Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Orangehrm HIGH 8.8
CVE-2025-66225

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the u…

Fix: 5.8+
Fix from $1,950 2025-11-29
Kiteworks HIGH 8.8
CVE-2025-53939

Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to une…

Fix: 9.1.0+
Fix from $1,950 2025-11-29
Librechat HIGH 8.1
CVE-2025-66201

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by …

Fix: 0.8.1+
Fix from $1,950 2025-11-29
Unclassified HIGH 8.7
CVE-2025-0658

A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; aft…

Mitigation only
Fix from $1,950 2025-11-27
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66259

Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions …

Mitigation only
Fix from $2,300 2025-11-26
Dgx Os MEDIUM 5.5
CVE-2025-33191

NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified HIGH 8.1
CVE-2025-0248

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, una…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified HIGH 7.7
CVE-2025-12740

A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a ma…

Mitigation only
Fix from $1,950 2025-11-24
Unclassified HIGH 7.7
CVE-2025-12741

A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malic…

Mitigation only
Fix from $1,950 2025-11-24
Wolfssl MEDIUM 5.4
CVE-2025-12889

With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.

Patch available
Fix from $1,600 2025-11-22
Roo Code HIGH 8.1
CVE-2025-65946

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possibl…

Fix: 3.26.7+
Fix from $1,950 2025-11-21
Wolfssl MEDIUM 6.5
CVE-2025-11933

Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated att…

Fix: 5.8.4+
Fix from $1,600 2025-11-21
Wolfssl MEDIUM 5.3
CVE-2025-11936

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to ca…

Fix: 5.8.4+
Fix from $1,600 2025-11-21
Vllm HIGH 8.8
CVE-2025-62164

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability co…

Fix: 0.11.1+
Fix from $1,950 2025-11-21
Unclassified HIGH 7.1
CVE-2025-11676

Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated adjacent attackers to perfor…

Mitigation only
Fix from $1,950 2025-11-20
Opera11 Firmware CRITICAL 9.8
CVE-2025-63213

The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the…

Mitigation only
Fix from $2,300 2025-11-19
Homarr MEDIUM 6.1
CVE-2025-64759

Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a use…

Fix: 1.43.3+
Fix from $1,600 2025-11-19
Unclassified MEDIUM 5.3
CVE-2025-12842

The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and inc…

Mitigation only
Fix from $1,600 2025-11-19
Rumpus CRITICAL 9.8
CVE-2025-55058

CWE-20 Improper Input Validation

No fix yet
Fix from $2,300 2025-11-17
Unclassified HIGH 8.8
CVE-2025-13319

An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL v…

Mitigation only
Fix from $1,950 2025-11-17
Unclassified CRITICAL 9.4
CVE-2025-10460

A SQL Injection vulnerability on an endpoint in BEIMS Contractor Web, a legacy product that is no longer maintained or patched by the vendor, allows …

Mitigation only
Fix from $2,300 2025-11-17
Directus MEDIUM 5.5
CVE-2025-64747

Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions…

Fix: 11.13.0+
Fix from $1,600 2025-11-13
Unclassified MEDIUM 5.3
CVE-2024-45301

Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to ac…

Mitigation only
Fix from $1,600 2025-11-12
Ceph HIGH 7.5
CVE-2024-47866

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put…

Fix: after 19.2.3
Fix from $1,950 2025-11-12
Github Copilot Chat HIGH 8.8
CVE-2025-62222

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz…

Fix: 0.32.5+
Fix from $1,950 2025-11-11
Quickassist Technology HIGH 8.8
CVE-2025-33000

Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of priv…

Fix: 2.6.0-0018+
Fix from $1,950 2025-11-11
Unclassified MEDIUM 5.6
CVE-2025-24512

Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a…

Mitigation only
Fix from $1,600 2025-11-11
Computing Improvement Program HIGH 8.8
CVE-2025-24299

Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation …

Fix: 2.4.11001+
Fix from $1,950 2025-11-11
R6260 Firmware HIGH 7.5
CVE-2025-12942

Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform …

Fix: 1.1.0.86+
Fix from $1,950 2025-11-11
Dgn2200 Firmware HIGH 8.8
CVE-2025-12944

Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network access to the device to poten…

Fix: 1.0.0.132+
Fix from $1,950 2025-11-11