Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2025-32432 KEVEPSS 100% Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.1… Craft Cms 3.9.15 / 4.14.15+ Fix from $2,3002025-04-25 CRITICAL 9.8 CVE-2025-31324 KEVEPSS 100% SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma… Netweaver Mitigation only Fix from $2,3002025-04-24 MEDIUM 6.7 CVE-2025-1976 KEV Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary… Fabric Operating System 9.1.1d7+ Fix from $1,6002025-04-24 CRITICAL 10.0 CVE-2025-34028 KEVEPSS 98% The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand… Commvault 11.38.20+ Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2025-42599 KEV Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request creat… Active\! Mail 6.60.05008562+ Fix from $2,3002025-04-18 CRITICAL 10.0 CVE-2025-32433 KEVEPSS 99% Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server ma… Confd Basic 5.7.19.1 / 6.1.16.2+ Fix from $2,3002025-04-16 CRITICAL 9.8 CVE-2025-31201 KEVEPSS 15% This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, vis… macOS 2.4.1 / 15.4.1+ Fix from $2,3002025-04-16 CRITICAL 9.8 CVE-2025-31200 KEVEPSS 20% A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvO… macOS 2.4.1 / 11.5+ Fix from $2,3002025-04-16 CRITICAL 9.8 CVE-2024-58136 KEVEPSS 85% Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wil… Yii 2.0.52+ Fix from $2,3002025-04-10 HIGH 7.8 CVE-2025-29824 KEVEPSS 14% Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 CRITICAL 9.8 CVE-2025-3248 KEVEPSS 100% Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can … Langflow 1.3.0+ Fix from $2,3002025-04-07 CRITICAL 9.8 CVE-2025-31161 KEVEPSS 100% CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is us… Crushftp 10.8.4 / 11.3.1+ Fix from $2,3002025-04-03 CRITICAL 9.8 CVE-2025-30406 KEVEPSS 94% Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcod… Centrestack 16.4.10315.56368+ Fix from $2,3002025-04-03 CRITICAL 9.8 CVE-2025-22457 KEVEPSS 100% A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways… Connect Secure 22.7 / 22.8+ Fix from $2,3002025-04-03 HIGH 7.5 CVE-2025-31125 KEVEPSS 59% Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explici… Vite 4.5.11 / 5.4.16+ Fix from $1,9502025-03-31 HIGH 8.3 CVE-2025-2783 KEVEPSS 8% Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perfo… Chrome 134.0.6998.177+ Fix from $1,9502025-03-26 HIGH 7.2 CVE-2025-29635 KEVEPSS 90% A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices … Dir 823x Firmware Mitigation only Fix from $1,9502025-03-25 HIGH 7.2 CVE-2025-2749 KEV An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative … Xperience after 13.0.178 Fix from $1,9502025-03-24 CRITICAL 9.8 CVE-2025-2747 KEVEPSS 92% An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for … Xperience after 13.0.178 Fix from $2,3002025-03-24 CRITICAL 9.8 CVE-2025-2746 KEVEPSS 58% An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 … Xperience after 13.0.172 Fix from $2,3002025-03-24 HIGH 8.6 CVE-2025-30154 KEV reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 … Action Ast Grep 0.20.2 / 1.17.2+ Fix from $1,9502025-03-19 HIGH 8.6 CVE-2025-30066 KEVEPSS 70% tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on… Changed Files after 45.0.7 Fix from $1,9502025-03-15 MEDIUM 5.4 CVE-2025-27915 KEV An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic … Zimbra Collaboration Suite 10.0.13 / 10.1.5+ Fix from $1,6002025-03-12 CRITICAL 10.0 CVE-2025-24201 KEV An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and… Safari 2.3.2 / 11.4+ Fix from $2,3002025-03-11 HIGH 7.0 CVE-2025-26633 KEVEPSS 30% Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24993 KEV Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 MEDIUM 5.5 CVE-2025-24991 KEV Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,6002025-03-11 HIGH 7.8 CVE-2025-24985 KEV Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 HIGH 7.0 CVE-2025-24983 KEV Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 MEDIUM 5.4 CVE-2025-24054 KEVEPSS 59% External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,6002025-03-11