Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2025-6984 The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML… Mitigation only Fix from $1,9502025-09-04 HIGH 7.5 CVE-2025-36895 Information disclosure Android No fix yet Fix from $1,9502025-09-04 HIGH 7.5 CVE-2025-20336 A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could a… Desk Phone 9841 Firmware 3.3 / 14.3+ Fix from $1,9502025-09-03 MEDIUM 6.5 CVE-2025-20270 A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow… Evolved Programmable Network Manager 8.0.1 / 8.1.2+ Fix from $1,6002025-09-03 HIGH 7.5 CVE-2025-53694EPSS 6% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (… Experience Commerce 10.4+ Fix from $1,9502025-09-03 HIGH 7.5 CVE-2025-9843 A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This mani… Parking Management System Mitigation only Fix from $1,9502025-09-03 HIGH 7.5 CVE-2025-9842 A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. Th… Parking Management System Mitigation only Fix from $1,9502025-09-03 MEDIUM 5.5 CVE-2025-22430 In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead… Android Mitigation only Fix from $1,6002025-09-02 MEDIUM 5.5 CVE-2025-58061 OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, p… Mitigation only Fix from $1,6002025-08-28 CRITICAL 9.1 CVE-2025-58059 Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to before 13.1.2.RELEASE, any admi… Patch available Fix from $2,3002025-08-28 MEDIUM 5.3 CVE-2025-57756 Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered … Contao 4.13.56 / 5.3.38+ Fix from $1,6002025-08-28 MEDIUM 5.3 CVE-2025-57757 Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their n… Contao 5.3.38 / 5.6.1+ Fix from $1,6002025-08-28 HIGH 7.5 CVE-2024-13807 The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.0.5 via the backup funct… Mitigation only Fix from $1,9502025-08-28 MEDIUM 5.5 CVE-2025-20290 A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone N… Mitigation only Fix from $1,6002025-08-27 CRITICAL 9.1 CVE-2024-39335 Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administra… Mahara 23.04.6 / 24.04.1+ Fix from $2,3002025-08-26 HIGH 7.5 CVE-2025-29992 Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily… Mahara 24.04.9+ Fix from $1,9502025-08-26 HIGH 7.5 CVE-2025-9461 A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePacka… Bbs after 6.8 Fix from $1,9502025-08-26 HIGH 7.5 CVE-2023-47799 Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration inter… Mahara 22.10.4 / 23.04.4+ Fix from $1,9502025-08-25 CRITICAL 9.3 CVE-2025-7426 Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated… Mitigation only Fix from $2,3002025-08-25 HIGH 7.5 CVE-2025-9398 A security vulnerability has been detected in YiFang CMS up to 2.0.5. Affected by this vulnerability is the function exportInstallTable of the file a… Yifang after 2.0.5 Fix from $1,9502025-08-25 HIGH 8.1 CVE-2025-57755 claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resou… Mitigation only Fix from $1,9502025-08-21 MEDIUM 6.5 CVE-2025-9139 A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plain… Scada Lts No fix yet Fix from $1,6002025-08-19 HIGH 8.8 CVE-2025-7654 Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated… Mitigation only Fix from $1,9502025-08-19 MEDIUM 5.3 CVE-2025-54118 NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allo… Nameless 2.2.4+ Fix from $1,6002025-08-18 MEDIUM 5.3 CVE-2024-12575 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, a… Mitigation only Fix from $1,6002025-08-16 MEDIUM 6.2 CVE-2025-43201 This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may be able to unexpectedly leak … Music Classical 2.3+ Fix from $1,6002025-08-15 MEDIUM 5.7 CVE-2025-26709 There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker ca… Mitigation only Fix from $1,6002025-08-15 MEDIUM 5.9 CVE-2025-50862 The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on… Mitigation only Fix from $1,6002025-08-14 CRITICAL 9.8 CVE-2025-27845 In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This al… Mitigation only Fix from $2,3002025-08-14 HIGH 8.5 CVE-2025-9036 A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a Web… Mitigation only Fix from $1,9502025-08-14