Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dify CRITICAL 9.8
CVE-2025-56157

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE:…

Fix: after 1.5.1
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.8
CVE-2025-64236

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: fr…

No fix yet
Fix from $2,300 2025-12-18
Wh450 Firmware CRITICAL 9.8
CVE-2025-14879EPSS 7%

A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Reques…

Mitigation only
Fix from $2,300 2025-12-18
Ollama CRITICAL 9.8
CVE-2025-63389

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp…

Fix: after 0.12.3
Fix from $2,300 2025-12-18
Dify CRITICAL 9.1
CVE-2025-63388

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoin…

Mitigation only
Fix from $2,300 2025-12-18
Dify CRITICAL 9.1
CVE-2025-63386

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implemen…

Patch available
Fix from $2,300 2025-12-18
Wh450 Firmware CRITICAL 9.8
CVE-2025-14878

A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HT…

Mitigation only
Fix from $2,300 2025-12-18
Supplier Management System CRITICAL 9.8
CVE-2025-14877

A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The…

Mitigation only
Fix from $2,300 2025-12-18
Soliclub CRITICAL 9.8
CVE-2025-7358

Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. This issue affects SoliClub: b…

Fix: 5.3.7+
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.4
CVE-2025-65008

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in the adm.cgi endpoint, the mal…

Mitigation only
Fix from $2,300 2025-12-18
Firefox CRITICAL 9.8
CVE-2025-14860

Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.

Fix: 146.0.1+
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.3
CVE-2025-10910

A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.1
CVE-2025-66078

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote …

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.0
CVE-2025-66074

Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webho…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.9
CVE-2025-64374

Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors:…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.8
CVE-2025-64233

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.9
CVE-2025-64231

Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordp…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.8
CVE-2025-64227

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue af…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.8
CVE-2025-64206

Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.8
CVE-2025-64188

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through …

Mitigation only
Fix from $2,300 2025-12-18
Wp Gravity Forms Salesforce CRITICAL 9.8
CVE-2025-60180

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue af…

Fix: 1.5.2+
Fix from $2,300 2025-12-18
Wp Gravity Forms Hubspot CRITICAL 9.8
CVE-2025-60178

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravit…

Fix: 1.2.7+
Fix from $2,300 2025-12-18
Wp Gravity Forms Constant Contact Plugin CRITICAL 9.8
CVE-2025-60174

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.Thi…

Fix: after 1.1.2
Fix from $2,300 2025-12-18
Wp Gravity Forms Zoho Crm And Bigin CRITICAL 9.8
CVE-2025-60091

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects W…

Fix: 1.3.0+
Fix from $2,300 2025-12-18
Wp Gravity Forms Insightly CRITICAL 9.8
CVE-2025-60090

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gr…

Fix: 1.1.7+
Fix from $2,300 2025-12-18
Wp Gravity Forms Freshdesk Plugin CRITICAL 9.8
CVE-2025-60089

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affect…

Fix: 1.3.6+
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.3
CVE-2025-60062

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-wit…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.3
CVE-2025-58951

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management fo…

Mitigation only
Fix from $2,300 2025-12-18
Lunna CRITICAL 9.8
CVE-2025-58935

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Lunna lunna allo…

Fix: after 1.15
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.8
CVE-2025-54723

Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue affects DentiCare: from n/a thro…

Mitigation only
Fix from $2,300 2025-12-18