Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Oneflow MEDIUM 6.5
CVE-2025-63397

Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during bro…

Patch available
Fix from $1,600 2025-11-10
Chrome HIGH 8.8
CVE-2025-12907

Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code vi…

Fix: 140.0.7339.80+
Fix from $1,950 2025-11-08
Chrome MEDIUM 5.4
CVE-2025-12908

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domai…

Fix: 140.0.7339.80+
Fix from $1,600 2025-11-08
Onlook MEDIUM 6.1
CVE-2025-63785

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occur…

No fix yet
Fix from $1,600 2025-11-07
Onlook HIGH 7.6
CVE-2025-63783

A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onl…

No fix yet
Fix from $1,950 2025-11-07
Ai MEDIUM 5.3
CVE-2025-48985

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filet…

Fix: 5.0.52+
Fix from $1,600 2025-11-07
Thinkdashboard MEDIUM 6.1
CVE-2025-64176

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an attacker can upload any file…

Fix: 0.6.8+
Fix from $1,600 2025-11-06
Unclassified HIGH 7.1
CVE-2025-61084

MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An attack…

Mitigation only
Fix from $1,950 2025-11-05
Secure Access HIGH 7.5
CVE-2025-59595

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a spec…

Fix: 14.12+
Fix from $1,950 2025-11-04
Secure Access MEDIUM 6.5
CVE-2025-59596

CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a…

Fix: 14.12+
Fix from $1,600 2025-11-04
Redis HIGH 8.8
CVE-2025-62507EPSS 7%

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's…

Fix: 8.2.3+
Fix from $1,950 2025-11-04
Exynos 1280 Firmware MEDIUM 6.5
CVE-2025-54327

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validati…

Mitigation only
Fix from $1,600 2025-11-04
macOS HIGH 7.8
CVE-2025-43472

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1…

Fix: 14.8.2 / 15.7.2+
Fix from $1,950 2025-11-04
macOS HIGH 7.5
CVE-2025-43401

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1.…

Fix: 14.8.2 / 15.7.2+
Fix from $1,950 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43348

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may …

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
Unclassified CRITICAL 9.2
CVE-2025-64385

The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the manufacturer’s software. Usin…

Mitigation only
Fix from $2,300 2025-10-31
Unclassified CRITICAL 9.1
CVE-2025-61235

An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields can contai…

No fix yet
Fix from $2,300 2025-10-28
Shiyi Blog CRITICAL 9.8
CVE-2025-12305

A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJ…

Fix: after 1.2.1
Fix from $2,300 2025-10-27
Trufusion Enterprise CRITICAL 9.8
CVE-2025-27224

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly saniti…

Fix: after 7.10.4.0
Fix from $2,300 2025-10-27
Blu Ic2 Firmware MEDIUM 6.5
CVE-2025-12278

Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Fix: 1.20+
Fix from $1,600 2025-10-26
Blu Ic2 Firmware MEDIUM 6.1
CVE-2025-12284

Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Fix: 1.20+
Fix from $1,600 2025-10-26
Blu Ic2 Firmware CRITICAL 9.8
CVE-2025-12285

Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Fix: 1.20+
Fix from $2,300 2025-10-26
Blu Ic2 Firmware CRITICAL 9.8
CVE-2025-12275

Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Fix: 1.20+
Fix from $2,300 2025-10-26
Emoncms HIGH 7.5
CVE-2025-60938

Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands…

No fix yet
Fix from $1,950 2025-10-24
Openwrt HIGH 8.8
CVE-2025-62525

OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel m…

Fix: 24.10.4+
Fix from $1,950 2025-10-22
Blu Ic2 Firmware MEDIUM 6.1
CVE-2025-12001

Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Fix: 1.20+
Fix from $1,600 2025-10-20
Exynos W920 Firmware HIGH 7.5
CVE-2025-26781

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14…

Mitigation only
Fix from $1,950 2025-10-20
Churchcrm HIGH 8.1
CVE-2025-11938

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipul…

Fix: after 5.18.0
Fix from $1,950 2025-10-19
Unclassified CRITICAL 9.4
CVE-2025-8414

Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corru…

Mitigation only
Fix from $2,300 2025-10-17
Unclassified MEDIUM 6.5
CVE-2025-60537

Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute arbitrary…

Mitigation only
Fix from $1,600 2025-10-14