Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.7 CVE-2025-61679 Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even wi… Patch available Fix from $1,9502025-10-03 CRITICAL 9.8 CVE-2025-9209 The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due t… Mitigation only Fix from $2,3002025-10-03 MEDIUM 5.9 CVE-2025-61589 Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then g… Cursor 1.7+ Fix from $1,6002025-10-03 HIGH 7.5 CVE-2025-61665 WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability,… Wegia 3.5.0+ Fix from $1,9502025-10-02 HIGH 7.5 CVE-2025-59405 The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers … Flock Safety No fix yet Fix from $1,9502025-10-02 HIGH 7.5 CVE-2025-56161 YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the rela… Firefly Mall No fix yet Fix from $1,9502025-10-02 MEDIUM 5.3 CVE-2025-54290 Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence wi… Lxd 5.21.4 / 6.5+ Fix from $1,6002025-10-02 MEDIUM 5.4 CVE-2025-40646 Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by interceptin… Energy Crm Mitigation only Fix from $1,6002025-10-02 HIGH 8.7 CVE-2025-40645 Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensitive information about customer… Mitigation only Fix from $1,9502025-10-02 MEDIUM 5.9 CVE-2025-10744 The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… Mitigation only Fix from $1,6002025-10-01 MEDIUM 5.3 CVE-2025-34220 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,6002025-09-29 HIGH 8.8 CVE-2025-8868EPSS 23% In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restrict… Automate 4.13.295+ Fix from $1,9502025-09-29 CRITICAL 9.8 CVE-2025-11079 A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation r… Farm Management System Mitigation only Fix from $2,3002025-09-27 HIGH 7.5 CVE-2025-45994 An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /use… Passrecovery No fix yet Fix from $1,9502025-09-26 HIGH 7.5 CVE-2025-11028 A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image Handler. Performing manipulati… Vvveb after 1.0.7.2 Fix from $1,9502025-09-26 MEDIUM 6.8 CVE-2025-56463 Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure. Mw305r Firmware after 3.30 Fix from $1,6002025-09-26 HIGH 7.5 CVE-2025-11026 A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configurati… Vvveb after 1.0.7.2 Fix from $1,9502025-09-26 MEDIUM 5.3 CVE-2025-10952 A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream… Mitigation only Fix from $1,6002025-09-25 HIGH 7.5 CVE-2025-36601 Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An un… Powerscale Onefs 9.5.1.4 / 9.7.1.10+ Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-59833 Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hin… Flagforge 2.3+ Fix from $1,9502025-09-24 MEDIUM 6.5 CVE-2025-59535 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary them… Dotnetnuke 10.1.0+ Fix from $1,6002025-09-22 CRITICAL 9.6 CVE-2025-59434 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated … Mitigation only Fix from $2,3002025-09-22 CRITICAL 9.8 CVE-2025-57437 The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected… Web Presenter Hd Firmware Mitigation only Fix from $2,3002025-09-22 CRITICAL 9.8 CVE-2025-57441 The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Up… Atem Mini Pro Firmware Mitigation only Fix from $2,3002025-09-22 HIGH 7.5 CVE-2025-57430 Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns int… Creabox Manager No fix yet Fix from $1,9502025-09-22 MEDIUM 6.5 CVE-2025-57433 The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a specific endpo… Ip 4c Firmware No fix yet Fix from $1,6002025-09-22 HIGH 8.8 CVE-2023-49367 An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by… Mitigation only Fix from $1,9502025-09-18 MEDIUM 5.3 CVE-2024-25011 Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remed… Mitigation only Fix from $1,6002025-09-18 MEDIUM 6.5 CVE-2025-10607 A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi… I Educar after 2.10.0 Fix from $1,6002025-09-17 HIGH 7.5 CVE-2025-34185 Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote atta… Eve X1 Server Firmware after 4.7.18.0 Fix from $1,9502025-09-16