Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2025-66225 OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the u… Orangehrm 5.8+ Fix from $1,9502025-11-29 HIGH 8.8 CVE-2025-53939 Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to une… Kiteworks 9.1.0+ Fix from $1,9502025-11-29 HIGH 8.1 CVE-2025-66201 LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by … Librechat 0.8.1+ Fix from $1,9502025-11-29 HIGH 8.7 CVE-2025-0658 A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; aft… Mitigation only Fix from $1,9502025-11-27 CRITICAL 9.8 CVE-2025-66259 Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions … Mozart Next 100 Firmware Mitigation only Fix from $2,3002025-11-26 MEDIUM 5.5 CVE-2025-33191 NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this… Dgx Os Mitigation only Fix from $1,6002025-11-25 HIGH 8.1 CVE-2025-0248 HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, una… Mitigation only Fix from $1,9502025-11-25 HIGH 7.7 CVE-2025-12740 A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a ma… Mitigation only Fix from $1,9502025-11-24 HIGH 7.7 CVE-2025-12741 A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malic… Mitigation only Fix from $1,9502025-11-24 MEDIUM 5.4 CVE-2025-12889 With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest. Wolfssl Patch available Fix from $1,6002025-11-22 HIGH 8.1 CVE-2025-65946 Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possibl… Roo Code 3.26.7+ Fix from $1,9502025-11-21 MEDIUM 6.5 CVE-2025-11933 Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated att… Wolfssl 5.8.4+ Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-11936 Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to ca… Wolfssl 5.8.4+ Fix from $1,6002025-11-21 HIGH 8.8 CVE-2025-62164 vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability co… Vllm 0.11.1+ Fix from $1,9502025-11-21 HIGH 7.1 CVE-2025-11676 Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated adjacent attackers to perfor… Mitigation only Fix from $1,9502025-11-20 CRITICAL 9.8 CVE-2025-63213 The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the… Opera11 Firmware Mitigation only Fix from $2,3002025-11-19 MEDIUM 6.1 CVE-2025-64759 Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a use… Homarr 1.43.3+ Fix from $1,6002025-11-19 MEDIUM 5.3 CVE-2025-12842 The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and inc… Mitigation only Fix from $1,6002025-11-19 CRITICAL 9.8 CVE-2025-55058 CWE-20 Improper Input Validation Rumpus No fix yet Fix from $2,3002025-11-17 HIGH 8.8 CVE-2025-13319 An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL v… Mitigation only Fix from $1,9502025-11-17 CRITICAL 9.4 CVE-2025-10460 A SQL Injection vulnerability on an endpoint in BEIMS Contractor Web, a legacy product that is no longer maintained or patched by the vendor, allows … Mitigation only Fix from $2,3002025-11-17 MEDIUM 5.5 CVE-2025-64747 Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions… Directus 11.13.0+ Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2024-45301 Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to ac… Mitigation only Fix from $1,6002025-11-12 HIGH 7.5 CVE-2024-47866 Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put… Ceph after 19.2.3 Fix from $1,9502025-11-12 HIGH 8.8 CVE-2025-62222 Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz… Github Copilot Chat 0.32.5+ Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-33000 Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of priv… Quickassist Technology 2.6.0-0018+ Fix from $1,9502025-11-11 MEDIUM 5.6 CVE-2025-24512 Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a… Mitigation only Fix from $1,6002025-11-11 HIGH 8.8 CVE-2025-24299 Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation … Computing Improvement Program 2.4.11001+ Fix from $1,9502025-11-11 HIGH 7.5 CVE-2025-12942 Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform … R6260 Firmware 1.1.0.86+ Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-12944 Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network access to the device to poten… Dgn2200 Firmware 1.0.0.132+ Fix from $1,9502025-11-11