Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gemscms Backend CRITICAL 9.4
CVE-2025-52025

An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulner…

Fix: after 2025-05-28
Fix from $2,300 2026-01-23
Gemscms Backend CRITICAL 9.4
CVE-2025-52024

A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated us…

Fix: after 2025-05-28
Fix from $2,300 2026-01-23
Ruoyi CRITICAL 9.1
CVE-2025-70985

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

No fix yet
Fix from $2,300 2026-01-23
Springblade CRITICAL 9.9
CVE-2025-70983

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

Mitigation only
Fix from $2,300 2026-01-23
Smartermail CRITICAL 9.8
CVE-2026-24423 KEVEPSS 88%

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. …

Fix: 100.0.9511+
Fix from $2,300 2026-01-23
Builder CRITICAL 9.8
CVE-2025-67229

An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker t…

Fix: 0.32.1+
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2022-25369EPSS 41%

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a l…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2021-47891

Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary c…

Mitigation only
Fix from $2,300 2026-01-23
Nrf CRITICAL 9.1
CVE-2025-66719

An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/…

Patch available
Fix from $2,300 2026-01-23
Unclassified CRITICAL 10.0
CVE-2025-4320

Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technolo…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.4
CVE-2025-4319

Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Softw…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-1364

IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly operate system adminis…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-1363

IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain a…

Mitigation only
Fix from $2,300 2026-01-23
8180 Ip Audio Alerter Firmware CRITICAL 9.8
CVE-2026-0794

ALGO 8180 IP Audio Alerter SIP Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $2,300 2026-01-23
8180 Ip Audio Alerter Firmware CRITICAL 9.8
CVE-2026-0793

ALGO 8180 IP Audio Alerter InformaCast Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $2,300 2026-01-23
8180 Ip Audio Alerter Firmware CRITICAL 9.8
CVE-2026-0792

ALGO 8180 IP Audio Alerter SIP INVITE Alert-Info Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote at…

Mitigation only
Fix from $2,300 2026-01-23
8180 Ip Audio Alerter Firmware CRITICAL 9.8
CVE-2026-0791

ALGO 8180 IP Audio Alerter SIP INVITE Replaces Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote atta…

Mitigation only
Fix from $2,300 2026-01-23
8180 Ip Audio Alerter Firmware CRITICAL 9.8
CVE-2026-0787

ALGO 8180 IP Audio Alerter SAC Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-0773

Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2026-01-23
Langflow CRITICAL 9.8
CVE-2026-0770 KEVEPSS 63%

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote …

Fix: after 1.7.3
Fix from $2,300 2026-01-23
Langflow CRITICAL 9.8
CVE-2026-0769EPSS 38%

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

Mitigation only
Fix from $2,300 2026-01-23
Langflow CRITICAL 9.8
CVE-2026-0768

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…

Mitigation only
Fix from $2,300 2026-01-23
Gpt Academic CRITICAL 9.8
CVE-2026-0764

GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2026-01-23
Gpt Academic CRITICAL 9.8
CVE-2026-0763

GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote a…

Mitigation only
Fix from $2,300 2026-01-23
Metagpt CRITICAL 9.8
CVE-2026-0761

Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers …

Mitigation only
Fix from $2,300 2026-01-23
Metagpt CRITICAL 9.8
CVE-2026-0760

Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-0759

Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-0756

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-0755

gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2025-15063

Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $2,300 2026-01-23