Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Icx500 Firmware CRITICAL 9.8
CVE-2025-64093

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

Fix: 1.4.3.3+
Fix from $2,300 2026-01-09
GitLab CRITICAL 9.6
CVE-2025-13761

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unau…

Fix: 18.6.3+
Fix from $2,300 2026-01-09
Wget2 CRITICAL 9.8
CVE-2025-69194

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Meta…

Fix: 2.2.1+
Fix from $2,300 2026-01-09
Unclassified CRITICAL 9.1
CVE-2025-14741

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a …

Mitigation only
Fix from $2,300 2026-01-09
Android CRITICAL 9.1
CVE-2026-20973

Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

Mitigation only
Fix from $2,300 2026-01-09
Unclassified CRITICAL 10.0
CVE-2025-70974

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, t…

Mitigation only
Fix from $2,300 2026-01-09
Unclassified CRITICAL 9.8
CVE-2025-14736

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is du…

Mitigation only
Fix from $2,300 2026-01-09
Di 8200g Firmware CRITICAL 9.8
CVE-2026-0732EPSS 10%

A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the ar…

Mitigation only
Fix from $2,300 2026-01-09
Ks Wr3600 Firmware CRITICAL 9.4
CVE-2025-68717

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /…

No fix yet
Fix from $2,300 2026-01-08
Pwru01 Firmware CRITICAL 9.1
CVE-2025-68715

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /go…

No fix yet
Fix from $2,300 2026-01-08
Ruoyi Vue Plus CRITICAL 9.4
CVE-2025-66916

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expres…

Fix: after 5.5.1
Fix from $2,300 2026-01-08
Jimureport CRITICAL 9.8
CVE-2025-66913

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacke…

Fix: after 2.1.3
Fix from $2,300 2026-01-08
Qloapps CRITICAL 9.8
CVE-2025-67325

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote …

Fix: after 1.7.0
Fix from $2,300 2026-01-08
Ecase Portal CRITICAL 9.8
CVE-2026-22234

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predict…

Fix: 9.0.45.0+
Fix from $2,300 2026-01-08
Print Shop Pro Webdesk CRITICAL 9.8
CVE-2025-61548

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions…

Mitigation only
Fix from $2,300 2026-01-08
Print Shop Pro Webdesk CRITICAL 9.1
CVE-2025-61546

There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed i…

No fix yet
Fix from $2,300 2026-01-08
Online Shopping System CRITICAL 9.8
CVE-2025-61246

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

Mitigation only
Fix from $2,300 2026-01-08
Veeam Backup \& Replication CRITICAL 9.0
CVE-2025-59470

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order para…

Fix: 13.0.1.1071+
Fix from $2,300 2026-01-08
Veeam Backup \& Replication CRITICAL 9.0
CVE-2025-59469

This vulnerability allows a Backup or Tape Operator to write files as root.

Fix: 13.0.1.1071+
Fix from $2,300 2026-01-08
Veeam Backup \& Replication CRITICAL 9.1
CVE-2025-59468

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password paramet…

Fix: 13.0.1.1071+
Fix from $2,300 2026-01-08
Enaio CRITICAL 9.1
CVE-2025-56425

An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.18…

Fix: 10.10.0.183 / 11.0.0.183+
Fix from $2,300 2026-01-08
Veeam Backup \& Replication CRITICAL 9.8
CVE-2025-55125

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

Fix: 13.0.1.1071+
Fix from $2,300 2026-01-08
Rustfs CRITICAL 9.8
CVE-2026-22043

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in…

Mitigation only
Fix from $2,300 2026-01-08
Snuffleupagus CRITICAL 9.8
CVE-2026-22034

Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual patching system. On deployme…

Fix: 0.13.0+
Fix from $2,300 2026-01-08
Zimaos CRITICAL 9.8
CVE-2026-21891

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application…

Fix: after 1.5.0
Fix from $2,300 2026-01-08
Apex Central CRITICAL 9.8
CVE-2025-69258

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a ke…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.8
CVE-2025-62877

Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x int…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.3
CVE-2025-67928

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allow…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.9
CVE-2025-67924

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affe…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.8
CVE-2025-67911

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newslet…

Mitigation only
Fix from $2,300 2026-01-08