Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-55177 KEV Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, a… Whatsapp 2.25.21.73 / 2.25.21.78+ Fix from $1,6002025-08-29 CRITICAL 9.8 CVE-2025-57819 KEVEPSS 88% FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-su… Freepbx 15.0.66 / 16.0.89+ Fix from $2,3002025-08-28 CRITICAL 9.8 CVE-2025-7775 KEVEPSS 20% Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is conf… Netscaler Application Delivery Controller 12.1-55.330 / 13.1-37.241+ Fix from $2,3002025-08-26 CRITICAL 10.0 CVE-2025-43300 KEVEPSS 20% An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS… Ipados 13.7.8 / 14.7.8+ Fix from $2,3002025-08-21 HIGH 8.8 CVE-2025-8876 KEV Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. N Central 2025.3.1+ Fix from $1,9502025-08-14 HIGH 7.8 CVE-2025-8875 KEV Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. N Central 2025.3.1+ Fix from $1,9502025-08-14 HIGH 8.8 CVE-2025-8088 KEVEPSS 95% A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive f… Winrar 7.13 / 2023.01+ Fix from $1,9502025-08-08 CRITICAL 10.0 CVE-2025-54253 KEVEPSS 88% Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. … Experience Manager Forms after 6.5.23.0 Fix from $2,3002025-08-05 CRITICAL 9.8 CVE-2025-54948 KEVEPSS 21% A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and … Apex One Patch available Fix from $2,3002025-08-05 CRITICAL 9.1 CVE-2025-6205 KEVEPSS 71% A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged acces… Delmia Apriso 2025+ Fix from $2,3002025-08-04 HIGH 8.0 CVE-2025-6204 KEVEPSS 76% An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow a… Delmia Apriso after 2025 Fix from $1,9502025-08-04 HIGH 8.8 CVE-2025-31277 KEV The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, v… Safari 18.6+ Fix from $1,9502025-07-30 HIGH 7.8 CVE-2025-38352 KEV In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer… Linux Kernel 5.4.295 / 5.10.239+ Fix from $1,9502025-07-22 CRITICAL 9.8 CVE-2025-53770 KEVEPSS 100% Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsof… Sharepoint Server 16.0.18526.20508+ Fix from $2,3002025-07-20 HIGH 7.5 CVE-2025-54313 KEV eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package ex… Eslint Config Prettier 1.30.0+ Fix from $1,9502025-07-19 CRITICAL 9.8 CVE-2025-54309 KEVEPSS 94% CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote a… Crushftp 10.8.5 / 11.3.4_23+ Fix from $2,3002025-07-18 CRITICAL 9.8 CVE-2025-54068 KEVEPSS 96% Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achiev… Livewire 3.6.4+ Fix from $2,3002025-07-17 CRITICAL 9.8 CVE-2025-25257 KEVEPSS 100% An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6… Fortiweb 7.0.11 / 7.2.11+ Fix from $2,3002025-07-17 CRITICAL 10.0 CVE-2025-20337 KEVEPSS 66% A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the und… Identity Services Engine Mitigation only Fix from $2,3002025-07-16 HIGH 8.8 CVE-2025-6558 KEVEPSS 9% Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform… Chrome 2.6 / 11.6+ Fix from $1,9502025-07-15 CRITICAL 10.0 CVE-2025-47812 KEVEPSS 95% In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into use… Wing Ftp Server 7.4.4+ Fix from $2,3002025-07-10 HIGH 8.0 CVE-2025-48384 KEV Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acc… Git 2.43.7 / 2.44.4+ Fix from $1,9502025-07-08 MEDIUM 6.5 CVE-2025-49706 KEVEPSS 100% Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Sharepoint Enterprise Server 16.0.18526.20424+ Fix from $1,6002025-07-08 HIGH 8.8 CVE-2025-49704 KEVEPSS 100% Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server Mitigation only Fix from $1,9502025-07-08 HIGH 8.1 CVE-2025-6554 KEVEPSS 13% Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chro… Chrome 138.0.7204.92 / 138.0.7204.96+ Fix from $1,9502025-06-30 HIGH 7.8 CVE-2025-32463 KEVEPSS 56% Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot o… Ubuntu Linux 1.9.17+ Fix from $1,9502025-06-30 CRITICAL 10.0 CVE-2025-20281 KEVEPSS 97% A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the und… Identity Services Engine Mitigation only Fix from $2,3002025-06-25 CRITICAL 9.8 CVE-2025-6543 KEVEPSS 10% Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gate… Netscaler Application Delivery Controller 13.1-37.236 / 13.1-59.19+ Fix from $2,3002025-06-25 CRITICAL 10.0 CVE-2025-32975 KEV Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)… Kace Systems Management Appliance 13.0.385 / 13.1.81+ Fix from $2,3002025-06-24 MEDIUM 6.1 CVE-2025-48700 KEV An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Clas… Zimbra Collaboration Suite 10.0.12 / 10.1.4+ Fix from $1,6002025-06-23