Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.1 CVE-2025-68398 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i… Weblate 5.15.1+ Fix from $2,3002025-12-18 MEDIUM 6.1 CVE-2025-67163 A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injec… Simple Machines Forum Mitigation only Fix from $1,6002025-12-18 HIGH 7.5 CVE-2025-65561 An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via … Free5gc Patch available Fix from $1,9502025-12-18 CRITICAL 9.0 CVE-2025-67493 Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access … Homarr 1.45.3+ Fix from $2,3002025-12-17 MEDIUM 5.7 CVE-2025-43533 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.… Ipados 26.2+ Fix from $1,6002025-12-17 MEDIUM 6.1 CVE-2025-67170 A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser … Ritecms No fix yet Fix from $1,6002025-12-17 HIGH 7.2 CVE-2025-66923 A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitra… Open Source Point Of Sale No fix yet Fix from $1,9502025-12-17 HIGH 7.2 CVE-2025-66921 A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbi… Open Source Point Of Sale No fix yet Fix from $1,9502025-12-17 CRITICAL 10.0 CVE-2025-20393 KEVEPSS 30% A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could … Asyncos 15.0.2-007 / 15.0.5-016+ Fix from $2,3002025-12-17 HIGH 8.8 CVE-2025-58173 FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration par… Freshrss 1.27.1+ Fix from $1,9502025-12-16 CRITICAL 9.8 CVE-2025-14156EPSS 7% The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is … Mitigation only Fix from $2,3002025-12-15 MEDIUM 5.3 CVE-2025-9207 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plu… Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.0 CVE-2025-14606 A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the function pickle.loads of the file … Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.5 CVE-2025-43482 The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app ma… macOS 14.8.3 / 15.7.3+ Fix from $1,6002025-12-12 HIGH 7.5 CVE-2025-43494 A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS … Ipados 14.8.2 / 15.7.2+ Fix from $1,9502025-12-12 MEDIUM 6.5 CVE-2025-43464 A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.1. Visiting a website may lead to an ap… macOS 26.1+ Fix from $1,6002025-12-12 MEDIUM 6.5 CVE-2025-66451 LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modif… Librechat 0.8.1+ Fix from $1,6002025-12-11 MEDIUM 5.5 CVE-2025-36929 In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to local infor… Android Mitigation only Fix from $1,6002025-12-11 HIGH 7.8 CVE-2025-36932 In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This … Android Mitigation only Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-66918 edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter. Edoc Doctor Appointment System Patch available Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-64991 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior… Digital Employee Experience 15.0+ Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-64992 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction p… Digital Employee Experience 25.0+ Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-64993 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instruction… Digital Employee Experience 29.0+ Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-44016 A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows m… Digital Employee Experience 25.11+ Fix from $1,9502025-12-11 MEDIUM 6.5 CVE-2025-46266 A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows m… Digital Employee Experience 25.11+ Fix from $1,6002025-12-11 HIGH 7.2 CVE-2025-64986 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningO… Digital Employee Experience 21.0+ Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-64987 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC in… Digital Employee Experience 21.0+ Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-64988 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instructio… Digital Employee Experience 19.2+ Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-64989 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAnd… Digital Employee Experience 21.1+ Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-64990 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instru… Digital Employee Experience 21.1+ Fix from $1,9502025-12-11