Vulnerability index

Browse CVEs

7,744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2025-25951 An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information Syste… Academia Student Information System Mitigation only Fix from $1,9502025-03-03 HIGH 7.5 CVE-2024-13611 The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Informa… Better Messages 2.7.0+ Fix from $1,9502025-03-01 HIGH 7.2 CVE-2024-13911 The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… Mitigation only Fix from $1,9502025-03-01 HIGH 7.5 CVE-2024-13568 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u… Fluent Support 1.8.6+ Fix from $1,9502025-03-01 MEDIUM 5.1 CVE-2025-26263 GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to imp… Mitigation only Fix from $1,6002025-02-28 HIGH 7.5 CVE-2024-13638 The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.… Order Attachments For Woocommerce after 2.5.1 Fix from $1,9502025-02-28 HIGH 7.5 CVE-2024-13796 The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… Post Grid 2.3.7+ Fix from $1,9502025-02-28 HIGH 7.5 CVE-2025-25729 An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attacker… Mitigation only Fix from $1,9502025-02-28 MEDIUM 5.3 CVE-2024-38290 In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met. Xiq Se 24.2.11+ Fix from $1,6002025-02-27 MEDIUM 5.3 CVE-2025-27399 Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the visibility for domain blocks/re… Mastodon 4.1.23 / 4.2.16+ Fix from $1,6002025-02-27 HIGH 7.5 CVE-2025-25333 An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link. No fix yet Fix from $1,9502025-02-27 MEDIUM 5.3 CVE-2024-12434 The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. T… Mitigation only Fix from $1,6002025-02-26 MEDIUM 6.5 CVE-2025-25192 GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive i… Glpi 10.0.18+ Fix from $1,6002025-02-25 MEDIUM 6.5 CVE-2025-21626 GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anonymous user can fetch sensitive… Glpi 10.0.18+ Fix from $1,6002025-02-25 MEDIUM 5.3 CVE-2025-1063 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… Classified Listing 4.0.5+ Fix from $1,6002025-02-25 HIGH 7.5 CVE-2025-1606 A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of… Best Employee Management System No fix yet Fix from $1,9502025-02-24 MEDIUM 5.3 CVE-2025-1595 A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects un… No fix yet Fix from $1,6002025-02-23 HIGH 7.5 CVE-2025-22973 An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. … Qibocms X1 Mitigation only Fix from $1,9502025-02-20 MEDIUM 6.5 CVE-2024-54961 Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the username… Nagios Xi Mitigation only Fix from $1,6002025-02-20 MEDIUM 6.5 CVE-2025-26309 A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to caus… Libming No fix yet Fix from $1,6002025-02-20 MEDIUM 6.5 CVE-2025-26310 Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming … Libming No fix yet Fix from $1,6002025-02-20 HIGH 7.5 CVE-2024-57716 An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function. Mitigation only Fix from $1,9502025-02-20 MEDIUM 6.5 CVE-2025-25942 An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specific… Bento4 No fix yet Fix from $1,6002025-02-19 MEDIUM 6.5 CVE-2025-25945 An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDesc… Bento4 No fix yet Fix from $1,6002025-02-19 MEDIUM 5.5 CVE-2025-25946 An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncrypt… Bento4 No fix yet Fix from $1,6002025-02-19 MEDIUM 6.1 CVE-2020-13481 Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information. Mitigation only Fix from $1,6002025-02-19 MEDIUM 6.5 CVE-2025-25468 FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c. Ffmpeg 2025-01-13+ Fix from $1,6002025-02-18 HIGH 8.3 CVE-2025-26604 Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Beca… Patch available Fix from $1,9502025-02-18 MEDIUM 5.9 CVE-2024-13609 The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver… 1 Click Migration after 2.1 Fix from $1,6002025-02-18 HIGH 7.5 CVE-2024-13622 The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7… File Uploads Addon For Woocommerce after 1.7.1 Fix from $1,9502025-02-18