Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xm530v200 X6 Weq 8m Firmware CRITICAL 9.8
CVE-2025-65856

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated rem…

Mitigation only
Fix from $2,300 2025-12-22
Projectsend CRITICAL 9.8
CVE-2023-53980

ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Att…

Mitigation only
Fix from $2,300 2025-12-22
Sft Dab 600\/c Firmware CRITICAL 9.8
CVE-2023-53968

Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting…

Mitigation only
Fix from $2,300 2025-12-22
Linkandshare Transmitter CRITICAL 9.8
CVE-2023-53966

SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciou…

Mitigation only
Fix from $2,300 2025-12-22
Impact Firmware CRITICAL 9.8
CVE-2023-53964

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attac…

Mitigation only
Fix from $2,300 2025-12-22
Impact Firmware CRITICAL 9.8
CVE-2023-53963

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary s…

Mitigation only
Fix from $2,300 2025-12-22
First Firmware CRITICAL 9.8
CVE-2023-53960

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers t…

Mitigation only
Fix from $2,300 2025-12-22
Stream Extension CRITICAL 9.8
CVE-2023-53955

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and acces…

Mitigation only
Fix from $2,300 2025-12-22
Clipbucket CRITICAL 9.8
CVE-2025-67418

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative crede…

Fix: after 5.5.2
Fix from $2,300 2025-12-22
Mynet CRITICAL 9.6
CVE-2024-27708

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via …

Fix: after 26.06
Fix from $2,300 2025-12-22
Umbraco Cms CRITICAL 10.0
CVE-2025-67288

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this …

Mitigation only
Fix from $2,300 2025-12-22
Erpnext CRITICAL 9.6
CVE-2025-67289

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2025-12-22
Unclassified CRITICAL 9.5
CVE-2025-11545

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a attacker may …

Mitigation only
Fix from $2,300 2025-12-22
Unclassified CRITICAL 9.5
CVE-2025-11544

Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized fi…

Mitigation only
Fix from $2,300 2025-12-22
Refugee Food Management System CRITICAL 9.8
CVE-2025-15012

A vulnerability was determined in code-projects Refugee Food Management System 1.0. The affected element is an unknown function of the file /home/hom…

Mitigation only
Fix from $2,300 2025-12-22
Mp 01 Firmware CRITICAL 9.8
CVE-2025-12049

Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to…

Mitigation only
Fix from $2,300 2025-12-22
Np P502h Firmware CRITICAL 9.8
CVE-2025-11543

Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized fi…

Mitigation only
Fix from $2,300 2025-12-22
Np P502h Firmware CRITICAL 9.8
CVE-2025-11542

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.

Mitigation only
Fix from $2,300 2025-12-22
Np P502h Firmware CRITICAL 9.8
CVE-2025-11541

Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs.

Mitigation only
Fix from $2,300 2025-12-22
Enterprise Cloud Database CRITICAL 9.8
CVE-2025-15016

Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit t…

Mitigation only
Fix from $2,300 2025-12-22
Simple Stock System CRITICAL 9.8
CVE-2025-15011

A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.php. The manipulation of the …

Mitigation only
Fix from $2,300 2025-12-22
Wh450 Firmware CRITICAL 9.8
CVE-2025-15010

A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulatio…

Mitigation only
Fix from $2,300 2025-12-22
Wh450 Firmware CRITICAL 9.8
CVE-2025-15008

A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. …

Mitigation only
Fix from $2,300 2025-12-22
Wh450 Firmware CRITICAL 9.8
CVE-2025-15007

A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of …

Mitigation only
Fix from $2,300 2025-12-22
Wh450 Firmware CRITICAL 9.8
CVE-2025-15006

A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of …

Mitigation only
Fix from $2,300 2025-12-22
Seacms CRITICAL 9.8
CVE-2025-15002

A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.cla…

Fix: after 13.3
Fix from $2,300 2025-12-21
Complete Online Beauty Parlor Management System CRITICAL 9.8
CVE-2025-14990

A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /ad…

Mitigation only
Fix from $2,300 2025-12-21
Complete Online Beauty Parlor Management System CRITICAL 9.8
CVE-2025-14989

A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the fi…

Mitigation only
Fix from $2,300 2025-12-21
Unclassified CRITICAL 9.8
CVE-2025-13619

The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUs…

Mitigation only
Fix from $2,300 2025-12-20
Unclassified CRITICAL 9.8
CVE-2025-13329

The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback fu…

Mitigation only
Fix from $2,300 2025-12-20