Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
CRITICAL 9.8 CVE-2025-54304 An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The d… Ion Torrent Onetouch 2 Firmware Mitigation only Fix from $2,3002025-12-04 MEDIUM 5.3 CVE-2025-11379 The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is du… Mitigation only Fix from $1,6002025-12-04 MEDIUM 5.3 CVE-2025-12585 The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.… Mitigation only Fix from $1,6002025-12-03 HIGH 7.5 CVE-2025-41014 User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user e… Gim 2025-04-01+ Fix from $1,9502025-12-02 HIGH 7.5 CVE-2025-41015 User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user e… Gim 2025-04-01+ Fix from $1,9502025-12-02 MEDIUM 5.3 CVE-2025-41066 Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on … Groupware Mitigation only Fix from $1,6002025-12-02 MEDIUM 5.3 CVE-2025-13696 The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin … Patch available Fix from $1,6002025-12-02 HIGH 7.2 CVE-2025-66304 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view … Grav 1.8.0+ Fix from $1,9502025-12-01 MEDIUM 5.1 CVE-2025-2879 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture K… 5th Gen Gpu Architecture Kernel Driver Mitigation only Fix from $1,6002025-12-01 MEDIUM 6.5 CVE-2025-13785 A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the … Skuul after 2.6.5 Fix from $1,6002025-11-30 MEDIUM 6.5 CVE-2025-66027 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant detai… Rallly 4.5.6+ Fix from $1,6002025-11-29 MEDIUM 6.5 CVE-2025-13683 Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: throug… Devolutions Server 2025.3.10.0 / 2025.3.25.0+ Fix from $1,6002025-11-28 MEDIUM 5.5 CVE-2025-58305 Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability may affect service confidentia… Harmonyos No fix yet Fix from $1,6002025-11-28 HIGH 7.5 CVE-2025-64312 Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidential… Harmonyos Mitigation only Fix from $1,9502025-11-28 MEDIUM 5.5 CVE-2025-64311 Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,6002025-11-28 MEDIUM 5.3 CVE-2025-12584 The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_p… Mitigation only Fix from $1,6002025-11-27 HIGH 7.5 CVE-2025-65278 An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive informatio… Grocerymart No fix yet Fix from $1,9502025-11-26 HIGH 8.8 CVE-2025-65957 Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_API_KEY, TOKEN) are loaded us… Patch available Fix from $1,9502025-11-26 CRITICAL 9.0 CVE-2025-63729 An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SS… Sy Gpon 1110 Wdont Firmware No fix yet Fix from $2,3002025-11-25 CRITICAL 9.6 CVE-2025-60739 Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 … Eve X1 Server Firmware No fix yet Fix from $2,3002025-11-25 MEDIUM 5.3 CVE-2025-12525 The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'lockerco_submit_post' AJAX endpoint… Mitigation only Fix from $1,6002025-11-25 HIGH 8.7 CVE-2025-65951 Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based timelock encryption system fails… Patch available Fix from $1,9502025-11-25 CRITICAL 9.8 CVE-2025-63958 MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authenticatio… Vision Tools Workspace Mitigation only Fix from $2,3002025-11-24 HIGH 7.5 CVE-2025-13526 The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.8 via the… Mitigation only Fix from $1,9502025-11-22 MEDIUM 5.3 CVE-2025-12039 The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0… Mitigation only Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-11368 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.… Mitigation only Fix from $1,6002025-11-21 MEDIUM 6.5 CVE-2025-63212 GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) … Flexiva Lx100 Firmware No fix yet Fix from $1,6002025-11-19 HIGH 7.5 CVE-2025-63209 The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and possibly other models, contains… Star150 Firmware No fix yet Fix from $1,9502025-11-19 HIGH 7.5 CVE-2025-63205 An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production… Vb220 Firmware No fix yet Fix from $1,9502025-11-19 HIGH 7.5 CVE-2025-12426 The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to th… Quiz Maker 6.7.0.81+ Fix from $1,9502025-11-19