Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2025-10535 Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143. Firefox 143.0+ Fix from $1,9502025-09-16 MEDIUM 6.2 CVE-2025-10536 Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thund… Firefox 140.3.0 / 143.0+ Fix from $1,6002025-09-16 MEDIUM 5.7 CVE-2025-26711 There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker … Mitigation only Fix from $1,6002025-09-16 MEDIUM 5.3 CVE-2025-9808 The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint… Mitigation only Fix from $1,6002025-09-16 CRITICAL 9.8 CVE-2025-43362 The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to monitor ke… Ipados 18.7+ Fix from $2,3002025-09-15 MEDIUM 5.5 CVE-2025-43367 A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protec… macOS 14.8 / 26.0+ Fix from $1,6002025-09-15 MEDIUM 6.5 CVE-2025-43356 The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tah… Safari 18.7 / 26.0+ Fix from $1,6002025-09-15 MEDIUM 5.3 CVE-2025-10321 A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead t… Wl Wn578w2 Firmware No fix yet Fix from $1,6002025-09-12 MEDIUM 6.5 CVE-2025-56467 An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as acc… Mitigation only Fix from $1,6002025-09-12 HIGH 7.5 CVE-2025-54376 Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by… Hoverfly 1.12.0+ Fix from $1,9502025-09-10 HIGH 8.4 CVE-2025-55976 Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can d… Iwr 3000n Firmware after 1.9.8 Fix from $1,9502025-09-10 HIGH 7.5 CVE-2025-56406 An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE… Mitigation only Fix from $1,9502025-09-10 HIGH 8.7 CVE-2025-36759 Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addre… Mitigation only Fix from $1,9502025-09-10 HIGH 7.5 CVE-2025-29089 An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information Mitigation only Fix from $1,9502025-09-09 HIGH 7.5 CVE-2025-55243 Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a networ… Officeplus 3.10.0.26585+ Fix from $1,9502025-09-09 MEDIUM 5.5 CVE-2025-53804 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-47997 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose i… Sql Server 2016 13.0.6470.1 / 13.0.7065.1+ Fix from $1,6002025-09-09 MEDIUM 6.7 CVE-2025-33045 APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to … Aptio V 5.040+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-59018 Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑1… TYPO3 9.5.55 / 10.4.54+ Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-40757 A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BA… Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-58751 Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the pu… Vite 5.4.20 / 6.3.6+ Fix from $1,6002025-09-08 MEDIUM 5.3 CVE-2025-58752 Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served reg… Vite 5.4.20 / 6.3.6+ Fix from $1,6002025-09-08 CRITICAL 9.8 CVE-2025-22956 OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if an… Mitigation only Fix from $2,3002025-09-08 HIGH 7.5 CVE-2025-10093 A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php… Dir 852 Firmware No fix yet Fix from $1,9502025-09-08 HIGH 7.5 CVE-2025-58445 Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose de… Atlantis after 0.35.1 Fix from $1,9502025-09-06 MEDIUM 5.3 CVE-2025-7368 The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information Exposure in all versions up t… Mitigation only Fix from $1,6002025-09-06 HIGH 7.5 CVE-2025-55242 Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network. Xbox Gaming Services No fix yet Fix from $1,9502025-09-04 CRITICAL 9.9 CVE-2025-55190EPSS 5% Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.… Argo Cd 2.13.9 / 2.14.16+ Fix from $2,3002025-09-04 MEDIUM 6.2 CVE-2025-48527 In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead to local i… Android Patch available Fix from $1,6002025-09-04 MEDIUM 5.5 CVE-2025-26453 In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could l… Android Patch available Fix from $1,6002025-09-04