Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Whatsapp MEDIUM 5.4
CVE-2025-55177 KEV

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, a…

Fix: 2.25.21.73 / 2.25.21.78+
Fix from $1,600 2025-08-29
Freepbx CRITICAL 9.8
CVE-2025-57819 KEVEPSS 88%

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-su…

Fix: 15.0.66 / 16.0.89+
Fix from $2,300 2025-08-28
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2025-7775 KEVEPSS 20%

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is conf…

Fix: 12.1-55.330 / 13.1-37.241+
Fix from $2,300 2025-08-26
Ipados CRITICAL 10.0
CVE-2025-43300 KEVEPSS 20%

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS…

Fix: 13.7.8 / 14.7.8+
Fix from $2,300 2025-08-21
N Central HIGH 8.8
CVE-2025-8876 KEV

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

Fix: 2025.3.1+
Fix from $1,950 2025-08-14
N Central HIGH 7.8
CVE-2025-8875 KEV

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

Fix: 2025.3.1+
Fix from $1,950 2025-08-14
Winrar HIGH 8.8
CVE-2025-8088 KEVEPSS 95%

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive f…

Fix: 7.13 / 2023.01+
Fix from $1,950 2025-08-08
Experience Manager Forms CRITICAL 10.0
CVE-2025-54253 KEVEPSS 88%

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. …

Fix: after 6.5.23.0
Fix from $2,300 2025-08-05
Apex One CRITICAL 9.8
CVE-2025-54948 KEVEPSS 21%

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and …

Patch available
Fix from $2,300 2025-08-05
Delmia Apriso CRITICAL 9.1
CVE-2025-6205 KEVEPSS 71%

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged acces…

Fix: 2025+
Fix from $2,300 2025-08-04
Delmia Apriso HIGH 8.0
CVE-2025-6204 KEVEPSS 76%

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow a…

Fix: after 2025
Fix from $1,950 2025-08-04
Safari HIGH 8.8
CVE-2025-31277 KEV

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, v…

Fix: 18.6+
Fix from $1,950 2025-07-30
Linux Kernel HIGH 7.8
CVE-2025-38352 KEV

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer…

Fix: 5.4.295 / 5.10.239+
Fix from $1,950 2025-07-22
Sharepoint Server CRITICAL 9.8
CVE-2025-53770 KEVEPSS 100%

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsof…

Fix: 16.0.18526.20508+
Fix from $2,300 2025-07-20
Eslint Config Prettier HIGH 7.5
CVE-2025-54313 KEV

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package ex…

Fix: 1.30.0+
Fix from $1,950 2025-07-19
Crushftp CRITICAL 9.8
CVE-2025-54309 KEVEPSS 94%

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote a…

Fix: 10.8.5 / 11.3.4_23+
Fix from $2,300 2025-07-18
Livewire CRITICAL 9.8
CVE-2025-54068 KEVEPSS 96%

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achiev…

Fix: 3.6.4+
Fix from $2,300 2025-07-17
Fortiweb CRITICAL 9.8
CVE-2025-25257 KEVEPSS 100%

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6…

Fix: 7.0.11 / 7.2.11+
Fix from $2,300 2025-07-17
Identity Services Engine CRITICAL 10.0
CVE-2025-20337 KEVEPSS 66%

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the und…

Mitigation only
Fix from $2,300 2025-07-16
Chrome HIGH 8.8
CVE-2025-6558 KEVEPSS 9%

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform…

Fix: 2.6 / 11.6+
Fix from $1,950 2025-07-15
Wing Ftp Server CRITICAL 10.0
CVE-2025-47812 KEVEPSS 95%

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into use…

Fix: 7.4.4+
Fix from $2,300 2025-07-10
Git HIGH 8.0
CVE-2025-48384 KEV

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acc…

Fix: 2.43.7 / 2.44.4+
Fix from $1,950 2025-07-08
Sharepoint Enterprise Server MEDIUM 6.5
CVE-2025-49706 KEVEPSS 100%

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.18526.20424+
Fix from $1,600 2025-07-08
Sharepoint Server HIGH 8.8
CVE-2025-49704 KEVEPSS 100%

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-07-08
Chrome HIGH 8.1
CVE-2025-6554 KEVEPSS 13%

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chro…

Fix: 138.0.7204.92 / 138.0.7204.96+
Fix from $1,950 2025-06-30
Ubuntu Linux HIGH 7.8
CVE-2025-32463 KEVEPSS 56%

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot o…

Fix: 1.9.17+
Fix from $1,950 2025-06-30
Identity Services Engine CRITICAL 10.0
CVE-2025-20281 KEVEPSS 97%

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the und…

Mitigation only
Fix from $2,300 2025-06-25
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2025-6543 KEVEPSS 10%

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gate…

Fix: 13.1-37.236 / 13.1-59.19+
Fix from $2,300 2025-06-25
Kace Systems Management Appliance CRITICAL 10.0
CVE-2025-32975 KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)…

Fix: 13.0.385 / 13.1.81+
Fix from $2,300 2025-06-24
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2025-48700 KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Clas…

Fix: 10.0.12 / 10.1.4+
Fix from $1,600 2025-06-23