Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-15061

Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Mitigation only
Fix from $2,300 2026-01-23
Azure Resource Manager CRITICAL 9.9
CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-01-23
Orval CRITICAL 9.8
CVE-2026-24132

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 th…

Fix: 7.20.0 / 8.0.3+
Fix from $2,300 2026-01-23
Azure Front Door CRITICAL 9.8
CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-01-22
Entra Id CRITICAL 9.8
CVE-2026-24305

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-01-22
Dragonfly CRITICAL 9.8
CVE-2026-24124

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/…

Fix: 2.4.1+
Fix from $2,300 2026-01-22
Azure Logic Apps CRITICAL 9.8
CVE-2026-21227

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…

Mitigation only
Fix from $2,300 2026-01-22
Evmapa CRITICAL 9.8
CVE-2025-55705

This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can res…

Mitigation only
Fix from $2,300 2026-01-22
Evmapa CRITICAL 9.8
CVE-2025-54816

This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish con…

Mitigation only
Fix from $2,300 2026-01-22
Soft Serve CRITICAL 9.8
CVE-2026-24058

Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that all…

Fix: 0.11.3+
Fix from $2,300 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20912

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20897

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20750

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be ab…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.4
CVE-2026-1201

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could a…

Mitigation only
Fix from $2,300 2026-01-22
Html2pdf CRITICAL 9.8
CVE-2025-56590

An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute …

Mitigation only
Fix from $2,300 2026-01-22
Powerscale Onefs CRITICAL 9.8
CVE-2026-22278

Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthentica…

Fix: 9.13.0.0+
Fix from $2,300 2026-01-22
Unclassified CRITICAL 10.0
CVE-2025-69828

File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.1
CVE-2025-69312

Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Upload a Web Shell to a Web …

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.8
CVE-2025-69101

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows Authentication Abuse.This iss…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.8
CVE-2025-69079

Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue af…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.8
CVE-2025-69052

Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-n…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-68986

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a Web Server.This issue affects …

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-68910

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious Files.This issue affects Blogzee:…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-68909

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious Files.This issue affects Blog…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.8
CVE-2025-68869

Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privilege Escalation.This issue aff…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.3
CVE-2025-68857

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Downloads paid-downloads allows …

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.3
CVE-2025-68034

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp all…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.4
CVE-2025-68018

Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.0
CVE-2025-68015

Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scan…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 10.0
CVE-2025-68001

Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a Web Shell to a Web Server.Thi…

Mitigation only
Fix from $2,300 2026-01-22