Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2025-4523 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized access of data due to a missing … Idonate 2.1.10+ Fix from $1,6002025-08-01 MEDIUM 6.5 CVE-2025-54586 GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commi… Gitproxy 1.19.2+ Fix from $1,6002025-07-30 HIGH 8.1 CVE-2025-45620 An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request Ptc310uv2 Firmware No fix yet Fix from $1,9502025-07-30 MEDIUM 5.3 CVE-2025-43018 Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book. W1a75a Firmware 002.2508a+ Fix from $1,6002025-07-30 MEDIUM 5.3 CVE-2025-54425 Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the content delivery API can be restri… Umbraco Cms 13.9.3 / 15.4.4+ Fix from $1,6002025-07-30 MEDIUM 6.0 CVE-2025-4426 The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" w… No fix yet Fix from $1,6002025-07-30 MEDIUM 5.5 CVE-2025-43246 This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to access sensitive… macOS 14.7.7 / 15.6+ Fix from $1,6002025-07-30 MEDIUM 5.5 CVE-2025-43215 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may result in disclos… macOS 15.6+ Fix from $1,6002025-07-30 CRITICAL 9.8 CVE-2025-31279 A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS … Ipados 13.7.7 / 14.7.7+ Fix from $2,3002025-07-30 CRITICAL 9.8 CVE-2025-43189 This issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able t… macOS 14.7.7 / 15.6+ Fix from $2,3002025-07-30 CRITICAL 9.8 CVE-2025-50738 The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing su… Memos after 0.24.3 Fix from $2,3002025-07-29 CRITICAL 9.8 CVE-2025-8226 A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sy… Chancms 3.1.3+ Fix from $2,3002025-07-27 MEDIUM 6.5 CVE-2025-54380 Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would inco… Opencast 17.6+ Fix from $1,6002025-07-26 CRITICAL 9.4 CVE-2025-29628 A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobil… Mitigation only Fix from $2,3002025-07-25 CRITICAL 9.1 CVE-2025-29629 Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default crede… Mitigation only Fix from $2,3002025-07-25 MEDIUM 6.5 CVE-2025-3508 Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensi… W3z72e Firmware Mitigation only Fix from $1,6002025-07-25 HIGH 8.7 CVE-2020-36850 An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one u… Mitigation only Fix from $1,9502025-07-25 MEDIUM 6.5 CVE-2025-31955 HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the s… Dryice Iautomate No fix yet Fix from $1,6002025-07-24 MEDIUM 6.5 CVE-2025-7780 The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeA… Mitigation only Fix from $1,6002025-07-24 HIGH 8.1 CVE-2025-8039 In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Fir… Firefox 140.1 / 141.0+ Fix from $1,9502025-07-22 MEDIUM 5.3 CVE-2025-6082 The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to in… Mitigation only Fix from $1,6002025-07-22 MEDIUM 5.1 CVE-2025-52372 An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss… Hmailserver No fix yet Fix from $1,6002025-07-21 MEDIUM 6.5 CVE-2025-7919 WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitra… Mitigation only Fix from $1,6002025-07-21 MEDIUM 5.3 CVE-2025-46382 CWE-200 Exposure of Sensitive Information to an Unauthorized Actor No fix yet Fix from $1,6002025-07-20 CRITICAL 9.1 CVE-2025-7874 A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown function… Metacrm after 6.4.2 Fix from $2,3002025-07-20 CRITICAL 9.8 CVE-2025-7394 In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable… Wolfssl after 5.8.0 Fix from $2,3002025-07-18 HIGH 7.5 CVE-2025-50708 An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL Mitigation only Fix from $1,9502025-07-18 HIGH 8.7 CVE-2025-34130 An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin… Mitigation only Fix from $1,9502025-07-16 MEDIUM 6.1 CVE-2025-22227 In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must hav… Mitigation only Fix from $1,6002025-07-16 MEDIUM 5.3 CVE-2025-30758 Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface). Supported versions that are affected are 25.0-25.… Siebel Crm Deployment after 25.5 Fix from $1,6002025-07-15