Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 11 24h2 HIGH 7.8
CVE-2025-60710 KEV

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges …

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,950 2025-11-11
Triofox CRITICAL 9.1
CVE-2025-12480 KEVEPSS 91%

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after se…

Fix: 16.7.10368.56560+
Fix from $2,300 2025-11-10
Filestore HIGH 7.2
CVE-2025-64328 KEVEPSS 85%

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestor…

Fix: 17.0.3+
Fix from $1,950 2025-11-07
Safari HIGH 8.8
CVE-2023-43000 KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.…

Fix: 13.5 / 15.8.7+
Fix from $1,950 2025-11-05
React Native Community Cli CRITICAL 9.8
CVE-2025-11953 KEVEPSS 94%

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpo…

Fix: 19.1.2+
Fix from $2,300 2025-11-03
Identity Manager CRITICAL 9.8
CVE-2025-61757 KEVEPSS 88%

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12…

Mitigation only
Fix from $2,300 2025-10-21
Lanscope Endpoint Manager CRITICAL 9.8
CVE-2025-61932 KEV

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing …

Fix: 9.3.2.7 / 9.3.3.9+
Fix from $2,300 2025-10-20
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2025-53521 KEV

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Softw…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $2,300 2025-10-15
Windows Server 2012 CRITICAL 9.8
CVE-2025-59287 KEVEPSS 100%

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8524 / 10.0.17763.7922+
Fix from $2,300 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59230 KEV

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-24990 KEVEPSS 6%

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Configurator HIGH 7.5
CVE-2025-61884 KEVEPSS 98%

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3…

Fix: after 12.2.14
Fix from $1,950 2025-10-12
Centrestack HIGH 7.5
CVE-2025-11371 KEVEPSS 92%

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows …

Fix: 16.10.10408.56683+
Fix from $1,950 2025-10-09
Concurrent Processing CRITICAL 9.8
CVE-2025-61882 KEVEPSS 100%

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that …

Fix: after 12.2.14
Fix from $2,300 2025-10-05
Aria Operations HIGH 7.8
CVE-2025-41244 KEVEPSS 8%

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privilege…

Fix: 5.0.1 / 8.18.5+
Fix from $1,950 2025-09-29
Adaptive Security Appliance Software HIGH 8.6
CVE-2025-20362 KEVEPSS 87%

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Softwar…

Fix: 7.0.8.1 / 7.2.10.2+
Fix from $1,950 2025-09-25
Adaptive Security Appliance Software CRITICAL 9.9
CVE-2025-20333 KEVEPSS 40%

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (F…

Fix: 7.0.8.1 / 7.2.9+
Fix from $2,300 2025-09-25
Ios Xe Sd Wan HIGH 7.7
CVE-2025-20352 KEVEPSS 39%

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:…

Mitigation only
Fix from $1,950 2025-09-24
Chrome CRITICAL 9.8
CVE-2025-10585 KEVEPSS 5%

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 140.0.7339.185+
Fix from $2,300 2025-09-24
Web Help Desk CRITICAL 9.8
CVE-2025-26399 KEVEPSS 88%

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exp…

Fix: after 12.8.6
Fix from $2,300 2025-09-23
Email Security Gateway MEDIUM 6.1
CVE-2025-59689 KEV

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.…

Fix: 5.0.31 / 5.1.20+
Fix from $1,600 2025-09-19
Webpanel CRITICAL 9.0
CVE-2025-48703 KEVEPSS 100%

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_tota…

Fix: 0.9.8.1205+
Fix from $2,300 2025-09-19
Goanywhere Managed File Transfer CRITICAL 9.8
CVE-2025-10035 KEVEPSS 100%

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…

Fix: 7.6.3 / 7.8.4+
Fix from $2,300 2025-09-18
Fireware CRITICAL 9.8
CVE-2025-9242 KEVEPSS 91%

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code…

Fix: 12.5.13 / 12.11.4+
Fix from $2,300 2025-09-17
Android CRITICAL 9.8
CVE-2025-21043 KEV

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $2,300 2025-09-12
Android CRITICAL 9.8
CVE-2025-21042 KEVEPSS 33%

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $2,300 2025-09-12
Commerce CRITICAL 9.1
CVE-2025-54236 KEVEPSS 95%

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vu…

Mitigation only
Fix from $2,300 2025-09-09
Android HIGH 8.8
CVE-2025-48543 KEV

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to l…

Patch available
Fix from $1,950 2025-09-04
Experience Commerce CRITICAL 9.0
CVE-2025-53690 KEVEPSS 31%

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This iss…

Fix: after 9.0
Fix from $2,300 2025-09-03
Tl Wr841n Firmware HIGH 7.2
CVE-2025-9377 KEVEPSS 12%

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) …

Fix: 241108+
Fix from $1,950 2025-08-29