Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pangolin CRITICAL 9.8
CVE-2025-56333

An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component

Fix: 1.7.0+
Fix from $2,300 2025-12-29
Assessment Management CRITICAL 9.8
CVE-2025-15195

A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/ad…

Mitigation only
Fix from $2,300 2025-12-29
Dir 600 Firmware CRITICAL 9.8
CVE-2025-15194

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the…

Mitigation only
Fix from $2,300 2025-12-29
Frappe CRITICAL 9.0
CVE-2025-68929

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tri…

Fix: 14.99.6 / 15.88.1+
Fix from $2,300 2025-12-29
Jsish CRITICAL 9.8
CVE-2025-65570

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array ele…

Mitigation only
Fix from $2,300 2025-12-29
Machpanel CRITICAL 9.8
CVE-2025-57460

File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.

Mitigation only
Fix from $2,300 2025-12-29
Refugee Food Management System CRITICAL 9.8
CVE-2025-15186

A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file …

Mitigation only
Fix from $2,300 2025-12-29
Refugee Food Management System CRITICAL 9.8
CVE-2025-15185

A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ho…

Mitigation only
Fix from $2,300 2025-12-29
Refugee Food Management System CRITICAL 9.8
CVE-2025-15184

A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the file /home/refugeesreport2.p…

Mitigation only
Fix from $2,300 2025-12-29
Refugee Food Management System CRITICAL 9.8
CVE-2025-15183

A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown function of the file /home/vi…

Mitigation only
Fix from $2,300 2025-12-29
Refugee Food Management System CRITICAL 9.8
CVE-2025-15182

A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of the file /home/served.php. Ex…

Mitigation only
Fix from $2,300 2025-12-29
Refugee Food Management System CRITICAL 9.8
CVE-2025-15181

A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unknown function of the file /hom…

Mitigation only
Fix from $2,300 2025-12-29
Bpmflowwebkit CRITICAL 9.8
CVE-2025-15228

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and exe…

Fix: 5.0.5+
Fix from $2,300 2025-12-29
Wmpro CRITICAL 9.8
CVE-2025-15226

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdo…

Fix: after 5.2
Fix from $2,300 2025-12-29
Web Fax CRITICAL 9.8
CVE-2025-15069

Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 3.0.1

Fix: 4.0+
Fix from $2,300 2025-12-29
Web Fax CRITICAL 9.8
CVE-2025-15068

Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification through Manipulation.This issue…

Fix: 4.0+
Fix from $2,300 2025-12-29
Smartermail CRITICAL 10.0
CVE-2025-52691 KEVEPSS 86%

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po…

Fix: 100.0.9413+
Fix from $2,300 2025-12-29
Student Management System CRITICAL 9.8
CVE-2025-15168

A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such mani…

Mitigation only
Fix from $2,300 2025-12-29
Online Cake Ordering System CRITICAL 9.8
CVE-2025-15167

A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This…

Mitigation only
Fix from $2,300 2025-12-29
Online Cake Ordering System CRITICAL 9.8
CVE-2025-15166

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file /updatesupplier.php?action=ed…

Mitigation only
Fix from $2,300 2025-12-29
Online Cake Ordering System CRITICAL 9.8
CVE-2025-15165

A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown function of the file /updatecustom…

Mitigation only
Fix from $2,300 2025-12-29
Hotels Server CRITICAL 9.8
CVE-2025-15127

A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is so…

Fix: after 2019-03-23
Fix from $2,300 2025-12-28
Sxzos CRITICAL 9.8
CVE-2025-54322EPSS 15%

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and…

Fix: after 2025-12-26
Fix from $2,300 2025-12-27
Eigent CRITICAL 9.8
CVE-2025-68952

Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnera…

Mitigation only
Fix from $2,300 2025-12-27
Freshrss CRITICAL 9.8
CVE-2025-68932

FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() a…

Fix: 1.28.0+
Fix from $2,300 2025-12-27
Streamvault CRITICAL 9.1
CVE-2025-66203

StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault…

Fix: 251126+
Fix from $2,300 2025-12-27
N8n CRITICAL 9.9
CVE-2025-68668EPSS 13%

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node…

Fix: 2.0.0+
Fix from $2,300 2025-12-26
Cloudlog CRITICAL 9.8
CVE-2024-44065

Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

Mitigation only
Fix from $2,300 2025-12-26
Unclassified CRITICAL 9.3
CVE-2025-13158

Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object proto…

Mitigation only
Fix from $2,300 2025-12-26
Api Connect CRITICAL 9.8
CVE-2025-13915EPSS 9%

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acce…

Fix: after 10.0.8.5
Fix from $2,300 2025-12-26