Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Ipados MEDIUM 6.6
CVE-2025-24198

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Seq…

Fix: 13.7.5 / 14.7.5+
Fix from $1,600 2025-03-31
Ipados MEDIUM 5.5
CVE-2025-24202

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able t…

Fix: 15.4 / 18.4+
Fix from $1,600 2025-03-31
Ipados MEDIUM 5.5
CVE-2025-24205

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15…

Fix: 13.7.5 / 14.7.5+
Fix from $1,600 2025-03-31
macOS HIGH 7.0
CVE-2024-54533

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura…

Fix: 13.7.5 / 14.7.5+
Fix from $1,950 2025-03-31
Ipados HIGH 7.8
CVE-2025-24173

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macO…

Fix: 2.4 / 13.7.5+
Fix from $1,950 2025-03-31
Vite HIGH 7.5
CVE-2025-31125 KEVEPSS 59%

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explici…

Fix: 4.5.11 / 5.4.16+
Fix from $1,950 2025-03-31
411 Firmware CRITICAL 9.1
CVE-2025-22940

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

No fix yet
Fix from $2,300 2025-03-31
Fh1202 Firmware MEDIUM 5.3
CVE-2025-2995

A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects unknown code of the file /goform/…

No fix yet
Fix from $1,600 2025-03-31
Fh1202 Firmware MEDIUM 5.3
CVE-2025-2996

A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. This issue affects some unknown processing of the file /goform/Sy…

No fix yet
Fix from $1,600 2025-03-31
Fh1202 Firmware MEDIUM 5.3
CVE-2025-2993EPSS 10%

A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality…

No fix yet
Fix from $1,600 2025-03-31
Fh1202 Firmware MEDIUM 5.3
CVE-2025-2994

A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetti…

No fix yet
Fix from $1,600 2025-03-31
Fh1202 Firmware MEDIUM 5.3
CVE-2025-2991

A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of the file /goform/AdvSetWrlmac…

No fix yet
Fix from $1,600 2025-03-31
Fh1202 Firmware MEDIUM 5.3
CVE-2025-2992

A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is an unknown functionality of the fil…

No fix yet
Fix from $1,600 2025-03-31
Fh1202 Firmware MEDIUM 5.3
CVE-2025-2989

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /gofor…

No fix yet
Fix from $1,600 2025-03-31
Fh1202 Firmware MEDIUM 5.3
CVE-2025-2990

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /gofor…

No fix yet
Fix from $1,600 2025-03-31
Wcms CRITICAL 9.8
CVE-2025-2978

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?arti…

No fix yet
Fix from $2,300 2025-03-31
College Management System CRITICAL 9.8
CVE-2025-2973

A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file…

No fix yet
Fix from $2,300 2025-03-31
A3000ru Firmware MEDIUM 5.3
CVE-2025-2955

A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file…

Fix: after 5.9c.5185
Fix from $1,600 2025-03-30
Openmanus MEDIUM 5.5
CVE-2025-2954

A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the f…

Fix: after 2025.3.13
Fix from $1,600 2025-03-30
Micro Mall CRITICAL 9.8
CVE-2025-2952

A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /…

No fix yet
Fix from $2,300 2025-03-30
Splunk MEDIUM 6.5
CVE-2025-20230

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk C…

Fix: 3.7.23 / 3.8.38+
Fix from $1,600 2025-03-26
Splunk HIGH 8.0
CVE-2025-20229EPSS 14%

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and …

Fix: 9.1.8 / 9.1.2312.208+
Fix from $1,950 2025-03-26
Tlr 2005ksh Firmware CRITICAL 9.8
CVE-2025-26010

Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.

Mitigation only
Fix from $2,300 2025-03-26
Appsmith MEDIUM 6.5
CVE-2024-55963EPSS 28%

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, caus…

Fix: 1.51+
Fix from $1,600 2025-03-26
Remote Desktop Manager MEDIUM 5.4
CVE-2025-2499

Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit th…

Fix: 2024.3.31.0 / 2025.1.26.0+
Fix from $1,600 2025-03-26
Unclassified MEDIUM 5.5
CVE-2025-23203

Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4…

Patch available
Fix from $1,600 2025-03-26
Yutufz 5651s1 Senaryaudio MEDIUM 5.5
CVE-2023-52972

Huawei PCs have a vulnerability that allows low-privilege users to bypass SDDL permission checks . Successful exploitation this vulnerability could l…

Mitigation only
Fix from $1,600 2025-03-26
Unclassified CRITICAL 9.8
CVE-2025-29315

An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and …

Mitigation only
Fix from $2,300 2025-03-24
Unclassified MEDIUM 6.3
CVE-2025-2706

A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/Ti…

Mitigation only
Fix from $1,600 2025-03-24
Vite HIGH 7.5
CVE-2025-30208EPSS 75%

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies acc…

Fix: 4.5.10 / 5.4.15+
Fix from $1,950 2025-03-24