Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-66376 KEVEPSS 22% Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives… Zimbra Collaboration Suite 10.0.18 / 10.1.13+ Fix from $1,6002026-01-05 CRITICAL 10.0 CVE-2025-52691 KEVEPSS 85% Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po… Smartermail 100.0.9413+ Fix from $2,3002025-12-29 HIGH 8.8 CVE-2025-68645 KEVEPSS 32% A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling … Zimbra Collaboration Suite 10.0.18 / 10.1.13+ Fix from $1,9502025-12-22 HIGH 8.8 CVE-2025-68613 KEVEPSS 98% n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remo… N8n 1.120.4+ Fix from $1,9502025-12-19 HIGH 7.5 CVE-2025-14847 KEVEPSS 83% Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue a… MongoDB 4.4.30 / 5.0.32+ Fix from $1,9502025-12-19 CRITICAL 9.8 CVE-2025-14733 KEVEPSS 27% An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code… Fireware 12.5.15 / 12.11.6+ Fix from $2,3002025-12-19 MEDIUM 6.6 CVE-2025-40602 KEV A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). Sma6200 Firmware 12.4.3-03245 / 12.5.0-02283+ Fix from $1,6002025-12-18 MEDIUM 6.1 CVE-2025-68461 KEVEPSS 21% Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. Webmail 1.5.12 / 1.6.12+ Fix from $1,6002025-12-18 HIGH 8.8 CVE-2025-43529 KEVEPSS 9% A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and … Safari 18.7.3 / 26.2+ Fix from $1,9502025-12-17 CRITICAL 10.0 CVE-2025-20393 KEVEPSS 30% A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could … Asyncos 15.0.2-007 / 15.0.5-016+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-59374 KEV "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a sup… Live Update 3.6.8+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-37164 KEVEPSS 90% A remote code execution issue exists in HPE OneView. Oneview after 10.20.00 Fix from $2,3002025-12-16 MEDIUM 5.5 CVE-2025-43520 KEV A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1,… Ipados 14.8.2 / 15.7.2+ Fix from $1,6002025-12-12 HIGH 7.8 CVE-2025-43510 KEV A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 2… Ipados 14.8.2 / 15.7.2+ Fix from $1,9502025-12-12 CRITICAL 9.8 CVE-2025-14611 KEVEPSS 53% Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degr… Centrestack 16.12.10420.56791+ Fix from $2,3002025-12-12 HIGH 8.8 CVE-2025-14174 KEVEPSS 23% Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access… Chrome 18.7.3 / 26.2+ Fix from $1,9502025-12-12 HIGH 8.8 CVE-2025-8110 KEVEPSS 83% Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. Gogs after 0.13.3 Fix from $1,9502025-12-10 HIGH 7.8 CVE-2025-62221 KEV Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8146 / 10.0.19044.6691+ Fix from $1,9502025-12-09 CRITICAL 9.8 CVE-2025-59718 KEVEPSS 63% A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 … Fortiproxy 7.0.6 / 7.0.18+ Fix from $2,3002025-12-09 MEDIUM 5.5 CVE-2025-48633 KEV In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in … Android Patch available Fix from $1,6002025-12-08 HIGH 7.8 CVE-2025-48572 KEV In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalat… Android Mitigation only Fix from $1,9502025-12-08 HIGH 8.8 CVE-2025-34291 KEVEPSS 84% Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permis… Langflow after 1.6.9 Fix from $1,9502025-12-05 CRITICAL 9.8 CVE-2025-66644 KEV Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. Arrayos Ag 9.4.5.9+ Fix from $2,3002025-12-05 CRITICAL 10.0 CVE-2025-55182 KEVEPSS 100% A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the … React 15.0.5 / 15.1.9+ Fix from $2,3002025-12-03 HIGH 8.8 CVE-2025-62593 KEV Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabi… Ray Patch available Fix from $1,9502025-11-26 CRITICAL 9.8 CVE-2025-58360 KEVEPSS 65% GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XM… Geoserver 2.25.6 / 2.26.2+ Fix from $2,3002025-11-25 HIGH 7.2 CVE-2025-58034 KEVEPSS 56% An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiW… Fortiweb 7.0.12 / 7.2.12+ Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-13223 KEVEPSS 5% Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… Chrome 142.0.7444.175+ Fix from $1,9502025-11-17 CRITICAL 9.8 CVE-2025-64446 KEVEPSS 92% A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWe… Fortiweb 7.0.12 / 7.2.12+ Fix from $2,3002025-11-14 HIGH 7.0 CVE-2025-62215 KEVEPSS 6% Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat… Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,9502025-11-11