Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bagisto CRITICAL 9.8
CVE-2026-21448

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal custom…

Fix: 2.3.10+
Fix from $2,300 2026-01-02
Bagisto CRITICAL 9.8
CVE-2026-21446

Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial inst…

Fix: 2.3.10+
Fix from $2,300 2026-01-02
Langflow CRITICAL 9.1
CVE-2026-21445EPSS 34%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langf…

Fix: 1.7.1+
Fix from $2,300 2026-01-02
Unclassified CRITICAL 9.2
CVE-2026-21440

AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write…

Patch available
Fix from $2,300 2026-01-02
Emlog CRITICAL 9.3
CVE-2026-21430

Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF)…

No fix yet
Fix from $2,300 2026-01-02
Online Music Site CRITICAL 9.8
CVE-2026-0570

A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend/Feedback.php. Performing a m…

Mitigation only
Fix from $2,300 2026-01-02
Online Music Site CRITICAL 9.8
CVE-2026-0569

A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Su…

Mitigation only
Fix from $2,300 2026-01-02
Online Music Site CRITICAL 9.8
CVE-2026-0568

A flaw has been found in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Frontend/ViewSongs.php. This m…

Mitigation only
Fix from $2,300 2026-01-02
Content Management System CRITICAL 9.8
CVE-2026-0567

A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The …

Mitigation only
Fix from $2,300 2026-01-02
Content Management System CRITICAL 9.8
CVE-2026-0566

A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_po…

Mitigation only
Fix from $2,300 2026-01-02
Gpsd CRITICAL 9.8
CVE-2025-67268

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, wh…

Fix: 3.27.1+
Fix from $2,300 2026-01-02
Hyper Data Protector CRITICAL 9.8
CVE-2025-59389

An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to execute u…

Fix: 2.2.4.1+
Fix from $2,300 2026-01-02
Malware Remover CRITICAL 9.8
CVE-2025-11837

An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulner…

Fix: 6.6.8.20251023+
Fix from $2,300 2026-01-02
Online Movie Booking CRITICAL 9.8
CVE-2025-65125

SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive information.

Mitigation only
Fix from $2,300 2026-01-02
Content Management System CRITICAL 9.8
CVE-2026-0565

A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.p…

Mitigation only
Fix from $2,300 2026-01-02
Content Management System CRITICAL 9.8
CVE-2026-0546

A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipula…

Mitigation only
Fix from $2,300 2026-01-02
Ksoa CRITICAL 9.8
CVE-2025-15436

A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such ma…

Mitigation only
Fix from $2,300 2026-01-02
Ksoa CRITICAL 9.8
CVE-2025-15435

A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This man…

Mitigation only
Fix from $2,300 2026-01-02
Ksoa CRITICAL 9.8
CVE-2025-15434

A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The manipulation of the argument zpjh…

Mitigation only
Fix from $2,300 2026-01-02
Ksoa CRITICAL 9.8
CVE-2025-15425

A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_user.jsp of the component H…

Mitigation only
Fix from $2,300 2026-01-02
Ksoa CRITICAL 9.8
CVE-2025-15424

A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_worksdel.jsp of the component …

Mitigation only
Fix from $2,300 2026-01-02
Unclassified CRITICAL 9.8
CVE-2025-14998

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due …

Mitigation only
Fix from $2,300 2026-01-02
Ksoa CRITICAL 9.8
CVE-2025-15421

A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_worksadd.jsp of the component H…

Mitigation only
Fix from $2,300 2026-01-02
Ksoa CRITICAL 9.8
CVE-2025-15420

A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipul…

Mitigation only
Fix from $2,300 2026-01-02
Signal K Server CRITICAL 9.1
CVE-2025-68620

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained togeth…

Fix: 2.19.0+
Fix from $2,300 2026-01-01
Online Guitar Store CRITICAL 9.8
CVE-2025-15410

A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php.…

Mitigation only
Fix from $2,300 2026-01-01
Online Guitar Store CRITICAL 9.8
CVE-2025-15409

A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admi…

Mitigation only
Fix from $2,300 2026-01-01
Online Guitar Store CRITICAL 9.8
CVE-2025-15408

A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing…

Mitigation only
Fix from $2,300 2026-01-01
Online Guitar Store CRITICAL 9.8
CVE-2025-15407

A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Suc…

Mitigation only
Fix from $2,300 2026-01-01
School Management System CRITICAL 9.8
CVE-2026-0544

A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The ma…

Mitigation only
Fix from $2,300 2026-01-01