Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Student Result Management System HIGH 7.5
CVE-2025-50490

Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to e…

No fix yet
Fix from $1,950 2025-07-28
Doctor Appointment Management System HIGH 7.5
CVE-2025-50493

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to …

Mitigation only
Fix from $1,950 2025-07-28
Car Washing Management System HIGH 7.5
CVE-2025-50494

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execu…

No fix yet
Fix from $1,950 2025-07-28
Chancms MEDIUM 6.3
CVE-2025-8266

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArti…

Fix: 3.1.3+
Fix from $1,600 2025-07-28
Chancms CRITICAL 9.8
CVE-2025-8227

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functio…

Fix: 3.1.3+
Fix from $2,300 2025-07-27
Unclassified MEDIUM 5.3
CVE-2025-8097

The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient …

Mitigation only
Fix from $1,600 2025-07-26
Xwiki CRITICAL 9.8
CVE-2025-54385

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions between 17.0.0-rc1 to 17.2.2 and…

Fix: 16.10.6+
Fix from $2,300 2025-07-26
Dsp W215 Firmware CRITICAL 9.8
CVE-2014-125117EPSS 5%

A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploi…

Mitigation only
Fix from $2,300 2025-07-25
Unclassified HIGH 8.4
CVE-2014-125119

A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the C…

Mitigation only
Fix from $1,950 2025-07-25
Unclassified HIGH 8.4
CVE-2014-125114

A stack-based buffer overflow vulnerability exists in i-Ftp version 2.20 due to improper handling of the Time attribute within Schedule.xml. By placi…

No fix yet
Fix from $1,950 2025-07-25
Fastapi Guard HIGH 7.5
CVE-2025-54365

fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In versi…

Patch available
Fix from $1,950 2025-07-23
Kyverno HIGH 7.7
CVE-2025-47281

Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerabilit…

Fix: 1.14.2+
Fix from $1,950 2025-07-23
Unclassified HIGH 8.1
CVE-2025-6585

The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.2 via the cs_remove_pro…

Mitigation only
Fix from $1,950 2025-07-22
Haxcms Nodejs MEDIUM 6.5
CVE-2025-54134

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application cr…

Fix: 11.0.9+
Fix from $1,600 2025-07-21
Jena HIGH 8.8
CVE-2025-50151

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to…

Fix: 5.5.0+
Fix from $1,950 2025-07-21
Metacrm CRITICAL 9.8
CVE-2025-7876

A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This vulnerability affects the function AnalyzeParam of th…

Fix: after 6.4.2
Fix from $2,300 2025-07-20
Unclassified HIGH 8.7
CVE-2025-34129

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient …

Mitigation only
Fix from $1,950 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-34132

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified HIGH 8.4
CVE-2025-34124

A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m m…

No fix yet
Fix from $1,950 2025-07-16
Unclassified HIGH 8.4
CVE-2025-34123

A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The …

No fix yet
Fix from $1,950 2025-07-16
Unclassified HIGH 8.7
CVE-2025-34118

A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS3000 builds, that allows unau…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified CRITICAL 10.0
CVE-2025-34300EPSS 51%

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Pe…

Mitigation only
Fix from $2,300 2025-07-16
Chrome HIGH 8.8
CVE-2025-6558 KEVEPSS 9%

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform…

Fix: 2.6 / 11.6+
Fix from $1,950 2025-07-15
Unclassified HIGH 8.7
CVE-2025-34116

A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated att…

No fix yet
Fix from $1,950 2025-07-15
Unclassified HIGH 8.7
CVE-2025-34113

An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET param…

No fix yet
Fix from $1,950 2025-07-15
Unclassified HIGH 8.7
CVE-2025-34115

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endp…

No fix yet
Fix from $1,950 2025-07-15
Unclassified CRITICAL 10.0
CVE-2025-34105

A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vuln…

Mitigation only
Fix from $2,300 2025-07-15
Unclassified HIGH 8.6
CVE-2025-34108

A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. An attacker can send a special…

No fix yet
Fix from $1,950 2025-07-15
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2025-34111

An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's defaul…

Fix: after 15.1
Fix from $2,300 2025-07-15
Edge Chromium MEDIUM 5.6
CVE-2025-47182

Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

Fix: 138.0.3351.55+
Fix from $1,600 2025-07-11