Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Weblate CRITICAL 9.1
CVE-2025-68398

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i…

Fix: 5.15.1+
Fix from $2,300 2025-12-18
Simple Machines Forum MEDIUM 6.1
CVE-2025-67163

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injec…

Mitigation only
Fix from $1,600 2025-12-18
Free5gc HIGH 7.5
CVE-2025-65561

An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via …

Patch available
Fix from $1,950 2025-12-18
Homarr CRITICAL 9.0
CVE-2025-67493

Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access …

Fix: 1.45.3+
Fix from $2,300 2025-12-17
Ipados MEDIUM 5.7
CVE-2025-43533

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.…

Fix: 26.2+
Fix from $1,600 2025-12-17
Ritecms MEDIUM 6.1
CVE-2025-67170

A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser …

No fix yet
Fix from $1,600 2025-12-17
Open Source Point Of Sale HIGH 7.2
CVE-2025-66923

A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitra…

No fix yet
Fix from $1,950 2025-12-17
Open Source Point Of Sale HIGH 7.2
CVE-2025-66921

A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbi…

No fix yet
Fix from $1,950 2025-12-17
Asyncos CRITICAL 10.0
CVE-2025-20393 KEVEPSS 30%

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could …

Fix: 15.0.2-007 / 15.0.5-016+
Fix from $2,300 2025-12-17
Freshrss HIGH 8.8
CVE-2025-58173

FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration par…

Fix: 1.27.1+
Fix from $1,950 2025-12-16
Unclassified CRITICAL 9.8
CVE-2025-14156EPSS 7%

The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is …

Mitigation only
Fix from $2,300 2025-12-15
Unclassified MEDIUM 5.3
CVE-2025-9207

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plu…

Mitigation only
Fix from $1,600 2025-12-13
Unclassified MEDIUM 5.0
CVE-2025-14606

A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the function pickle.loads of the file …

Mitigation only
Fix from $1,600 2025-12-13
macOS MEDIUM 5.5
CVE-2025-43482

The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app ma…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
Ipados HIGH 7.5
CVE-2025-43494

A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS …

Fix: 14.8.2 / 15.7.2+
Fix from $1,950 2025-12-12
macOS MEDIUM 6.5
CVE-2025-43464

A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.1. Visiting a website may lead to an ap…

Fix: 26.1+
Fix from $1,600 2025-12-12
Librechat MEDIUM 6.5
CVE-2025-66451

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modif…

Fix: 0.8.1+
Fix from $1,600 2025-12-11
Android MEDIUM 5.5
CVE-2025-36929

In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to local infor…

Mitigation only
Fix from $1,600 2025-12-11
Android HIGH 7.8
CVE-2025-36932

In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This …

Mitigation only
Fix from $1,950 2025-12-11
Edoc Doctor Appointment System HIGH 8.8
CVE-2025-66918

edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.

Patch available
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64991

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior…

Fix: 15.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64992

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction p…

Fix: 25.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64993

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instruction…

Fix: 29.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 8.8
CVE-2025-44016

A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows m…

Fix: 25.11+
Fix from $1,950 2025-12-11
Digital Employee Experience MEDIUM 6.5
CVE-2025-46266

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows m…

Fix: 25.11+
Fix from $1,600 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64986

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningO…

Fix: 21.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64987

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC in…

Fix: 21.0+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64988

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instructio…

Fix: 19.2+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64989

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAnd…

Fix: 21.1+
Fix from $1,950 2025-12-11
Digital Employee Experience HIGH 7.2
CVE-2025-64990

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instru…

Fix: 21.1+
Fix from $1,950 2025-12-11