Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2020-37067

Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attacker…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.8
CVE-2020-37066

GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malicious input in the File Open U…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.8
CVE-2020-37065

StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to overwrite memory by manipula…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.3
CVE-2025-65078

An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be …

Mitigation only
Fix from $2,300 2026-02-03
Debian Linux CRITICAL 9.8
CVE-2025-62799

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.…

Fix: 2.6.11 / 3.3.1+
Fix from $2,300 2026-02-03
Fikir Odalari Adminpando CRITICAL 10.0
CVE-2025-10878

A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parame…

Fix: after 1.0.1
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25241

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<packa…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25240

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::ma…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25238

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription d…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25237

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug u…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25236

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25234

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion …

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.1
CVE-2026-25233

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Fuxa CRITICAL 9.8
CVE-2025-69983

FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-suppl…

Mitigation only
Fix from $2,300 2026-02-03
Fuxa CRITICAL 9.8
CVE-2025-69981

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allow…

Mitigation only
Fix from $2,300 2026-02-03
Fuxa CRITICAL 9.8
CVE-2025-69971

FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and veri…

Mitigation only
Fix from $2,300 2026-02-03
Fuxa CRITICAL 9.3
CVE-2025-69970

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by defa…

Mitigation only
Fix from $2,300 2026-02-03
A950rg Firmware CRITICAL 9.8
CVE-2025-67188

A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg interface of the /lib/cste_mo…

Mitigation only
Fix from $2,300 2026-02-03
A950rg Firmware CRITICAL 9.8
CVE-2025-67187

A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface…

Mitigation only
Fix from $2,300 2026-02-03
A950rg Firmware CRITICAL 9.8
CVE-2025-67186

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cste_modules/firewall.so.…

Mitigation only
Fix from $2,300 2026-02-03
Fpdf CRITICAL 9.8
CVE-2025-65875

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a…

Mitigation only
Fix from $2,300 2026-02-03
Iot Smart Water Meter Firmware CRITICAL 9.8
CVE-2025-63624

SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows a remote attacker to execute…

Mitigation only
Fix from $2,300 2026-02-03
Mediacrush CRITICAL 9.8
CVE-2025-61506

An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpo…

Fix: after 1.0.1
Fix from $2,300 2026-02-03
Cpas Audit Management System CRITICAL 9.8
CVE-2025-57529

YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validatio…

Fix: after 4.9
Fix from $2,300 2026-02-03
Aion CRITICAL 9.8
CVE-2025-52626

A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actio…

Mitigation only
Fix from $2,300 2026-02-03
60cyclecms CRITICAL 9.8
CVE-2020-37110

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through …

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.6
CVE-2026-1568

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allo…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.8
CVE-2025-5319

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.3
CVE-2026-1432

SQL injection vulnerability in the Buroweb platform version 2505.0.12, specifically in the 'tablon' component. This vulnerability is present in sever…

Mitigation only
Fix from $2,300 2026-02-03
Moodle CRITICAL 9.8
CVE-2025-67856

A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges…

Fix: 4.1.22 / 4.4.12+
Fix from $2,300 2026-02-03