Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2025-67968

Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue a…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.3
CVE-2025-67945

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.1
CVE-2025-67944

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.8
CVE-2025-67617

Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a t…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-62056

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <=…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-62050

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 10.0
CVE-2025-50002

Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects …

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.3
CVE-2025-49055

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-ca…

Mitigation only
Fix from $2,300 2026-01-22
Docling Core CRITICAL 9.8
CVE-2026-24009

Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML…

Fix: 2.48.4+
Fix from $2,300 2026-01-22
Ax3 Firmware CRITICAL 9.8
CVE-2025-69764

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buff…

Mitigation only
Fix from $2,300 2026-01-22
Smartermail CRITICAL 9.8
CVE-2026-23760 KEVEPSS 96%

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passw…

Fix: 100.0.9511+
Fix from $2,300 2026-01-22
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2026-1325

A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_…

Fix: after 3.0.12
Fix from $2,300 2026-01-22
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2026-1324EPSS 7%

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon…

Fix: after 3.0.12
Fix from $2,300 2026-01-22
Nerveshub CRITICAL 9.8
CVE-2025-64097

NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vulnerability present starting …

Fix: 2.3.0+
Fix from $2,300 2026-01-22
Meetinghub Paperless Meetings CRITICAL 9.8
CVE-2026-1331

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execu…

Fix: 2025-12-10+
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.8
CVE-2026-0920

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.…

Mitigation only
Fix from $2,300 2026-01-22
Appsmith CRITICAL 9.8
CVE-2026-24042

Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthentica…

Fix: after 1.94
Fix from $2,300 2026-01-22
Grist Core CRITICAL 9.6
CVE-2026-24002

Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases w…

Fix: 1.7.9+
Fix from $2,300 2026-01-22
Sm Crypto CRITICAL 9.1
CVE-2026-23966

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists …

Fix: 0.3.14+
Fix from $2,300 2026-01-22
Dataease CRITICAL 9.8
CVE-2026-23958

Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT s…

Fix: 2.10.19+
Fix from $2,300 2026-01-22
On Prem Enterprise Server CRITICAL 9.8
CVE-2025-27378

AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this …

Fix: 7.0.6+
Fix from $2,300 2026-01-22
Hustoj CRITICAL 9.0
CVE-2026-23873

hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Form…

Fix: after 26.01.31
Fix from $2,300 2026-01-22
Seroval CRITICAL 9.8
CVE-2026-23736

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to im…

Fix: 1.4.1+
Fix from $2,300 2026-01-21
Reverb CRITICAL 9.8
CVE-2026-23524

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from th…

Fix: 1.7.0+
Fix from $2,300 2026-01-21
Fleet CRITICAL 9.8
CVE-2026-23518

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows …

Fix: 4.53.3 / 4.75.2+
Fix from $2,300 2026-01-21
Vllm CRITICAL 9.8
CVE-2026-22807

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging …

Fix: 0.14.0+
Fix from $2,300 2026-01-21
5ire CRITICAL 9.6
CVE-2026-22793

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsi…

Fix: 0.15.3+
Fix from $2,300 2026-01-21
5ire CRITICAL 9.6
CVE-2026-22792

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe HTML renderi…

Fix: 0.15.3+
Fix from $2,300 2026-01-21
Ax3 Firmware CRITICAL 9.8
CVE-2025-69766

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buff…

Mitigation only
Fix from $2,300 2026-01-21
Ax3 Firmware CRITICAL 9.8
CVE-2025-69763

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remot…

Mitigation only
Fix from $2,300 2026-01-21