Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-60710 KEV Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges … Windows 11 24h2 10.0.26100.7392 / 10.0.26200.7392+ Fix from $1,9502025-11-11 CRITICAL 9.1 CVE-2025-12480 KEVEPSS 91% Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after se… Triofox 16.7.10368.56560+ Fix from $2,3002025-11-10 HIGH 7.2 CVE-2025-64328 KEVEPSS 85% FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestor… Filestore 17.0.3+ Fix from $1,9502025-11-07 HIGH 8.8 CVE-2023-43000 KEV A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.… Safari 13.5 / 15.8.7+ Fix from $1,9502025-11-05 CRITICAL 9.8 CVE-2025-11953 KEVEPSS 94% The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpo… React Native Community Cli 19.1.2+ Fix from $2,3002025-11-03 CRITICAL 9.8 CVE-2025-61757 KEVEPSS 88% Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12… Identity Manager Mitigation only Fix from $2,3002025-10-21 CRITICAL 9.8 CVE-2025-61932 KEV Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing … Lanscope Endpoint Manager 9.3.2.7 / 9.3.3.9+ Fix from $2,3002025-10-20 CRITICAL 9.8 CVE-2025-53521 KEV When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Softw… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $2,3002025-10-15 CRITICAL 9.8 CVE-2025-59287 KEVEPSS 100% Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.8524 / 10.0.17763.7922+ Fix from $2,3002025-10-14 HIGH 7.8 CVE-2025-59230 KEV Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-24990 KEVEPSS 6% Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an… Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.5 CVE-2025-61884 KEVEPSS 98% Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3… Configurator after 12.2.14 Fix from $1,9502025-10-12 HIGH 7.5 CVE-2025-11371 KEVEPSS 92% In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows … Centrestack 16.10.10408.56683+ Fix from $1,9502025-10-09 CRITICAL 9.8 CVE-2025-61882 KEVEPSS 100% Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that … Concurrent Processing after 12.2.14 Fix from $2,3002025-10-05 HIGH 7.8 CVE-2025-41244 KEVEPSS 8% VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privilege… Aria Operations 5.0.1 / 8.18.5+ Fix from $1,9502025-09-29 HIGH 8.6 CVE-2025-20362 KEVEPSS 87% Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Softwar… Adaptive Security Appliance Software 7.0.8.1 / 7.2.10.2+ Fix from $1,9502025-09-25 CRITICAL 9.9 CVE-2025-20333 KEVEPSS 40% A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (F… Adaptive Security Appliance Software 7.0.8.1 / 7.2.9+ Fix from $2,3002025-09-25 HIGH 7.7 CVE-2025-20352 KEVEPSS 39% A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:… Ios Xe Sd Wan Mitigation only Fix from $1,9502025-09-24 CRITICAL 9.8 CVE-2025-10585 KEVEPSS 5% Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… Chrome 140.0.7339.185+ Fix from $2,3002025-09-24 CRITICAL 9.8 CVE-2025-26399 KEVEPSS 88% SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exp… Web Help Desk after 12.8.6 Fix from $2,3002025-09-23 MEDIUM 6.1 CVE-2025-59689 KEV Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.… Email Security Gateway 5.0.31 / 5.1.20+ Fix from $1,6002025-09-19 CRITICAL 9.0 CVE-2025-48703 KEVEPSS 100% CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_tota… Webpanel 0.9.8.1205+ Fix from $2,3002025-09-19 CRITICAL 9.8 CVE-2025-10035 KEVEPSS 100% A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to… Goanywhere Managed File Transfer 7.6.3 / 7.8.4+ Fix from $2,3002025-09-18 CRITICAL 9.8 CVE-2025-9242 KEVEPSS 91% An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code… Fireware 12.5.13 / 12.11.4+ Fix from $2,3002025-09-17 CRITICAL 9.8 CVE-2025-21043 KEV Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. Android Mitigation only Fix from $2,3002025-09-12 CRITICAL 9.8 CVE-2025-21042 KEVEPSS 33% Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. Android Mitigation only Fix from $2,3002025-09-12 CRITICAL 9.1 CVE-2025-54236 KEVEPSS 95% Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vu… Commerce Mitigation only Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-48543 KEV In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to l… Android Patch available Fix from $1,9502025-09-04 CRITICAL 9.0 CVE-2025-53690 KEVEPSS 31% Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This iss… Experience Commerce after 9.0 Fix from $2,3002025-09-03 HIGH 7.2 CVE-2025-9377 KEVEPSS 12% The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) … Tl Wr841n Firmware 241108+ Fix from $1,9502025-08-29