Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.4 CVE-2025-43495 The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to mo… Ipados 26.1+ Fix from $1,6002025-11-04 MEDIUM 5.5 CVE-2025-43455 A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. A… Ipados 26.1+ Fix from $1,6002025-11-04 HIGH 7.5 CVE-2025-43449 The issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious app may be able to track users… Ipados 26.1+ Fix from $1,9502025-11-04 MEDIUM 5.5 CVE-2025-43411 This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An a… macOS 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 MEDIUM 5.5 CVE-2025-43391 A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS… Ipados 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 MEDIUM 5.5 CVE-2025-43378 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to … macOS 15.7.2+ Fix from $1,6002025-11-04 MEDIUM 5.5 CVE-2025-43360 The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentionally revealed. Ipados 26.0+ Fix from $1,6002025-11-04 MEDIUM 5.5 CVE-2025-43345 A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, ma… Ipados 14.8 / 15.7+ Fix from $1,6002025-11-04 HIGH 8.1 CVE-2025-43323 This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watch… Ipados 26.0+ Fix from $1,9502025-11-04 MEDIUM 6.8 CVE-2025-60892 An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting u… Mitigation only Fix from $1,6002025-11-03 MEDIUM 5.9 CVE-2025-12616 A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a m… News Portal No fix yet Fix from $1,6002025-11-03 CRITICAL 10.0 CVE-2025-29270 Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the… Mitigation only Fix from $2,3002025-10-31 MEDIUM 5.3 CVE-2025-12521 The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify … Mitigation only Fix from $1,6002025-10-31 MEDIUM 6.5 CVE-2025-34272 In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back… Log Server 2024+ Fix from $1,6002025-10-30 MEDIUM 6.8 CVE-2025-11998 The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing prior user identity to be inh… Mitigation only Fix from $1,6002025-10-30 MEDIUM 6.0 CVE-2025-12147 In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclu… Mitigation only Fix from $1,6002025-10-29 MEDIUM 6.0 CVE-2025-12148 In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of… Mitigation only Fix from $1,6002025-10-29 MEDIUM 5.3 CVE-2023-7320 The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.8.2, due to improper CORS ha… Mitigation only Fix from $1,6002025-10-29 HIGH 7.5 CVE-2025-60805 An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-res… Mitigation only Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-60858 Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing… Mitigation only Fix from $1,9502025-10-28 MEDIUM 5.3 CVE-2025-62524 PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-B… Pilos 4.8.0+ Fix from $1,6002025-10-27 HIGH 7.5 CVE-2025-12363 Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Blu Ic2 Firmware 1.20+ Fix from $1,9502025-10-27 HIGH 7.5 CVE-2025-27225EPSS 17% TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpo… Trufusion Enterprise after 7.10.4.0 Fix from $1,9502025-10-27 HIGH 7.5 CVE-2025-52268 StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tok… Mitigation only Fix from $1,9502025-10-27 HIGH 7.2 CVE-2025-61482 Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to … Mitigation only Fix from $1,9502025-10-27 CRITICAL 10.0 CVE-2025-61481 An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path at… Mitigation only Fix from $2,3002025-10-27 HIGH 7.5 CVE-2025-12276 A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of th… Learnhouse after 2025-09-21 Fix from $1,9502025-10-27 MEDIUM 5.3 CVE-2025-11760 The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information i… Mitigation only Fix from $1,6002025-10-25 HIGH 7.5 CVE-2025-11145 Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor… Mitigation only Fix from $1,9502025-10-24 HIGH 7.5 CVE-2025-6980 Captive Portal can expose sensitive information No fix yet Fix from $1,9502025-10-23