Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
CRITICAL 9.8 CVE-2025-43986 An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interf… Mitigation only Fix from $2,3002025-08-13 HIGH 7.5 CVE-2025-43988 KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers to retrieve sensitive configur… Mitigation only Fix from $1,9502025-08-13 HIGH 8.2 CVE-2025-55165 Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.… Patch available Fix from $1,9502025-08-12 MEDIUM 6.5 CVE-2025-53781 Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a net… Ecesv6 Series Azure Vm Firmware No fix yet Fix from $1,6002025-08-12 MEDIUM 6.5 CVE-2025-53728 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose inform… Dynamics 365 9.1.39.04+ Fix from $1,6002025-08-12 MEDIUM 5.5 CVE-2025-53156 Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally. Windows 11 24h2 10.0.25398.1791 / 10.0.26100.4851+ Fix from $1,6002025-08-12 HIGH 7.0 CVE-2025-53134 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a… Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 MEDIUM 5.5 CVE-2025-53136 Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,6002025-08-12 MEDIUM 6.5 CVE-2025-50154EPSS 26% Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ… Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,6002025-08-12 HIGH 7.5 CVE-2025-33051 Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over … Exchange Server 15.02.2562.020+ Fix from $1,9502025-08-12 CRITICAL 9.8 CVE-2025-3831 Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties. Harmony Sase Mitigation only Fix from $2,3002025-08-12 HIGH 7.8 CVE-2025-40768 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes an interna… Sinec Traffic Analyzer 3.0+ Fix from $1,9502025-08-12 MEDIUM 5.3 CVE-2025-4390 The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the … Mitigation only Fix from $1,6002025-08-12 MEDIUM 5.1 CVE-2025-8866 YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could … Mitigation only Fix from $1,6002025-08-11 HIGH 7.1 CVE-2025-55008 The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versi… Patch available Fix from $1,9502025-08-09 HIGH 7.1 CVE-2025-55009 The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions 0.… Patch available Fix from $1,9502025-08-09 MEDIUM 5.3 CVE-2025-8738 A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code o… Mitigation only Fix from $1,6002025-08-08 MEDIUM 6.7 CVE-2024-58257 EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution. Enzoh W5611t Firmware Mitigation only Fix from $1,6002025-08-08 HIGH 7.8 CVE-2024-58256 EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution. Enzoh W5611t Firmware No fix yet Fix from $1,9502025-08-08 MEDIUM 6.7 CVE-2024-58255 EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution. Enzoh W5611t Firmware No fix yet Fix from $1,6002025-08-08 MEDIUM 5.3 CVE-2025-54786 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken au… Suitecrm Mitigation only Fix from $1,6002025-08-07 HIGH 7.5 CVE-2025-46659 An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request. Exonaut Mitigation only Fix from $1,9502025-08-06 CRITICAL 9.8 CVE-2025-30127 An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video r… Mitigation only Fix from $2,3002025-08-06 HIGH 7.5 CVE-2025-51040 Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html endpoint in Electrolink 500W, 1k… Fm\/dab\/tv Transmitter Web Management System No fix yet Fix from $1,9502025-08-06 MEDIUM 5.3 CVE-2025-8620 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including… Givewp 4.6.1+ Fix from $1,6002025-08-06 MEDIUM 5.5 CVE-2025-54615 Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of this vulnerability may affect se… Harmonyos No fix yet Fix from $1,6002025-08-06 HIGH 7.5 CVE-2025-29745 A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash… Mitigation only Fix from $1,9502025-08-05 MEDIUM 5.3 CVE-2025-8525 A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Bo… Xboot after 3.3.4 Fix from $1,6002025-08-04 MEDIUM 5.3 CVE-2025-6722 The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… Mitigation only Fix from $1,6002025-08-02 CRITICAL 9.6 CVE-2025-54133 Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's M… Cursor 1.3+ Fix from $2,3002025-08-02