Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2025-53887 Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Dir… Directus 11.9.0+ Fix from $1,6002025-07-15 MEDIUM 6.5 CVE-2025-53640 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to… Indico 3.3.7+ Fix from $1,6002025-07-14 HIGH 7.5 CVE-2024-51769 An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. Autopass License Server 9.17+ Fix from $1,9502025-07-14 MEDIUM 5.3 CVE-2025-7573 A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000… No fix yet Fix from $1,6002025-07-14 MEDIUM 5.3 CVE-2025-7572 A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. … No fix yet Fix from $1,6002025-07-14 HIGH 7.5 CVE-2025-7565 A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi… Bl Ac3600 Firmware after 1.0.22 Fix from $1,9502025-07-14 HIGH 7.5 CVE-2020-36848 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in… Total Upkeep 1.14.10+ Fix from $1,9502025-07-12 MEDIUM 5.3 CVE-2025-6745 The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_que… Mitigation only Fix from $1,6002025-07-11 MEDIUM 6.5 CVE-2025-4593 The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6… Mitigation only Fix from $1,6002025-07-11 HIGH 7.1 CVE-2025-34098 A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper input validation in the log … No fix yet Fix from $1,9502025-07-10 MEDIUM 5.5 CVE-2025-52473 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branche… Liboqs 0.14.0+ Fix from $1,6002025-07-10 CRITICAL 10.0 CVE-2025-53624 The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists ve… Patch available Fix from $2,3002025-07-09 MEDIUM 6.5 CVE-2025-53512 The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contai… Juju 2.9.52 / 3.6.8+ Fix from $1,6002025-07-08 MEDIUM 6.5 CVE-2025-49671 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis… Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,6002025-07-08 MEDIUM 5.5 CVE-2025-49664 Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose infor… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 MEDIUM 5.5 CVE-2025-48808 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 MEDIUM 6.2 CVE-2025-47980 Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information local… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 MEDIUM 5.3 CVE-2025-20325 In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.113, and 9.2.240… Splunk 9.1.10 / 9.2.7+ Fix from $1,6002025-07-07 CRITICAL 9.3 CVE-2025-34072 A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI… Mitigation only Fix from $2,3002025-07-02 HIGH 7.5 CVE-2024-13451 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is v… Bit Form 2.17.6+ Fix from $1,9502025-07-02 HIGH 7.5 CVE-2025-49741 No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Edge Chromium 135.0.3179.98+ Fix from $1,9502025-07-01 CRITICAL 9.0 CVE-2025-34064 A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-productio… Mitigation only Fix from $2,3002025-07-01 HIGH 8.7 CVE-2025-34059 An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/… Mitigation only Fix from $1,9502025-07-01 MEDIUM 5.7 CVE-2025-34062 An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attack… Mitigation only Fix from $1,6002025-07-01 MEDIUM 6.9 CVE-2025-34051 A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?ac… No fix yet Fix from $1,6002025-07-01 HIGH 8.2 CVE-2025-53003 The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without s… Patch available Fix from $1,9502025-07-01 HIGH 8.8 CVE-2025-52898 Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor … Frappe 14.94.3 / 15.58.0+ Fix from $1,9502025-06-30 HIGH 7.5 CVE-2025-49845 Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers_allowed_groups` site setting… Discourse 3.4.6+ Fix from $1,9502025-06-25 HIGH 7.1 CVE-2025-27827 A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to conduct a… Mitigation only Fix from $1,9502025-06-24 HIGH 8.6 CVE-2025-6432 When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not… Firefox 140.0+ Fix from $1,9502025-06-24