Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 8.1
CVE-2025-27363 KEVEPSS 28%

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font sub…

Fix: after 2.13.0
Fix from $1,950 2025-03-11
Megarac Sp X CRITICAL 9.8
CVE-2024-54085 KEVEPSS 61%

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful e…

Fix: 12.7 / 13.5+
Fix from $2,300 2025-03-11
Tomcat CRITICAL 9.8
CVE-2025-24813 KEVEPSS 100%

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade…

Fix: 9.0.99 / 10.1.35+
Fix from $2,300 2025-03-10
Ic 7100 Firmware CRITICAL 9.8
CVE-2025-1316 KEVEPSS 73%

Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device

Mitigation only
Fix from $2,300 2025-03-05
Esxi MEDIUM 6.0
CVE-2025-22226 KEV

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with adm…

Fix: 13.6.3 / 17.6.3+
Fix from $1,600 2025-03-04
Esxi HIGH 8.2
CVE-2025-22225 KEV

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write…

Mitigation only
Fix from $1,950 2025-03-04
Esxi HIGH 8.2
CVE-2025-22224 KEV

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with …

Fix: 17.6.3+
Fix from $1,950 2025-03-04
Backup \& Replication Director HIGH 8.6
CVE-2024-48248 KEVEPSS 94%

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to re…

Fix: 11.0.0.88174+
Fix from $1,950 2025-03-04
Xwiki CRITICAL 9.8
CVE-2025-24893 KEVEPSS 100%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code …

Fix: 15.10.11 / 16.4.1+
Fix from $2,300 2025-02-20
Power Pages CRITICAL 9.8
CVE-2025-24989 KEV

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th…

Patch available
Fix from $2,300 2025-02-19
Pan Os MEDIUM 6.5
CVE-2025-0111 KEV

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the manag…

Fix: 10.1.14 / 10.2.7+
Fix from $1,600 2025-02-12
Pan Os CRITICAL 9.1
CVE-2025-0108 KEVEPSS 98%

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web inte…

Fix: 10.1.14 / 10.2.7+
Fix from $2,300 2025-02-12
Windows 10 1607 HIGH 7.8
CVE-2025-21418 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Fix: 10.0.10240.20915 / 10.0.17763.6893+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 7.1
CVE-2025-21391 KEV

Windows Storage Elevation of Privilege Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Fortiproxy HIGH 8.1
CVE-2025-24472 KEV

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 throu…

Fix: 7.0.17 / 7.0.20+
Fix from $1,950 2025-02-11
Wazuh CRITICAL 9.9
CVE-2025-24016 KEVEPSS 94%

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, a…

Fix: 4.9.1+
Fix from $2,300 2025-02-10
Ipados MEDIUM 6.1
CVE-2025-24200 KEV

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7…

Fix: 15.8.4 / 16.7.11+
Fix from $1,600 2025-02-10
Cityworks HIGH 8.8
CVE-2025-0994 KEVEPSS 31%

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerabil…

Fix: 15.8.9 / 23.10+
Fix from $1,950 2025-02-06
Vmg1312 B10a Firmware HIGH 8.8
CVE-2024-40891 KEVEPSS 22%

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B1…

Mitigation only
Fix from $1,950 2025-02-04
Vmg1312 B10a Firmware HIGH 8.8
CVE-2024-40890 KEVEPSS 22%

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmw…

Mitigation only
Fix from $1,950 2025-02-04
Ds 2105 Pro Firmware HIGH 8.8
CVE-2023-52163 KEVEPSS 97%

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer …

Mitigation only
Fix from $1,950 2025-02-03
Veracore HIGH 7.5
CVE-2025-25181 KEVEPSS 51%

A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands …

Fix: 2025.1.1.3+
Fix from $1,950 2025-02-03
Veracore HIGH 8.8
CVE-2024-57968 KEVEPSS 32%

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during w…

Fix: 2024.4.2.1+
Fix from $1,950 2025-02-03
Ipados CRITICAL 10.0
CVE-2025-24085 KEVEPSS 17%

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 1…

Fix: 2.3 / 11.3+
Fix from $2,300 2025-01-27
Active Iq Unified Manager HIGH 7.0
CVE-2025-0411 KEVEPSS 67%

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected…

Fix: 24.09+
Fix from $1,950 2025-01-25
Sma8200v CRITICAL 9.8
CVE-2025-23006 KEVEPSS 23%

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central …

Fix: 12.4.3-02854+
Fix from $2,300 2025-01-23
Craft Cms HIGH 8.1
CVE-2025-23209 KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerab…

Fix: 4.13.8 / 5.5.8+
Fix from $1,950 2025-01-18
Simplehelp HIGH 7.2
CVE-2024-57728 KEVEPSS 7%

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted …

Fix: 5.5.8+
Fix from $1,950 2025-01-15
Simplehelp HIGH 7.5
CVE-2024-57727 KEVEPSS 95%

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote atta…

Fix: 5.5.8+
Fix from $1,950 2025-01-15
Simplehelp CRITICAL 9.9
CVE-2024-57726 KEVEPSS 67%

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive per…

Fix: 5.5.8+
Fix from $2,300 2025-01-15