Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2025-60805 An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-res… Mitigation only Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-60858 Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing… Mitigation only Fix from $1,9502025-10-28 MEDIUM 5.3 CVE-2025-62524 PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-B… Pilos 4.8.0+ Fix from $1,6002025-10-27 HIGH 7.5 CVE-2025-12363 Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Blu Ic2 Firmware 1.20+ Fix from $1,9502025-10-27 HIGH 7.5 CVE-2025-27225EPSS 17% TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpo… Trufusion Enterprise after 7.10.4.0 Fix from $1,9502025-10-27 HIGH 7.5 CVE-2025-52268 StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tok… Mitigation only Fix from $1,9502025-10-27 HIGH 7.2 CVE-2025-61482 Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to … Mitigation only Fix from $1,9502025-10-27 CRITICAL 10.0 CVE-2025-61481 An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path at… Mitigation only Fix from $2,3002025-10-27 HIGH 7.5 CVE-2025-12276 A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of th… Learnhouse after 2025-09-21 Fix from $1,9502025-10-27 MEDIUM 5.3 CVE-2025-11760 The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information i… Mitigation only Fix from $1,6002025-10-25 HIGH 7.5 CVE-2025-11145 Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor… Mitigation only Fix from $1,9502025-10-24 HIGH 7.5 CVE-2025-6980 Captive Portal can expose sensitive information No fix yet Fix from $1,9502025-10-23 MEDIUM 6.5 CVE-2025-62400 Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal priv… Moodle 4.1.21 / 4.4.11+ Fix from $1,6002025-10-23 HIGH 7.5 CVE-2025-62604 MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval of arbitrary user information.… Metersphere 2.10.25+ Fix from $1,9502025-10-22 MEDIUM 5.3 CVE-2025-61764 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $1,6002025-10-21 HIGH 7.5 CVE-2025-53066 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supporte… Graalvm Mitigation only Fix from $1,9502025-10-21 MEDIUM 5.8 CVE-2025-53047 Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and … Database Server after 23.9 Fix from $1,6002025-10-21 HIGH 8.1 CVE-2025-53043 Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.… Product Hub after 12.2.14 Fix from $1,9502025-10-21 HIGH 8.6 CVE-2025-53036 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P… Financial Services Analytical Applications Infrastructure Mitigation only Fix from $1,9502025-10-21 HIGH 7.5 CVE-2025-61220 The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other users and gain unauthorized … Mitigation only Fix from $1,9502025-10-21 HIGH 8.6 CVE-2025-60344EPSS 10% A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input paramet… Mitigation only Fix from $1,9502025-10-21 HIGH 8.2 CVE-2025-11151 Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability … Mitigation only Fix from $1,9502025-10-21 MEDIUM 6.5 CVE-2025-6239 Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. Manageengine Applications Manager 17.6+ Fix from $1,6002025-10-21 MEDIUM 6.9 CVE-2025-62699 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Translate Extension allows Footprint… Mitigation only Fix from $1,6002025-10-21 MEDIUM 5.3 CVE-2025-10750 The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is… Mitigation only Fix from $1,6002025-10-18 MEDIUM 6.9 CVE-2025-62669 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resourc… No fix yet Fix from $1,6002025-10-18 MEDIUM 6.5 CVE-2025-61907 Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoin… Icinga 2.13.13 / 2.14.7+ Fix from $1,6002025-10-16 MEDIUM 6.5 CVE-2025-53092 Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default… Strapi 5.20.0+ Fix from $1,6002025-10-16 MEDIUM 5.5 CVE-2025-59284 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. Windows 11 22h2 10.0.22621.6060 / 10.0.22631.6060+ Fix from $1,6002025-10-14 MEDIUM 5.5 CVE-2025-59260 Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose inf… Windows Server 2016 10.0.17763.7919 / 10.0.20348.4294+ Fix from $1,6002025-10-14