Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Craft Cms CRITICAL 10.0
CVE-2025-32432 KEVEPSS 100%

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.1…

Fix: 3.9.15 / 4.14.15+
Fix from $2,300 2025-04-25
Netweaver CRITICAL 9.8
CVE-2025-31324 KEVEPSS 100%

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma…

Mitigation only
Fix from $2,300 2025-04-24
Fabric Operating System MEDIUM 6.7
CVE-2025-1976 KEV

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary…

Fix: 9.1.1d7+
Fix from $1,600 2025-04-24
Commvault CRITICAL 10.0
CVE-2025-34028 KEVEPSS 98%

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand…

Fix: 11.38.20+
Fix from $2,300 2025-04-22
Active\! Mail CRITICAL 9.8
CVE-2025-42599 KEV

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request creat…

Fix: 6.60.05008562+
Fix from $2,300 2025-04-18
Confd Basic CRITICAL 10.0
CVE-2025-32433 KEVEPSS 99%

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server ma…

Fix: 5.7.19.1 / 6.1.16.2+
Fix from $2,300 2025-04-16
macOS CRITICAL 9.8
CVE-2025-31201 KEVEPSS 15%

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, vis…

Fix: 2.4.1 / 15.4.1+
Fix from $2,300 2025-04-16
macOS CRITICAL 9.8
CVE-2025-31200 KEVEPSS 20%

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvO…

Fix: 2.4.1 / 11.5+
Fix from $2,300 2025-04-16
Yii CRITICAL 9.8
CVE-2024-58136 KEVEPSS 85%

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wil…

Fix: 2.0.52+
Fix from $2,300 2025-04-10
Windows 10 1507 HIGH 7.8
CVE-2025-29824 KEVEPSS 14%

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Langflow CRITICAL 9.8
CVE-2025-3248 KEVEPSS 100%

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can …

Fix: 1.3.0+
Fix from $2,300 2025-04-07
Crushftp CRITICAL 9.8
CVE-2025-31161 KEVEPSS 100%

CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is us…

Fix: 10.8.4 / 11.3.1+
Fix from $2,300 2025-04-03
Centrestack CRITICAL 9.8
CVE-2025-30406 KEVEPSS 94%

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcod…

Fix: 16.4.10315.56368+
Fix from $2,300 2025-04-03
Connect Secure CRITICAL 9.8
CVE-2025-22457 KEVEPSS 100%

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways…

Fix: 22.7 / 22.8+
Fix from $2,300 2025-04-03
Vite HIGH 7.5
CVE-2025-31125 KEVEPSS 59%

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explici…

Fix: 4.5.11 / 5.4.16+
Fix from $1,950 2025-03-31
Chrome HIGH 8.3
CVE-2025-2783 KEVEPSS 8%

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perfo…

Fix: 134.0.6998.177+
Fix from $1,950 2025-03-26
Dir 823x Firmware HIGH 7.2
CVE-2025-29635 KEVEPSS 90%

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices …

Mitigation only
Fix from $1,950 2025-03-25
Xperience HIGH 7.2
CVE-2025-2749 KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative …

Fix: after 13.0.178
Fix from $1,950 2025-03-24
Xperience CRITICAL 9.8
CVE-2025-2747 KEVEPSS 92%

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for …

Fix: after 13.0.178
Fix from $2,300 2025-03-24
Xperience CRITICAL 9.8
CVE-2025-2746 KEVEPSS 58%

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 …

Fix: after 13.0.172
Fix from $2,300 2025-03-24
Action Ast Grep HIGH 8.6
CVE-2025-30154 KEV

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 …

Fix: 0.20.2 / 1.17.2+
Fix from $1,950 2025-03-19
Changed Files HIGH 8.6
CVE-2025-30066 KEVEPSS 70%

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on…

Fix: after 45.0.7
Fix from $1,950 2025-03-15
Zimbra Collaboration Suite MEDIUM 5.4
CVE-2025-27915 KEV

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic …

Fix: 10.0.13 / 10.1.5+
Fix from $1,600 2025-03-12
Safari CRITICAL 10.0
CVE-2025-24201 KEV

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and…

Fix: 2.3.2 / 11.4+
Fix from $2,300 2025-03-11
Windows 10 1507 HIGH 7.0
CVE-2025-26633 KEVEPSS 30%

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,950 2025-03-11
Windows 10 1507 HIGH 7.8
CVE-2025-24993 KEV

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,950 2025-03-11
Windows 10 1507 MEDIUM 5.5
CVE-2025-24991 KEV

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,600 2025-03-11
Windows 10 1507 HIGH 7.8
CVE-2025-24985 KEV

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,950 2025-03-11
Windows 10 1507 HIGH 7.0
CVE-2025-24983 KEV

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,950 2025-03-11
Windows 10 1507 MEDIUM 5.4
CVE-2025-24054 KEVEPSS 59%

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,600 2025-03-11