Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2025-30996

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Fol…

Mitigation only
Fix from $2,300 2026-01-06
Wolfssh CRITICAL 9.8
CVE-2025-14942

wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or tr…

Fix: 1.4.22+
Fix from $2,300 2026-01-06
Cobalt X1 CRITICAL 9.8
CVE-2025-60534

Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order t…

Mitigation only
Fix from $2,300 2026-01-06
Unclassified CRITICAL 9.8
CVE-2025-39477

Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

Mitigation only
Fix from $2,300 2026-01-06
Ac23 Firmware CRITICAL 9.8
CVE-2026-0640

A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation…

Mitigation only
Fix from $2,300 2026-01-06
Hy511 Firmware CRITICAL 9.8
CVE-2025-65212

An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie ver…

Fix: 2.1+
Fix from $2,300 2026-01-06
Mc102 G Firmware CRITICAL 9.8
CVE-2025-60262

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability …

Mitigation only
Fix from $2,300 2026-01-06
Unclassified CRITICAL 9.8
CVE-2020-36925

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass a…

Mitigation only
Fix from $2,300 2026-01-06
Bravia Signage CRITICAL 9.8
CVE-2020-36923

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. …

Fix: after 1.7.8
Fix from $2,300 2026-01-06
Unclassified CRITICAL 9.8
CVE-2020-36912

Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manip…

Mitigation only
Fix from $2,300 2026-01-06
Unclassified CRITICAL 9.8
CVE-2025-15001

The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.…

Mitigation only
Fix from $2,300 2026-01-06
Unclassified CRITICAL 9.8
CVE-2025-14996

The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up…

Mitigation only
Fix from $2,300 2026-01-06
Iccdev CRITICAL 9.8
CVE-2026-21675

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulner…

Fix: 2.3.1.1+
Fix from $2,300 2026-01-06
Boomplay CRITICAL 9.8
CVE-2025-15385

Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects co…

Fix: after 7.4.63
Fix from $2,300 2026-01-06
Crypt\ CRITICAL 9.8
CVE-2025-15444

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodi…

Fix: 0.000042+
Fix from $2,300 2026-01-06
Online Music Site CRITICAL 9.8
CVE-2026-0607

A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executi…

Mitigation only
Fix from $2,300 2026-01-06
Online Music Site CRITICAL 9.8
CVE-2026-0606

A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Album…

Mitigation only
Fix from $2,300 2026-01-05
Unclassified CRITICAL 9.3
CVE-2026-0625

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows…

Mitigation only
Fix from $2,300 2026-01-05
Craft Cms CRITICAL 9.1
CVE-2025-68456

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trig…

Fix: 4.16.17 / 5.8.21+
Fix from $2,300 2026-01-05
Vega CRITICAL 9.3
CVE-2025-65110

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 an…

Fix: 5.6.3 / 6.1.2+
Fix from $2,300 2026-01-05
Online Music Site CRITICAL 9.8
CVE-2026-0605

A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the …

Mitigation only
Fix from $2,300 2026-01-05
Passy CRITICAL 9.1
CVE-2025-67397

An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload in…

Mitigation only
Fix from $2,300 2026-01-05
Exynos 990 Firmware CRITICAL 9.1
CVE-2025-27807

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…

Mitigation only
Fix from $2,300 2026-01-05
Opencti CRITICAL 9.1
CVE-2025-61781

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo…

Fix: 6.8.1+
Fix from $2,300 2026-01-05
Muffon CRITICAL 9.6
CVE-2025-55204

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in.…

Fix: 2.3.0+
Fix from $2,300 2026-01-05
Argentina Afip Invoices CRITICAL 9.6
CVE-2025-59467

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Adm…

Fix: 1.3.0+
Fix from $2,300 2026-01-05
Unclassified CRITICAL 9.3
CVE-2025-39484

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue …

Mitigation only
Fix from $2,300 2026-01-05
Unclassified CRITICAL 9.8
CVE-2025-14346EPSS 6%

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pa…

Mitigation only
Fix from $2,300 2026-01-05
Supplier Management System CRITICAL 9.8
CVE-2026-0597

A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_pr…

Mitigation only
Fix from $2,300 2026-01-05
Awie CRITICAL 9.8
CVE-2025-15029EPSS 12%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules)…

Fix: 24.04.3 / 24.10.3+
Fix from $2,300 2026-01-05