Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Director CRITICAL 9.9
CVE-2025-46066

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

No fix yet
Fix from $2,300 2026-01-12
Zx G12 Firmware CRITICAL 9.8
CVE-2025-65552

D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not impl…

Mitigation only
Fix from $2,300 2026-01-12
Unclassified CRITICAL 9.3
CVE-2025-41006

Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.

Mitigation only
Fix from $2,300 2026-01-12
Dx Netops Spectrum CRITICAL 9.8
CVE-2025-69270

Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.Thi…

Fix: 24.3.9+
Fix from $2,300 2026-01-12
Dx Netops Spectrum CRITICAL 9.8
CVE-2025-69269

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, L…

Fix: 23.3.7+
Fix from $2,300 2026-01-12
Iot Edge Linux Docker CRITICAL 9.8
CVE-2025-52694EPSS 39%

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vu…

Fix: 2.0.2 / 3.4.15+
Fix from $2,300 2026-01-12
Online Music Site CRITICAL 9.8
CVE-2026-0852

A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PH…

Mitigation only
Fix from $2,300 2026-01-12
Online Music Site CRITICAL 9.8
CVE-2026-0851

A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/Adm…

Mitigation only
Fix from $2,300 2026-01-12
Quickjs CRITICAL 9.8
CVE-2026-0821

A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file qui…

Fix: after 0.11.0
Fix from $2,300 2026-01-10
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15503

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function o…

Fix: after 3.0.8
Fix from $2,300 2026-01-10
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15502EPSS 6%

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro…

Fix: after 3.0.8
Fix from $2,300 2026-01-10
Devtoys CRITICAL 9.8
CVE-2026-22685

DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension i…

Fix: 2.0.9.0+
Fix from $2,300 2026-01-10
Weknora CRITICAL 9.8
CVE-2026-22687

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables th…

Fix: 0.2.5+
Fix from $2,300 2026-01-10
Full Calendar Macro CRITICAL 10.0
CVE-2025-65091

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONServi…

Fix: 2.4.5+
Fix from $2,300 2026-01-10
React Router\/node CRITICAL 9.1
CVE-2025-61686EPSS 17%

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node …

Fix: 2.17.2 / 7.9.4+
Fix from $2,300 2026-01-10
Openproject CRITICAL 9.1
CVE-2026-22600

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun…

Fix: 16.6.4+
Fix from $2,300 2026-01-10
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15501EPSS 7%

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th…

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Uni2ts CRITICAL 9.8
CVE-2026-22584

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code…

Fix: 2.0.0+
Fix from $2,300 2026-01-09
Operation And Maintenance Management System CRITICAL 9.8
CVE-2025-15500EPSS 6%

A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file …

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Operation And Maintenance Management System CRITICAL 9.8
CVE-2025-15499EPSS 5%

A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o…

Fix: after 3.0.8
Fix from $2,300 2026-01-09
Br 6208ac Firmware CRITICAL 9.8
CVE-2025-70161EPSS 25%

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the …

Mitigation only
Fix from $2,300 2026-01-09
Dir 895la1 Firmware CRITICAL 9.8
CVE-2025-69542EPSS 9%

A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease r…

Mitigation only
Fix from $2,300 2026-01-09
Unclassified CRITICAL 10.0
CVE-2025-69426

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an …

Mitigation only
Fix from $2,300 2026-01-09
Unclassified CRITICAL 10.0
CVE-2025-69425

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privile…

Mitigation only
Fix from $2,300 2026-01-09
Yshopmall CRITICAL 9.8
CVE-2025-15496

A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of th…

Fix: after 1.9.1
Fix from $2,300 2026-01-09
Docsys CRITICAL 9.8
CVE-2025-15493

A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMa…

Fix: after 2.02.36
Fix from $2,300 2026-01-09
Unclassified CRITICAL 9.3
CVE-2020-36875

AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The pl…

Mitigation only
Fix from $2,300 2026-01-09
Bet E Portal CRITICAL 9.8
CVE-2025-14598

BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables ar…

Mitigation only
Fix from $2,300 2026-01-09
Unclassified CRITICAL 9.3
CVE-2025-7072

The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an una…

Mitigation only
Fix from $2,300 2026-01-09
Ip7137 Firmware CRITICAL 9.8
CVE-2025-66050

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is…

Mitigation only
Fix from $2,300 2026-01-09