Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Agilebpm HIGH 8.8
CVE-2025-5680

A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerabili…

Fix: after 2.5.0
Fix from $1,950 2025-06-05
Agilebpm HIGH 8.8
CVE-2025-5679

A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the functio…

Fix: after 2.5.0
Fix from $1,950 2025-06-05
Unclassified HIGH 8.9
CVE-2025-1701

CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by sending a specially crafted …

Mitigation only
Fix from $1,950 2025-06-04
Chestnutcms HIGH 8.8
CVE-2025-5552

A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknown code of the file /dev-api/g…

No fix yet
Fix from $1,950 2025-06-04
Phpwcms HIGH 7.2
CVE-2025-5498

A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/i…

Fix: 1.9.46 / 1.10.9+
Fix from $1,950 2025-06-03
Phpwcms CRITICAL 9.8
CVE-2025-5499

A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the f…

Fix: 1.9.46 / 1.10.9+
Fix from $2,300 2025-06-03
Phpwcms CRITICAL 9.8
CVE-2025-5497

A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_…

Fix: 1.10.8+
Fix from $2,300 2025-06-03
Unclassified HIGH 8.4
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in use…

Mitigation only
Fix from $1,950 2025-06-02
Vllm MEDIUM 6.5
CVE-2025-48944

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the …

Fix: 0.9.0+
Fix from $1,600 2025-05-30
Unclassified MEDIUM 6.6
CVE-2025-4635

A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to obtain remote code execution …

Mitigation only
Fix from $1,600 2025-05-30
Unclassified MEDIUM 6.6
CVE-2025-48490

Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined fo…

Patch available
Fix from $1,600 2025-05-30
Adp Application Developer Platform HIGH 8.8
CVE-2025-5326

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Aff…

Mitigation only
Fix from $1,950 2025-05-29
Unclassified HIGH 8.8
CVE-2024-51392

An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component

Mitigation only
Fix from $1,950 2025-05-29
Aptio V MEDIUM 6.1
CVE-2025-33043

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerabili…

Fix: 5.011+
Fix from $1,600 2025-05-29
Redis CRITICAL 9.8
CVE-2025-27151

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi…

Fix: 7.2.9 / 7.4.4+
Fix from $2,300 2025-05-29
Label Studio Ml Backend HIGH 7.8
CVE-2025-5173

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. A…

Fix: after 2024-09-30
Fix from $1,950 2025-05-26
Pypickle HIGH 7.8
CVE-2025-5174

A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pyp…

Fix: 2.0.0+
Fix from $1,950 2025-05-26
Unclassified MEDIUM 5.3
CVE-2025-5148

A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is…

Patch available
Fix from $1,600 2025-05-25
Zentao CRITICAL 9.1
CVE-2025-5114

A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the fi…

No fix yet
Fix from $2,300 2025-05-23
Unclassified MEDIUM 6.9
CVE-2025-41378

The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend …

Mitigation only
Fix from $1,600 2025-05-23
Unclassified MEDIUM 6.3
CVE-2025-41379

The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rul…

Mitigation only
Fix from $1,600 2025-05-23
Innovation HIGH 7.8
CVE-2024-40458

An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.

No fix yet
Fix from $1,950 2025-05-22
Unclassified HIGH 8.8
CVE-2024-25010

Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where improper input validation could …

Mitigation only
Fix from $1,950 2025-05-22
Harman Mgu21 Firmware MEDIUM 6.5
CVE-2025-3885

Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to crea…

Mitigation only
Fix from $1,600 2025-05-22
Yandex Browser HIGH 7.5
CVE-2021-25255

Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.

Fix: 21.1.0+
Fix from $1,950 2025-05-21
Gardener CRITICAL 9.9
CVE-2025-47283

Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener p…

Fix: 1.116.4 / 1.117.5+
Fix from $2,300 2025-05-19
Unclassified CRITICAL 9.9
CVE-2025-47282

Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security vulnerability was discovered i…

Mitigation only
Fix from $2,300 2025-05-19
Basestation CRITICAL 9.8
CVE-2025-4905

A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the function load_qc_pickl of the …

Fix: after 3.0.4
Fix from $2,300 2025-05-19
Unclassified HIGH 8.6
CVE-2025-2305

A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitra…

Mitigation only
Fix from $1,950 2025-05-16
Unclassified HIGH 7.5
CVE-2024-53827

Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially crafted messages may cause servi…

Mitigation only
Fix from $1,950 2025-05-16