Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Iccdev MEDIUM 5.5
CVE-2026-21495

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,600 2026-01-07
Iccdev MEDIUM 5.5
CVE-2026-21496

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,600 2026-01-07
Iccdev MEDIUM 5.5
CVE-2026-21497

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,600 2026-01-07
Iccdev MEDIUM 5.5
CVE-2026-21498

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,600 2026-01-07
Iccdev MEDIUM 5.5
CVE-2026-21499

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,600 2026-01-07
Iccdev HIGH 7.8
CVE-2026-21500

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-07
Oai Cn5g Amf HIGH 7.5
CVE-2025-66786

OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSO…

Fix: after 2.0.1
Fix from $1,950 2026-01-07
Build Of Apache Camel CRITICAL 9.6
CVE-2025-12543

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr…

Fix: 2.2.39 / 2.3.21+
Fix from $2,300 2026-01-07
Iccdev HIGH 7.1
CVE-2026-21487

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have an Out-of-bounds Read, U…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-06
Iccdev HIGH 8.8
CVE-2026-21677

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have Undefined Behavior in its …

Fix: 2.3.1.1+
Fix from $1,950 2026-01-06
Iccdev HIGH 8.8
CVE-2026-21485

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined B…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-06
Iccdev CRITICAL 9.8
CVE-2026-21675

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulner…

Fix: 2.3.1.1+
Fix from $2,300 2026-01-06
Spinnaker MEDIUM 6.6
CVE-2025-61916

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-si…

Fix: 2025.1.6 / 2025.2.3+
Fix from $1,600 2026-01-05
Exynos 1330 Firmware HIGH 7.1
CVE-2025-52519

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Improper vali…

Mitigation only
Fix from $1,950 2026-01-05
Unclassified MEDIUM 6.3
CVE-2025-15453

A security vulnerability has been detected in milvus up to 2.6.7. This vulnerability affects the function expr.Exec of the file pkg/util/expr/expr.go…

Mitigation only
Fix from $1,600 2026-01-05
Pluxml HIGH 7.2
CVE-2025-15438

A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the co…

Fix: after 5.8.22
Fix from $1,950 2026-01-02
Titra CRITICAL 9.1
CVE-2025-69288

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule …

Fix: 0.99.49+
Fix from $2,300 2025-12-31
Eyoucms HIGH 8.8
CVE-2025-15375

A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the…

Fix: 1.7.8+
Fix from $1,950 2025-12-31
Unclassified MEDIUM 6.3
CVE-2025-15246

A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function FurySerializer.deserialize of…

Mitigation only
Fix from $1,600 2025-12-30
Dvp 12se11t Firmware HIGH 7.5
CVE-2025-15358

DVP-12SE11T - Denial of Service Vulnerability

Fix: 2.16+
Fix from $1,950 2025-12-30
Unclassified MEDIUM 5.0
CVE-2025-15222

A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSerialize…

Mitigation only
Fix from $1,600 2025-12-30
Unclassified MEDIUM 6.3
CVE-2025-69205

Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a302…

Mitigation only
Fix from $1,600 2025-12-29
Binutils HIGH 7.5
CVE-2025-66864

An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via craft…

No fix yet
Fix from $1,950 2025-12-29
Binutils HIGH 7.5
CVE-2025-66866

An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE fi…

No fix yet
Fix from $1,950 2025-12-29
Xno 8082r Firmware MEDIUM 5.4
CVE-2025-8075

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered th…

Fix: 2.23.00 / 2.24.00+
Fix from $1,600 2025-12-26
Xno 8082r Firmware HIGH 7.2
CVE-2025-52600

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a …

Fix: 2.24.00+
Fix from $1,950 2025-12-26
Unclassified CRITICAL 9.8
CVE-2025-8769

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an atta…

Mitigation only
Fix from $2,300 2025-12-24
Unclassified CRITICAL 9.9
CVE-2025-68667

Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows a remote, unauthenticated att…

Patch available
Fix from $2,300 2025-12-23
Xcomfort Ethernet Communication Interface HIGH 8.8
CVE-2025-59886

Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the dev…

Mitigation only
Fix from $1,950 2025-12-23
Dvp15mc11t Firmware HIGH 7.5
CVE-2025-59301

Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.

Fix: 1.16.0+
Fix from $1,950 2025-12-22