Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2025-24142 A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, m… macOS 13.7.6 / 14.7.6+ Fix from $1,6002025-05-12 MEDIUM 5.5 CVE-2025-24144 An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS … Ipados 2.3 / 11.3+ Fix from $1,6002025-05-12 MEDIUM 5.5 CVE-2025-24155 The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app m… macOS 13.7.6 / 14.7.6+ Fix from $1,6002025-05-12 MEDIUM 5.5 CVE-2025-24220 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may be able to… Ipados 18.4+ Fix from $1,6002025-05-12 MEDIUM 5.3 CVE-2025-4536 A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classified as critical. Affected by th… Group Audio Visual Integrated Management No fix yet Fix from $1,6002025-05-11 MEDIUM 5.3 CVE-2025-4535 A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0. Affected… Group Audio Visual Integrated Management No fix yet Fix from $1,6002025-05-11 MEDIUM 5.5 CVE-2025-4526 A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page… Ngc Explorer Mitigation only Fix from $1,6002025-05-11 CRITICAL 9.1 CVE-2025-20221 A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 an… Ios Xe Mitigation only Fix from $2,3002025-05-07 MEDIUM 5.3 CVE-2025-47418 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible in… Mitigation only Fix from $1,6002025-05-06 MEDIUM 5.1 CVE-2025-47417 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. When Enable Debug Im… Mitigation only Fix from $1,6002025-05-06 HIGH 7.1 CVE-2025-46820 phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.y… Patch available Fix from $1,9502025-05-06 MEDIUM 5.5 CVE-2024-58252 Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect ser… Harmonyos No fix yet Fix from $1,6002025-05-06 HIGH 7.5 CVE-2025-46813 Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d113… Discourse 3.5.0+ Fix from $1,9502025-05-05 HIGH 7.5 CVE-2025-4270EPSS 13% A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/… A720r Firmware No fix yet Fix from $1,9502025-05-05 MEDIUM 5.3 CVE-2025-4271 A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functional… A720r Firmware No fix yet Fix from $1,6002025-05-05 MEDIUM 5.9 CVE-2025-4222 The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup file… Mitigation only Fix from $1,6002025-05-03 MEDIUM 6.5 CVE-2025-46332 Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 and prior and @vercel/flags f… Mitigation only Fix from $1,6002025-05-02 MEDIUM 5.3 CVE-2025-2880 The Yame | Link In Bio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.9.0 through the p… Mitigation only Fix from $1,6002025-05-02 MEDIUM 5.7 CVE-2024-11994 APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this co… Mitigation only Fix from $1,6002025-05-01 HIGH 7.1 CVE-2023-46669 Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and… Elastic Agent 8.15.0+ Fix from $1,9502025-05-01 MEDIUM 6.3 CVE-2025-46552 KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some comm… Patch available Fix from $1,6002025-04-29 MEDIUM 5.7 CVE-2025-24270 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS S… Ipados 2.4 / 13.7.5+ Fix from $1,6002025-04-29 HIGH 7.5 CVE-2025-3978 A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file… Lecms No fix yet Fix from $1,9502025-04-27 MEDIUM 5.3 CVE-2025-3975 A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of… Ecommerce Website In Php No fix yet Fix from $1,6002025-04-27 MEDIUM 5.3 CVE-2025-3966 A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file… Paicoding No fix yet Fix from $1,6002025-04-27 HIGH 7.5 CVE-2025-32983 NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace. Ngeniusone 6.4.0+ Fix from $1,9502025-04-25 HIGH 7.5 CVE-2025-32986 NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint. Ngeniusone 6.4.0+ Fix from $1,9502025-04-25 HIGH 7.5 CVE-2025-32044 A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact infor… Moodle 4.5.3+ Fix from $1,9502025-04-25 MEDIUM 5.3 CVE-2025-3923 The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… Mitigation only Fix from $1,6002025-04-25 HIGH 7.5 CVE-2024-11299 The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.37 via the WordPress … Memberpress after 1.11.37 Fix from $1,9502025-04-22