Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2025-69366

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Emerce Core emerce-core allows Bli…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69365

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Uroan Core uroan-core allows Blind…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69337

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Wolmart Core wolmart-core allows Bli…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69329

Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < …

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69310

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodly Core woodly-core allows Bli…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69309

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasplate Core saasplate-core allo…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestbyte Core nestbyte-core allows…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69307

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medinik Core medinik-core allows B…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69306

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Electio Core electio-core allows B…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69305

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete Core crete-core allows Blind…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69304

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allmart allmart-core allows Blind …

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-69301

Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <=…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.3
CVE-2025-69295

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.9
CVE-2025-68549

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affe…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-68541

Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-67997

Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-67996

Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-67995

Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a throu…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.9
CVE-2025-67979

Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows …

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.5
CVE-2026-21627

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain c…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-10970

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL …

Mitigation only
Fix from $2,300 2026-02-20
Librenms CRITICAL 9.1
CVE-2026-26988EPSS 7%

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in th…

Fix: 26.2.0+
Fix from $2,300 2026-02-20
Slyde CRITICAL 9.8
CVE-2026-26974

Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically imports **/*.plugin.{js,mjs} file…

Fix: 0.0.5+
Fix from $2,300 2026-02-20
Cyber Protect CRITICAL 10.0
CVE-2025-30416

Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Window…

Mitigation only
Fix from $2,300 2026-02-20
Cyber Protect CRITICAL 10.0
CVE-2025-30412

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Wind…

Mitigation only
Fix from $2,300 2026-02-20
Cyber Protect CRITICAL 10.0
CVE-2025-30411

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Wind…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-30410

Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Lin…

Mitigation only
Fix from $2,300 2026-02-20
Openclaw CRITICAL 9.8
CVE-2026-27002

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Doc…

Fix: 2026.2.15+
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.8
CVE-2026-27476

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 …

Mitigation only
Fix from $2,300 2026-02-19
Ruckus Network Director CRITICAL 9.8
CVE-2025-67305

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all…

Fix: 4.5.0.56+
Fix from $2,300 2026-02-19