Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zimbra Collaboration Suite MEDIUM 6.1
CVE-2025-66376 KEVEPSS 22%

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives…

Fix: 10.0.18 / 10.1.13+
Fix from $1,600 2026-01-05
Smartermail CRITICAL 10.0
CVE-2025-52691 KEVEPSS 85%

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po…

Fix: 100.0.9413+
Fix from $2,300 2025-12-29
Zimbra Collaboration Suite HIGH 8.8
CVE-2025-68645 KEVEPSS 32%

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling …

Fix: 10.0.18 / 10.1.13+
Fix from $1,950 2025-12-22
N8n HIGH 8.8
CVE-2025-68613 KEVEPSS 98%

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remo…

Fix: 1.120.4+
Fix from $1,950 2025-12-19
MongoDB HIGH 7.5
CVE-2025-14847 KEVEPSS 83%

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue a…

Fix: 4.4.30 / 5.0.32+
Fix from $1,950 2025-12-19
Fireware CRITICAL 9.8
CVE-2025-14733 KEVEPSS 27%

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code…

Fix: 12.5.15 / 12.11.6+
Fix from $2,300 2025-12-19
Sma6200 Firmware MEDIUM 6.6
CVE-2025-40602 KEV

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

Fix: 12.4.3-03245 / 12.5.0-02283+
Fix from $1,600 2025-12-18
Webmail MEDIUM 6.1
CVE-2025-68461 KEVEPSS 21%

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Fix: 1.5.12 / 1.6.12+
Fix from $1,600 2025-12-18
Safari HIGH 8.8
CVE-2025-43529 KEVEPSS 9%

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and …

Fix: 18.7.3 / 26.2+
Fix from $1,950 2025-12-17
Asyncos CRITICAL 10.0
CVE-2025-20393 KEVEPSS 30%

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could …

Fix: 15.0.2-007 / 15.0.5-016+
Fix from $2,300 2025-12-17
Live Update CRITICAL 9.8
CVE-2025-59374 KEV

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a sup…

Fix: 3.6.8+
Fix from $2,300 2025-12-17
Oneview CRITICAL 9.8
CVE-2025-37164 KEVEPSS 90%

A remote code execution issue exists in HPE OneView.

Fix: after 10.20.00
Fix from $2,300 2025-12-16
Ipados MEDIUM 5.5
CVE-2025-43520 KEV

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1,…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-12-12
Ipados HIGH 7.8
CVE-2025-43510 KEV

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 2…

Fix: 14.8.2 / 15.7.2+
Fix from $1,950 2025-12-12
Centrestack CRITICAL 9.8
CVE-2025-14611 KEVEPSS 53%

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degr…

Fix: 16.12.10420.56791+
Fix from $2,300 2025-12-12
Chrome HIGH 8.8
CVE-2025-14174 KEVEPSS 23%

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access…

Fix: 18.7.3 / 26.2+
Fix from $1,950 2025-12-12
Gogs HIGH 8.8
CVE-2025-8110 KEVEPSS 83%

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

Fix: after 0.13.3
Fix from $1,950 2025-12-10
Windows 10 1809 HIGH 7.8
CVE-2025-62221 KEV

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Fortiproxy CRITICAL 9.8
CVE-2025-59718 KEVEPSS 63%

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 …

Fix: 7.0.6 / 7.0.18+
Fix from $2,300 2025-12-09
Android MEDIUM 5.5
CVE-2025-48633 KEV

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in …

Patch available
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48572 KEV

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalat…

Mitigation only
Fix from $1,950 2025-12-08
Langflow HIGH 8.8
CVE-2025-34291 KEVEPSS 84%

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permis…

Fix: after 1.6.9
Fix from $1,950 2025-12-05
Arrayos Ag CRITICAL 9.8
CVE-2025-66644 KEV

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

Fix: 9.4.5.9+
Fix from $2,300 2025-12-05
React CRITICAL 10.0
CVE-2025-55182 KEVEPSS 100%

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the …

Fix: 15.0.5 / 15.1.9+
Fix from $2,300 2025-12-03
Ray HIGH 8.8
CVE-2025-62593 KEV

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabi…

Patch available
Fix from $1,950 2025-11-26
Geoserver CRITICAL 9.8
CVE-2025-58360 KEVEPSS 65%

GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XM…

Fix: 2.25.6 / 2.26.2+
Fix from $2,300 2025-11-25
Fortiweb HIGH 7.2
CVE-2025-58034 KEVEPSS 56%

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiW…

Fix: 7.0.12 / 7.2.12+
Fix from $1,950 2025-11-18
Chrome HIGH 8.8
CVE-2025-13223 KEVEPSS 5%

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 142.0.7444.175+
Fix from $1,950 2025-11-17
Fortiweb CRITICAL 9.8
CVE-2025-64446 KEVEPSS 92%

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWe…

Fix: 7.0.12 / 7.2.12+
Fix from $2,300 2025-11-14
Windows 10 1809 HIGH 7.0
CVE-2025-62215 KEVEPSS 6%

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11