Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zimbra Collaboration Suite MEDIUM 6.1
CVE-2025-48700 KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Clas…

Fix: 10.0.12 / 10.1.4+
Fix from $1,600 2025-06-23
Winrar HIGH 7.8
CVE-2025-6218 KEVEPSS 89%

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…

Fix: 7.12+
Fix from $1,950 2025-06-21
Netscaler Application Delivery Controller HIGH 7.5
CVE-2025-5777 KEVEPSS 100%

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Prox…

Fix: 12.1-55.328 / 13.1-37.235+
Fix from $1,950 2025-06-17
Windows 10 1507 HIGH 8.8
CVE-2025-33073 KEVEPSS 80%

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Windows 10 1507 HIGH 8.8
CVE-2025-33053 KEVEPSS 85%

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Aqt1000 Firmware HIGH 8.6
CVE-2025-21479 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

No fix yet
Fix from $1,950 2025-06-03
Ar8031 Firmware HIGH 7.5
CVE-2025-27038 KEV

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

Mitigation only
Fix from $1,950 2025-06-03
Aqt1000 Firmware HIGH 8.6
CVE-2025-21480 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Mitigation only
Fix from $1,950 2025-06-03
Chrome HIGH 8.8
CVE-2025-5419 KEVEPSS 8%

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 137.0.3296.62 / 137.0.7151.68+
Fix from $1,950 2025-06-03
Delmia Apriso CRITICAL 9.0
CVE-2025-5086 KEVEPSS 90%

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code executio…

Fix: after 2025
Fix from $2,300 2025-06-02
Debian Linux HIGH 8.8
CVE-2025-49113 KEVEPSS 98%

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…

Fix: 1.5.10 / 1.6.11+
Fix from $1,950 2025-06-02
Telemessage MEDIUM 5.3
CVE-2025-48927 KEVEPSS 9%

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the…

Mitigation only
Fix from $1,600 2025-05-28
Concerto HIGH 7.5
CVE-2025-34026 KEVEPSS 83%

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at at…

Fix: 12.1.2+
Fix from $1,950 2025-05-21
Meteobridge Vm HIGH 8.8
CVE-2025-4008 KEVEPSS 94%

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system thro…

Fix: 6.2+
Fix from $1,950 2025-05-21
Windows 10 1507 HIGH 7.8
CVE-2025-32709 KEV

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows 10 1507 HIGH 7.8
CVE-2025-32706 KEV

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows 10 1507 HIGH 7.8
CVE-2025-32701 KEV

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows 10 1809 HIGH 7.8
CVE-2025-30400 KEV

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7314 / 10.0.19044.5854+
Fix from $1,950 2025-05-13
Windows 10 1507 HIGH 7.5
CVE-2025-30397 KEVEPSS 27%

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a ne…

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Endpoint Manager Mobile HIGH 8.8
CVE-2025-4428 KEVEPSS 86%

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t…

Fix: 11.12.0.5 / 12.3.0.2+
Fix from $1,950 2025-05-13
Endpoint Manager Mobile HIGH 7.5
CVE-2025-4427 KEVEPSS 100%

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources wit…

Fix: 11.12.0.5 / 12.3.0.2+
Fix from $1,950 2025-05-13
Fortimail CRITICAL 9.8
CVE-2025-32756 KEVEPSS 30%

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiC…

Fix: 6.4.6 / 6.4.11+
Fix from $2,300 2025-05-13
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-4632 KEVEPSS 24%

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to wr…

Fix: 21.1052.0+
Fix from $2,300 2025-05-13
Netweaver CRITICAL 9.1
CVE-2025-42999 KEVEPSS 12%

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ…

Mitigation only
Fix from $2,300 2025-05-13
Craft Cms MEDIUM 5.3
CVE-2025-35939 KEV

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an…

Fix: 4.15.3 / 5.7.5+
Fix from $1,600 2025-05-07
Sysaid CRITICAL 9.8
CVE-2025-2776 KEVEPSS 64%

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing function…

Fix: after 23.3.40
Fix from $2,300 2025-05-07
Sysaid HIGH 7.5
CVE-2025-2775 KEVEPSS 43%

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionali…

Fix: after 23.3.40
Fix from $1,950 2025-05-07
Output Messenger HIGH 8.8
CVE-2025-27920 KEV

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in paramete…

Fix: 2.0.63+
Fix from $1,950 2025-05-05
Screenconnect HIGH 7.2
CVE-2025-3935 KEV

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preser…

Fix: 25.2.4+
Fix from $1,950 2025-04-25
Commvault HIGH 8.8
CVE-2025-3928 KEV

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:…

Fix: 11.20.217 / 11.28.141+
Fix from $1,950 2025-04-25