Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2025-5680 A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerabili… Agilebpm after 2.5.0 Fix from $1,9502025-06-05 HIGH 8.8 CVE-2025-5679 A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the functio… Agilebpm after 2.5.0 Fix from $1,9502025-06-05 HIGH 8.9 CVE-2025-1701 CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by sending a specially crafted … Mitigation only Fix from $1,9502025-06-04 HIGH 8.8 CVE-2025-5552 A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknown code of the file /dev-api/g… Chestnutcms No fix yet Fix from $1,9502025-06-04 HIGH 7.2 CVE-2025-5498 A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/i… Phpwcms 1.9.46 / 1.10.9+ Fix from $1,9502025-06-03 CRITICAL 9.8 CVE-2025-5499 A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the f… Phpwcms 1.9.46 / 1.10.9+ Fix from $2,3002025-06-03 CRITICAL 9.8 CVE-2025-5497 A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_… Phpwcms 1.10.8+ Fix from $2,3002025-06-03 HIGH 8.4 CVE-2025-5455 An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in use… Mitigation only Fix from $1,9502025-06-02 MEDIUM 6.5 CVE-2025-48944 vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the … Vllm 0.9.0+ Fix from $1,6002025-05-30 MEDIUM 6.6 CVE-2025-4635 A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to obtain remote code execution … Mitigation only Fix from $1,6002025-05-30 MEDIUM 6.6 CVE-2025-48490 Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined fo… Patch available Fix from $1,6002025-05-30 HIGH 8.8 CVE-2025-5326 A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Aff… Adp Application Developer Platform Mitigation only Fix from $1,9502025-05-29 HIGH 8.8 CVE-2024-51392 An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component Mitigation only Fix from $1,9502025-05-29 MEDIUM 6.1 CVE-2025-33043 APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerabili… Aptio V 5.011+ Fix from $1,6002025-05-29 CRITICAL 9.8 CVE-2025-27151 Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi… Redis 7.2.9 / 7.4.4+ Fix from $2,3002025-05-29 HIGH 7.8 CVE-2025-5173 A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. A… Label Studio Ml Backend after 2024-09-30 Fix from $1,9502025-05-26 HIGH 7.8 CVE-2025-5174 A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pyp… Pypickle 2.0.0+ Fix from $1,9502025-05-26 MEDIUM 5.3 CVE-2025-5148 A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is… Patch available Fix from $1,6002025-05-25 CRITICAL 9.1 CVE-2025-5114 A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the fi… Zentao No fix yet Fix from $2,3002025-05-23 MEDIUM 6.9 CVE-2025-41378 The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend … Mitigation only Fix from $1,6002025-05-23 MEDIUM 6.3 CVE-2025-41379 The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rul… Mitigation only Fix from $1,6002025-05-23 HIGH 7.8 CVE-2024-40458 An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets. Innovation No fix yet Fix from $1,9502025-05-22 HIGH 8.8 CVE-2024-25010 Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where improper input validation could … Mitigation only Fix from $1,9502025-05-22 MEDIUM 6.5 CVE-2025-3885 Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to crea… Harman Mgu21 Firmware Mitigation only Fix from $1,6002025-05-22 HIGH 7.5 CVE-2021-25255 Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service. Yandex Browser 21.1.0+ Fix from $1,9502025-05-21 CRITICAL 9.9 CVE-2025-47283 Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener p… Gardener 1.116.4 / 1.117.5+ Fix from $2,3002025-05-19 CRITICAL 9.9 CVE-2025-47282 Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security vulnerability was discovered i… Mitigation only Fix from $2,3002025-05-19 CRITICAL 9.8 CVE-2025-4905 A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the function load_qc_pickl of the … Basestation after 3.0.4 Fix from $2,3002025-05-19 HIGH 8.6 CVE-2025-2305 A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitra… Mitigation only Fix from $1,9502025-05-16 HIGH 7.5 CVE-2024-53827 Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially crafted messages may cause servi… Mitigation only Fix from $1,9502025-05-16