Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-68726

In the Linux kernel, the following vulnerability has been resolved: crypto: aead - Fix reqsize handling Commit afddce13ce81d ("crypto: api - Add re…

No fix yet
Fix from $2,300 2025-12-24
Unclassified CRITICAL 9.8
CVE-2025-68359

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of qgroup record after failure to add delayed ref head I…

Mitigation only
Fix from $2,300 2025-12-24
Unclassified CRITICAL 9.3
CVE-2023-53996

In the Linux kernel, the following vulnerability has been resolved: x86/sev: Make enc_dec_hypercall() accept a size instead of npages enc_dec_hyper…

Mitigation only
Fix from $2,300 2025-12-24
Unclassified CRITICAL 9.8
CVE-2023-53867

In the Linux kernel, the following vulnerability has been resolved: ceph: fix potential use-after-free bug when trimming caps When trimming the cap…

Mitigation only
Fix from $2,300 2025-12-24
Unclassified CRITICAL 9.8
CVE-2025-13773

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, …

Mitigation only
Fix from $2,300 2025-12-24
5ire CRITICAL 9.6
CVE-2025-68669

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerabil…

Fix: 0.15.2+
Fix from $2,300 2025-12-23
Unclassified CRITICAL 9.9
CVE-2025-68667

Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows a remote, unauthenticated att…

Patch available
Fix from $2,300 2025-12-23
Langchain.js CRITICAL 9.1
CVE-2025-68665

LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0…

Fix: 0.3.37 / 0.3.80+
Fix from $2,300 2025-12-23
Online Farm System CRITICAL 9.8
CVE-2025-15049

A vulnerability was identified in code-projects Online Farm System 1.0. Affected is an unknown function of the file /addProduct.php. The manipulation…

Mitigation only
Fix from $2,300 2025-12-23
Wh450 Firmware CRITICAL 9.8
CVE-2025-15048EPSS 12%

A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request…

Mitigation only
Fix from $2,300 2025-12-23
Wh450 Firmware CRITICAL 9.8
CVE-2025-15047

A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Han…

Mitigation only
Fix from $2,300 2025-12-23
Wh450 Firmware CRITICAL 9.8
CVE-2025-15046

A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component H…

Mitigation only
Fix from $2,300 2025-12-23
Unclassified CRITICAL 9.8
CVE-2025-14500

IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $2,300 2025-12-23
Wh450 Firmware CRITICAL 9.8
CVE-2025-15045

A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit of the component HTTP Request…

Mitigation only
Fix from $2,300 2025-12-23
Wh450 Firmware CRITICAL 9.8
CVE-2025-15044

A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetting. The manipulation of the a…

Mitigation only
Fix from $2,300 2025-12-23
Unclassified CRITICAL 10.0
CVE-2025-14931

Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot…

Mitigation only
Fix from $2,300 2025-12-23
Event Management CRITICAL 9.8
CVE-2025-65354

Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST pa…

Mitigation only
Fix from $2,300 2025-12-23
Cadmium Cms CRITICAL 9.8
CVE-2025-51511

Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.

Mitigation only
Fix from $2,300 2025-12-23
Isaac Launchable CRITICAL 9.8
CVE-2025-33224

NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this…

Mitigation only
Fix from $2,300 2025-12-23
Isaac Launchable CRITICAL 9.8
CVE-2025-33223

NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this…

Mitigation only
Fix from $2,300 2025-12-23
Isaac Launchable CRITICAL 9.8
CVE-2025-33222

NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerab…

Mitigation only
Fix from $2,300 2025-12-23
E5600 Firmware CRITICAL 9.8
CVE-2025-29229

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

Mitigation only
Fix from $2,300 2025-12-23
E5600 Firmware CRITICAL 9.8
CVE-2025-29228

Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

Mitigation only
Fix from $2,300 2025-12-23
Ruoyi CRITICAL 10.0
CVE-2024-57521

SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.ja…

Fix: after 4.7.9
Fix from $2,300 2025-12-23
Cyclone Data Distribution Service CRITICAL 10.0
CVE-2025-67109

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute command…

Fix: 0.10.5+
Fix from $2,300 2025-12-23
Fast Dds CRITICAL 10.0
CVE-2025-67108

eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.

Mitigation only
Fix from $2,300 2025-12-23
Ex8000 Firmware CRITICAL 9.8
CVE-2025-50526

Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

Mitigation only
Fix from $2,300 2025-12-23
Unclassified CRITICAL 9.8
CVE-2025-68341

In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix race As explain in commit fa34…

Mitigation only
Fix from $2,300 2025-12-23
Unclassified CRITICAL 9.8
CVE-2025-14388

The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including…

Mitigation only
Fix from $2,300 2025-12-23
Student Management System CRITICAL 9.8
CVE-2025-15034

A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the file /record.php. The manipula…

Mitigation only
Fix from $2,300 2025-12-23