Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 823x Firmware CRITICAL 9.8
CVE-2026-1125EPSS 15%

A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings.…

Mitigation only
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1124

A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report…

Mitigation only
Fix from $2,300 2026-01-18
N8n CRITICAL 9.9
CVE-2026-0863EPSS 9%

Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted…

Fix: after 2.4.2
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1123

A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Para…

Mitigation only
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1122

A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Pa…

Mitigation only
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1121

A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Para…

Mitigation only
Fix from $2,300 2026-01-18
Ksoa CRITICAL 9.8
CVE-2026-1120

A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component H…

Mitigation only
Fix from $2,300 2026-01-18
Society Management System CRITICAL 9.8
CVE-2026-1119

A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/delete_activity.p…

Mitigation only
Fix from $2,300 2026-01-18
Society Management System CRITICAL 9.8
CVE-2026-1118

A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/add_activity.php. Perf…

Mitigation only
Fix from $2,300 2026-01-18
Eyoucms CRITICAL 9.8
CVE-2026-1107

A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av…

Mitigation only
Fix from $2,300 2026-01-18
Easycms CRITICAL 9.8
CVE-2026-1105

A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of …

Fix: after 1.6
Fix from $2,300 2026-01-18
Teamwork Management System CRITICAL 9.8
CVE-2026-1062

A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java.…

Fix: after 2.28.0
Fix from $2,300 2026-01-17
Teamwork Management System CRITICAL 9.8
CVE-2026-1061

A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/…

Fix: after 2.28.0
Fix from $2,300 2026-01-17
Warehouse Management System CRITICAL 9.8
CVE-2026-1059

A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknow…

Fix: after 2021-11-15
Fix from $2,300 2026-01-17
Unclassified CRITICAL 9.8
CVE-2025-10484

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, …

Mitigation only
Fix from $2,300 2026-01-17
Unclassified CRITICAL 9.8
CVE-2025-15403

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'a…

Mitigation only
Fix from $2,300 2026-01-17
Unclassified CRITICAL 10.0
CVE-2026-23800

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 be…

Mitigation only
Fix from $2,300 2026-01-16
Inspector CRITICAL 9.8
CVE-2026-23744EPSS 45%

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vu…

Fix: 1.4.3+
Fix from $2,300 2026-01-16
Unclassified CRITICAL 9.3
CVE-2012-10064

Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-co…

No fix yet
Fix from $2,300 2026-01-16
Filemanager CRITICAL 9.8
CVE-2025-14894

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME val…

Fix: 1.0.0+
Fix from $2,300 2026-01-16
Myxalytics CRITICAL 9.8
CVE-2025-59870

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introduci…

Mitigation only
Fix from $2,300 2026-01-16
Brpc CRITICAL 9.8
CVE-2025-60021EPSS 25%

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …

Fix: 1.15.0+
Fix from $2,300 2026-01-16
Diaview CRITICAL 9.8
CVE-2026-0975

Delta Electronics DIAView has Command Injection vulnerability.

Fix: 4.4.0+
Fix from $2,300 2026-01-16
Police Statistics Database System CRITICAL 9.8
CVE-2026-1021

Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload a…

Fix: after 1.0.2
Fix from $2,300 2026-01-16
Police Statistics Database System CRITICAL 9.8
CVE-2026-1019

Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, m…

Fix: after 1.0.3
Fix from $2,300 2026-01-16
Diaview CRITICAL 9.8
CVE-2025-62582

Delta Electronics DIAView has multiple vulnerabilities.

Fix: 4.4.0+
Fix from $2,300 2026-01-16
Diaview CRITICAL 9.8
CVE-2025-62581

Delta Electronics DIAView has multiple vulnerabilities.

Fix: 4.4.0+
Fix from $2,300 2026-01-16
Process Optimization CRITICAL 10.0
CVE-2025-61937

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” s…

Fix: 2025+
Fix from $2,300 2026-01-16
Mf455dw Firmware CRITICAL 9.8
CVE-2025-14237

Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network …

Fix: after 06.02
Fix from $2,300 2026-01-16
Mf455dw Firmware CRITICAL 9.8
CVE-2025-14236

Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment…

Fix: after 06.02
Fix from $2,300 2026-01-16