Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Titra CRITICAL 9.1
CVE-2025-69288

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule …

Fix: 0.99.49+
Fix from $2,300 2025-12-31
Ragflow CRITICAL 9.8
CVE-2025-69286

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm i…

Fix: 0.22.0+
Fix from $2,300 2025-12-31
Libcoap CRITICAL 9.8
CVE-2025-34468

libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-contro…

Fix: after 4.3.5
Fix from $2,300 2025-12-31
Dir 806a Firmware CRITICAL 9.8
CVE-2025-15391

A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipul…

Mitigation only
Fix from $2,300 2025-12-31
Lares Firmware CRITICAL 9.8
CVE-2025-15114

Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInf…

Mitigation only
Fix from $2,300 2025-12-30
Lares Firmware CRITICAL 9.3
CVE-2025-15113

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers t…

Mitigation only
Fix from $2,300 2025-12-30
Lares Firmware CRITICAL 9.8
CVE-2025-15111

Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrati…

Mitigation only
Fix from $2,300 2025-12-30
Flamingo Xl Firmware CRITICAL 10.0
CVE-2024-58338

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the trace…

Mitigation only
Fix from $2,300 2025-12-30
Lan Controller Firmware CRITICAL 9.8
CVE-2023-54327

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords thro…

Fix: after 1.58a
Fix from $2,300 2025-12-30
Flamingo Xl Firmware CRITICAL 9.8
CVE-2023-53983

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can…

Mitigation only
Fix from $2,300 2025-12-30
Unclassified CRITICAL 9.8
CVE-2022-50803

JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privi…

Mitigation only
Fix from $2,300 2025-12-30
Impact Firmware CRITICAL 9.8
CVE-2022-50796

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path tr…

Mitigation only
Fix from $2,300 2025-12-30
Impact Firmware CRITICAL 9.8
CVE-2022-50794

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers …

Mitigation only
Fix from $2,300 2025-12-30
First Firmware CRITICAL 9.8
CVE-2022-50696

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal…

Mitigation only
Fix from $2,300 2025-12-30
Impact Firmware CRITICAL 9.8
CVE-2022-50694

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to ma…

Mitigation only
Fix from $2,300 2025-12-30
Minidvblinux CRITICAL 9.8
CVE-2022-50691

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root throug…

Mitigation only
Fix from $2,300 2025-12-30
Di 7400g\+ Firmware CRITICAL 9.8
CVE-2025-15357

A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of th…

Mitigation only
Fix from $2,300 2025-12-30
Matio CRITICAL 9.8
CVE-2025-50343

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the …

Mitigation only
Fix from $2,300 2025-12-30
Society Management System CRITICAL 9.8
CVE-2025-15354

A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/add_admin.php. Ex…

Mitigation only
Fix from $2,300 2025-12-30
Society Management System CRITICAL 9.8
CVE-2025-15353

A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of the file /admin/edit_admin_q…

Mitigation only
Fix from $2,300 2025-12-30
Simple Php Cms CRITICAL 9.8
CVE-2025-15263

A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin …

Mitigation only
Fix from $2,300 2025-12-30
Pangolin CRITICAL 9.1
CVE-2025-56332

Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Default Configuration

Fix: 1.7.0+
Fix from $2,300 2025-12-30
Rustfs CRITICAL 9.8
CVE-2025-68926EPSS 31%

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardc…

Mitigation only
Fix from $2,300 2025-12-30
Ax1800 Firmware CRITICAL 9.8
CVE-2025-66848

JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and ea…

Fix: after 4.5.1.r4533
Fix from $2,300 2025-12-30
Unclassified CRITICAL 9.6
CVE-2025-52835

Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a Web Shell to a Web Server.This…

Mitigation only
Fix from $2,300 2025-12-30
Br 6208ac Firmware CRITICAL 9.8
CVE-2025-15257EPSS 5%

A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formR…

Mitigation only
Fix from $2,300 2025-12-30
Br 6208ac Firmware CRITICAL 9.8
CVE-2025-15256

A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the com…

Mitigation only
Fix from $2,300 2025-12-30
W6 S Firmware CRITICAL 9.8
CVE-2025-15255

A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHa…

Mitigation only
Fix from $2,300 2025-12-30
Unclassified CRITICAL 9.8
CVE-2023-54292

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix data race on CQP request done KCSAN detects a data race on cqp_…

Mitigation only
Fix from $2,300 2025-12-30
Unclassified CRITICAL 9.8
CVE-2023-54280

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_…

No fix yet
Fix from $2,300 2025-12-30