Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2025-27363 KEVEPSS 28% An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font sub… Debian Linux after 2.13.0 Fix from $1,9502025-03-11 CRITICAL 9.8 CVE-2024-54085 KEVEPSS 61% AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful e… Megarac Sp X 12.7 / 13.5+ Fix from $2,3002025-03-11 CRITICAL 9.8 CVE-2025-24813 KEVEPSS 100% Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploade… Tomcat 9.0.99 / 10.1.35+ Fix from $2,3002025-03-10 CRITICAL 9.8 CVE-2025-1316 KEVEPSS 73% Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device Ic 7100 Firmware Mitigation only Fix from $2,3002025-03-05 MEDIUM 6.0 CVE-2025-22226 KEV VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with adm… Esxi 13.6.3 / 17.6.3+ Fix from $1,6002025-03-04 HIGH 8.2 CVE-2025-22225 KEV VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write… Esxi Mitigation only Fix from $1,9502025-03-04 HIGH 8.2 CVE-2025-22224 KEV VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with … Esxi 17.6.3+ Fix from $1,9502025-03-04 HIGH 8.6 CVE-2024-48248 KEVEPSS 94% NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to re… Backup \& Replication Director 11.0.0.88174+ Fix from $1,9502025-03-04 CRITICAL 9.8 CVE-2025-24893 KEVEPSS 100% XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code … Xwiki 15.10.11 / 16.4.1+ Fix from $2,3002025-02-20 CRITICAL 9.8 CVE-2025-24989 KEV An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th… Power Pages Patch available Fix from $2,3002025-02-19 MEDIUM 6.5 CVE-2025-0111 KEV An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the manag… Pan Os 10.1.14 / 10.2.7+ Fix from $1,6002025-02-12 CRITICAL 9.1 CVE-2025-0108 KEVEPSS 98% An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web inte… Pan Os 10.1.14 / 10.2.7+ Fix from $2,3002025-02-12 HIGH 7.8 CVE-2025-21418 KEV Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows 10 1607 10.0.10240.20915 / 10.0.17763.6893+ Fix from $1,9502025-02-11 HIGH 7.1 CVE-2025-21391 KEV Windows Storage Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,9502025-02-11 HIGH 8.1 CVE-2025-24472 KEV An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 throu… Fortiproxy 7.0.17 / 7.0.20+ Fix from $1,9502025-02-11 CRITICAL 9.9 CVE-2025-24016 KEVEPSS 94% Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, a… Wazuh 4.9.1+ Fix from $2,3002025-02-10 MEDIUM 6.1 CVE-2025-24200 KEV An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7… Ipados 15.8.4 / 16.7.11+ Fix from $1,6002025-02-10 HIGH 8.8 CVE-2025-0994 KEVEPSS 31% Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerabil… Cityworks 15.8.9 / 23.10+ Fix from $1,9502025-02-06 HIGH 8.8 CVE-2024-40891 KEVEPSS 22% **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B1… Vmg1312 B10a Firmware Mitigation only Fix from $1,9502025-02-04 HIGH 8.8 CVE-2024-40890 KEVEPSS 22% **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmw… Vmg1312 B10a Firmware Mitigation only Fix from $1,9502025-02-04 HIGH 8.8 CVE-2023-52163 KEVEPSS 97% Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer … Ds 2105 Pro Firmware Mitigation only Fix from $1,9502025-02-03 HIGH 7.5 CVE-2025-25181 KEVEPSS 51% A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands … Veracore 2025.1.1.3+ Fix from $1,9502025-02-03 HIGH 8.8 CVE-2024-57968 KEVEPSS 32% Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during w… Veracore 2024.4.2.1+ Fix from $1,9502025-02-03 CRITICAL 10.0 CVE-2025-24085 KEVEPSS 17% A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 1… Ipados 2.3 / 11.3+ Fix from $2,3002025-01-27 HIGH 7.0 CVE-2025-0411 KEVEPSS 67% 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected… Active Iq Unified Manager 24.09+ Fix from $1,9502025-01-25 CRITICAL 9.8 CVE-2025-23006 KEVEPSS 23% Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central … Sma8200v 12.4.3-02854+ Fix from $2,3002025-01-23 HIGH 8.1 CVE-2025-23209 KEV Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerab… Craft Cms 4.13.8 / 5.5.8+ Fix from $1,9502025-01-18 HIGH 7.2 CVE-2024-57728 KEVEPSS 7% SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted … Simplehelp 5.5.8+ Fix from $1,9502025-01-15 HIGH 7.5 CVE-2024-57727 KEVEPSS 95% SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote atta… Simplehelp 5.5.8+ Fix from $1,9502025-01-15 CRITICAL 9.9 CVE-2024-57726 KEVEPSS 67% SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive per… Simplehelp 5.5.8+ Fix from $2,3002025-01-15