Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-68775

In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations leak socket When a handshake r…

Mitigation only
Fix from $2,300 2026-01-13
Hub CRITICAL 9.8
CVE-2025-65783

An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to …

Mitigation only
Fix from $2,300 2026-01-13
Unclassified CRITICAL 9.0
CVE-2025-12548

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltratio…

Mitigation only
Fix from $2,300 2026-01-13
Unclassified CRITICAL 9.3
CVE-2026-22755EPSS 21%

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365…

Mitigation only
Fix from $2,300 2026-01-13
Firefox CRITICAL 9.8
CVE-2026-0892

Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 147.0+
Fix from $2,300 2026-01-13
Firefox CRITICAL 9.8
CVE-2026-0884

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 1…

Fix: 140.7.0 / 147.0+
Fix from $2,300 2026-01-13
Firefox CRITICAL 10.0
CVE-2026-0881

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Fix: 147.0+
Fix from $2,300 2026-01-13
Firefox CRITICAL 9.8
CVE-2026-0879

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firef…

Fix: 115.32.0 / 140.7.0+
Fix from $2,300 2026-01-13
Manageengine Adselfservice Plus CRITICAL 9.1
CVE-2025-11250

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

Fix: 6.5+
Fix from $2,300 2026-01-13
Unclassified CRITICAL 10.0
CVE-2025-40805

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to c…

Mitigation only
Fix from $2,300 2026-01-13
Unclassified CRITICAL 9.1
CVE-2025-14829

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This ma…

Mitigation only
Fix from $2,300 2026-01-13
Unclassified CRITICAL 9.8
CVE-2025-10915

The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check.

Mitigation only
Fix from $2,300 2026-01-13
Unclassified CRITICAL 9.9
CVE-2026-0501

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute cra…

Mitigation only
Fix from $2,300 2026-01-13
Unclassified CRITICAL 9.1
CVE-2026-0491

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw en…

Mitigation only
Fix from $2,300 2026-01-13
Riot CRITICAL 9.8
CVE-2026-22214

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds…

Fix: 2025.10+
Fix from $2,300 2026-01-12
Riot CRITICAL 9.8
CVE-2026-22213

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability…

Fix: 2025.10+
Fix from $2,300 2026-01-12
Gym Management System CRITICAL 9.4
CVE-2025-67146

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) train…

No fix yet
Fix from $2,300 2026-01-12
F\@st 3686 Firmware CRITICAL 9.8
CVE-2025-29329

Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary…

Mitigation only
Fix from $2,300 2026-01-12
Now Assist Ai Agents CRITICAL 9.8
CVE-2025-12420EPSS 47%

A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform t…

Fix: 3.15.2 / 4.0.4+
Fix from $2,300 2026-01-12
Unclassified CRITICAL 9.8
CVE-2025-67147

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1…

Mitigation only
Fix from $2,300 2026-01-12
Covid 19 Contact Tracing System CRITICAL 9.8
CVE-2025-66802

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into …

Mitigation only
Fix from $2,300 2026-01-12
Online Exam System CRITICAL 9.1
CVE-2025-51567

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary…

No fix yet
Fix from $2,300 2026-01-12
Orval CRITICAL 9.8
CVE-2026-22785

orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation l…

Fix: 7.18.0+
Fix from $2,300 2026-01-12
Tinyweb CRITICAL 9.8
CVE-2026-22781

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via …

Fix: 1.98+
Fix from $2,300 2026-01-12
Librechat CRITICAL 9.9
CVE-2026-22252

LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without valida…

Patch available
Fix from $2,300 2026-01-12
Mindsdb CRITICAL 9.1
CVE-2025-68472EPSS 19%

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the f…

Fix: 25.11.1+
Fix from $2,300 2026-01-12
Cm3 Acora Cms CRITICAL 10.0
CVE-2025-63314

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user pas…

Mitigation only
Fix from $2,300 2026-01-12
Botmanager CRITICAL 9.8
CVE-2025-46070

An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

Mitigation only
Fix from $2,300 2026-01-12
Director CRITICAL 9.9
CVE-2025-46066

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

No fix yet
Fix from $2,300 2026-01-12
Zx G12 Firmware CRITICAL 9.8
CVE-2025-65552

D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not impl…

Mitigation only
Fix from $2,300 2026-01-12