Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2025-50490 Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to e… Student Result Management System No fix yet Fix from $1,9502025-07-28 HIGH 7.5 CVE-2025-50493 Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to … Doctor Appointment Management System Mitigation only Fix from $1,9502025-07-28 HIGH 7.5 CVE-2025-50494 Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execu… Car Washing Management System No fix yet Fix from $1,9502025-07-28 MEDIUM 6.3 CVE-2025-8266 A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArti… Chancms 3.1.3+ Fix from $1,6002025-07-28 CRITICAL 9.8 CVE-2025-8227 A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functio… Chancms 3.1.3+ Fix from $2,3002025-07-27 MEDIUM 5.3 CVE-2025-8097 The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient … Mitigation only Fix from $1,6002025-07-26 CRITICAL 9.8 CVE-2025-54385 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions between 17.0.0-rc1 to 17.2.2 and… Xwiki 16.10.6+ Fix from $2,3002025-07-26 CRITICAL 9.8 CVE-2014-125117EPSS 5% A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploi… Dsp W215 Firmware Mitigation only Fix from $2,3002025-07-25 HIGH 8.4 CVE-2014-125119 A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the C… Mitigation only Fix from $1,9502025-07-25 HIGH 8.4 CVE-2014-125114 A stack-based buffer overflow vulnerability exists in i-Ftp version 2.20 due to improper handling of the Time attribute within Schedule.xml. By placi… No fix yet Fix from $1,9502025-07-25 HIGH 7.5 CVE-2025-54365 fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In versi… Fastapi Guard Patch available Fix from $1,9502025-07-23 HIGH 7.7 CVE-2025-47281 Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerabilit… Kyverno 1.14.2+ Fix from $1,9502025-07-23 HIGH 8.1 CVE-2025-6585 The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.2 via the cs_remove_pro… Mitigation only Fix from $1,9502025-07-22 MEDIUM 6.5 CVE-2025-54134 HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application cr… Haxcms Nodejs 11.0.9+ Fix from $1,6002025-07-21 HIGH 8.8 CVE-2025-50151 File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to… Jena 5.5.0+ Fix from $1,9502025-07-21 CRITICAL 9.8 CVE-2025-7876 A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This vulnerability affects the function AnalyzeParam of th… Metacrm after 6.4.2 Fix from $2,3002025-07-20 HIGH 8.7 CVE-2025-34129 A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient … Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.3 CVE-2025-34132 A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field… Mitigation only Fix from $2,3002025-07-16 HIGH 8.4 CVE-2025-34124 A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m m… No fix yet Fix from $1,9502025-07-16 HIGH 8.4 CVE-2025-34123 A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The … No fix yet Fix from $1,9502025-07-16 HIGH 8.7 CVE-2025-34118 A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS3000 builds, that allows unau… Mitigation only Fix from $1,9502025-07-16 CRITICAL 10.0 CVE-2025-34300EPSS 51% A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Pe… Mitigation only Fix from $2,3002025-07-16 HIGH 8.8 CVE-2025-6558 KEVEPSS 9% Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform… Chrome 2.6 / 11.6+ Fix from $1,9502025-07-15 HIGH 8.7 CVE-2025-34116 A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated att… No fix yet Fix from $1,9502025-07-15 HIGH 8.7 CVE-2025-34113 An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET param… No fix yet Fix from $1,9502025-07-15 HIGH 8.7 CVE-2025-34115 An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endp… No fix yet Fix from $1,9502025-07-15 CRITICAL 10.0 CVE-2025-34105 A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vuln… Mitigation only Fix from $2,3002025-07-15 HIGH 8.6 CVE-2025-34108 A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. An attacker can send a special… No fix yet Fix from $1,9502025-07-15 CRITICAL 9.8 CVE-2025-34111 An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's defaul… Tikiwiki Cms\/groupware after 15.1 Fix from $2,3002025-07-15 MEDIUM 5.6 CVE-2025-47182 Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. Edge Chromium 138.0.3351.55+ Fix from $1,6002025-07-11