Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2025-67910

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.3
CVE-2025-23993

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allow…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.8
CVE-2025-23504

Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This …

Mitigation only
Fix from $2,300 2026-01-08
Intern Membership Management System CRITICAL 9.8
CVE-2026-0700

A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/ch…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.8
CVE-2019-25296

The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_uploa…

Mitigation only
Fix from $2,300 2026-01-08
Kanboard CRITICAL 9.1
CVE-2026-21881

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass wh…

Fix: 1.2.49+
Fix from $2,300 2026-01-08
N8n CRITICAL 9.9
CVE-2026-21877EPSS 5%

n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us…

Fix: 1.121.3+
Fix from $2,300 2026-01-08
Clipbucket CRITICAL 9.8
CVE-2026-21875

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the ad…

Fix: 5.5.2-191+
Fix from $2,300 2026-01-08
Llama.cpp CRITICAL 9.8
CVE-2026-21869

llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input …

Mitigation only
Fix from $2,300 2026-01-08
N8n CRITICAL 10.0
CVE-2026-21858EPSS 78%

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underly…

Fix: 1.121.0+
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.3
CVE-2025-15346

A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to n…

Patch available
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.8
CVE-2019-25282

V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipulate the 'parent' GET paramet…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.8
CVE-2019-25268

NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening applicatio…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.8
CVE-2017-20216EPSS 11%

FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerF…

Mitigation only
Fix from $2,300 2026-01-08
Pnpm CRITICAL 9.8
CVE-2025-69264

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing t…

Fix: 10.26.0+
Fix from $2,300 2026-01-07
Panda3d CRITICAL 9.8
CVE-2026-22189

The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounde…

Fix: after 1.10.16
Fix from $2,300 2026-01-07
Rustfs CRITICAL 9.8
CVE-2025-68705EPSS 7%

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerabi…

Patch available
Fix from $2,300 2026-01-07
Tarkov Data Manager CRITICAL 9.8
CVE-2026-21854

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpo…

Fix: 2025-01-02+
Fix from $2,300 2026-01-07
Iccdev CRITICAL 9.8
CVE-2026-21679

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $2,300 2026-01-07
Terminal Controller Mcp CRITICAL 10.0
CVE-2025-61492

A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via…

Mitigation only
Fix from $2,300 2026-01-07
Build Of Apache Camel CRITICAL 9.6
CVE-2025-12543

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr…

Fix: 2.2.39 / 2.3.21+
Fix from $2,300 2026-01-07
Unclassified CRITICAL 9.2
CVE-2026-22542

An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified CRITICAL 9.2
CVE-2026-22540

The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board …

Mitigation only
Fix from $2,300 2026-01-07
Unclassified CRITICAL 9.8
CVE-2025-47552

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified CRITICAL 9.3
CVE-2025-32303

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.Th…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified CRITICAL 9.3
CVE-2026-0650

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of p…

Mitigation only
Fix from $2,300 2026-01-07
House Rental And Property Listing Project CRITICAL 9.8
CVE-2026-0643

A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=re…

Mitigation only
Fix from $2,300 2026-01-07
Uniffle CRITICAL 9.1
CVE-2025-68637

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration expos…

Fix: 0.10.0+
Fix from $2,300 2026-01-07
Unclassified CRITICAL 9.8
CVE-2025-15018

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This…

Mitigation only
Fix from $2,300 2026-01-07
Tew 713re Firmware CRITICAL 9.8
CVE-2025-15471EPSS 13%

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation…

Mitigation only
Fix from $2,300 2026-01-07