6002025-12-16 MEDIUM 5.9 CVE-2025-13439 The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including… Mitigation only Fix from $1,6002025-12-16 MEDIUM 5.5 CVE-2025-66963 An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html Hi3120 Firmware No fix yet Fix from $1,6002025-12-15 CRITICAL 9.8 CVE-2025-11693 The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.… Mitigation only Fix from $2,3002025-12-13 MEDIUM 5.5 CVE-2025-43523 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to … macOS 15.7.3+ Fix from $1,6002025-12-12 MEDIUM 5.5 CVE-2025-43530 This issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS … macOS 14.8.3 / 15.7.3+ Fix from $1,6002025-12-12 MEDIUM 5.5 CVE-2025-43538 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sono… macOS 14.8.3+ Fix from $1,6002025-12-12 HIGH 7.5 CVE-2025-43542 This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia… macOS 15.7.3+ Fix from $1,9502025-12-12 MEDIUM 5.5 CVE-2025-43473 This issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. macOS 26.1+ Fix from $1,6002025-12-12 MEDIUM 5.5 CVE-2025-43509 This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app ma… macOS 14.8.3 / 15.7.3+ Fix from $1,6002025-12-12 MEDIUM 5.3 CVE-2025-12408 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc… Mitigation only Fix from $1,6002025-12-12 MEDIUM 5.3 CVE-2025-13660 The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. This is due to the plugin expo… Mitigation only Fix from $1,6002025-12-12 HIGH 7.5 CVE-2025-14528 A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Han… Dir 803 Firmware after 1.04 Fix from $1,9502025-12-11 HIGH 8.7 CVE-2025-67718 Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path… Patch available Fix from $1,9502025-12-11 CRITICAL 9.8 CVE-2025-65820 An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application which opens a… Meatmeet Mitigation only Fix from $2,3002025-12-10 HIGH 7.5 CVE-2025-63094 XiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackers to acces… Xiangshan No fix yet Fix from $1,9502025-12-10 MEDIUM 6.5 CVE-2025-52493 PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear mask… Runbook Automation after 2025-06-12 Fix from $1,6002025-12-10 MEDIUM 6.5 CVE-2025-64670 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over… Windows 10 21h2 10.0.19044.6691 / 10.0.19045.6691+ Fix from $1,6002025-12-09 HIGH 7.5 CVE-2025-14286 A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/Downlo… Ac9 Firmware No fix yet Fix from $1,9502025-12-09 MEDIUM 5.8 CVE-2024-38798 EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Succe… No fix yet Fix from $1,6002025-12-09 MEDIUM 5.5 CVE-2025-66330 App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect service confi… Harmonyos No fix yet Fix from $1,6002025-12-08 MEDIUM 5.5 CVE-2025-58279 Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentialit… Harmonyos No fix yet Fix from $1,6002025-12-08 MEDIUM 5.3 CVE-2025-14198 A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummyt… Verysync after 2.21.3 Fix from $1,6002025-12-07 MEDIUM 5.3 CVE-2025-14197 A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/res… Mitigation only Fix from $1,6002025-12-07 HIGH 7.4 CVE-2025-66623 Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.… Strimzi 0.49.1+ Fix from $1,9502025-12-05 MEDIUM 5.3 CVE-2025-13494 The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the pl… Mitigation only Fix from $1,6002025-12-05 MEDIUM 5.3 CVE-2025-13006 The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… Mitigation only Fix from $1,6002025-12-05 HIGH 7.4 CVE-2025-10285 The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker coul… Mitigation only Fix from $1,9502025-12-04 HIGH 7.5 CVE-2025-56427 Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir funct… Composio No fix yet Fix from $1,9502025-12-04