Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filezilla Client CRITICAL 9.8
CVE-2023-53959

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll i…

Mitigation only
Fix from $2,300 2025-12-19
Unclassified CRITICAL 9.8
CVE-2023-53951

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can l…

Mitigation only
Fix from $2,300 2025-12-19
Unclassified CRITICAL 9.8
CVE-2023-53950

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions throug…

Mitigation only
Fix from $2,300 2025-12-19
Unclassified CRITICAL 9.8
CVE-2023-53948

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary…

Mitigation only
Fix from $2,300 2025-12-19
Simple Stock System CRITICAL 9.8
CVE-2025-14968

A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown functionality of the file /marke…

Mitigation only
Fix from $2,300 2025-12-19
Student Management System CRITICAL 9.8
CVE-2025-14967

A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2025-12-19
T10 Firmware CRITICAL 9.8
CVE-2025-14964

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manip…

Mitigation only
Fix from $2,300 2025-12-19
Simple Blood Donor Management System CRITICAL 9.8
CVE-2025-14961

A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unknown function of the file /edit…

Mitigation only
Fix from $2,300 2025-12-19
Simple Blood Donor Management System CRITICAL 9.8
CVE-2025-14960

A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unknown function of the file /ed…

Mitigation only
Fix from $2,300 2025-12-19
Simple Stock System CRITICAL 9.8
CVE-2025-14959

A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of the file /market/signup.php. E…

Mitigation only
Fix from $2,300 2025-12-19
Dive CRITICAL 9.6
CVE-2025-66580

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS)…

Fix: 0.11.1+
Fix from $2,300 2025-12-19
Gt Edge Ai CRITICAL 9.8
CVE-2025-63665

An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into…

Fix: 2.0.12+
Fix from $2,300 2025-12-19
Galette CRITICAL 9.8
CVE-2025-58053

Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a s…

Fix: 1.2.0+
Fix from $2,300 2025-12-19
Unclassified CRITICAL 9.1
CVE-2024-49587

Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission…

Mitigation only
Fix from $2,300 2025-12-19
Unclassified CRITICAL 9.3
CVE-2025-34433

AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installati…

Patch available
Fix from $2,300 2025-12-19
Supplier Management System CRITICAL 9.8
CVE-2025-14952

A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Perfo…

Mitigation only
Fix from $2,300 2025-12-19
Scholars Tracking System CRITICAL 9.8
CVE-2025-14951

A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unknown function of the file /ho…

Mitigation only
Fix from $2,300 2025-12-19
Scholars Tracking System CRITICAL 9.8
CVE-2025-14950

A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.ph…

Mitigation only
Fix from $2,300 2025-12-19
Online Food Delivery System CRITICAL 9.1
CVE-2025-1928

Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows …

Mitigation only
Fix from $2,300 2025-12-19
Scholars Tracking System CRITICAL 9.8
CVE-2025-14940

A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /admin/delete_u…

Mitigation only
Fix from $2,300 2025-12-19
Mintlify CRITICAL 9.8
CVE-2025-67843

A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to e…

Fix: 2025-11-15+
Fix from $2,300 2025-12-19
Fireware CRITICAL 9.8
CVE-2025-14733 KEVEPSS 27%

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code…

Fix: 12.5.15 / 12.11.6+
Fix from $2,300 2025-12-19
Azure Cosmos Db CRITICAL 9.6
CVE-2025-64675

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp…

Mitigation only
Fix from $2,300 2025-12-19
Weblate CRITICAL 9.1
CVE-2025-68398

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i…

Fix: 5.15.1+
Fix from $2,300 2025-12-18
Partner Center CRITICAL 9.8
CVE-2025-65041

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-12-18
Azure Container Apps CRITICAL 10.0
CVE-2025-65037

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-12-18
Scrcpy CRITICAL 9.1
CVE-2025-34449

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deseriali…

Fix: 3.3.4+
Fix from $2,300 2025-12-18
Webaccess\/scada CRITICAL 9.1
CVE-2025-14850

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

Mitigation only
Fix from $2,300 2025-12-18
Webaccess\/scada CRITICAL 9.8
CVE-2025-14849

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

Mitigation only
Fix from $2,300 2025-12-18
Webserver CRITICAL 9.8
CVE-2023-53941EPSS 6%

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by i…

Mitigation only
Fix from $2,300 2025-12-18