Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-53433

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes EasyEat easyeat…

Mitigation only
Fix from $2,300 2025-12-18
Zerobyte CRITICAL 9.1
CVE-2025-68435

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication…

Fix: 0.18.5+
Fix from $2,300 2025-12-17
Model Context Protocol Servers CRITICAL 9.1
CVE-2025-68145EPSS 7%

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository…

Fix: 2025.12.18+
Fix from $2,300 2025-12-17
Online Appointment Booking System CRITICAL 9.8
CVE-2025-14833

A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /…

Mitigation only
Fix from $2,300 2025-12-17
Simple Cms CRITICAL 9.8
CVE-2023-53926

PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database querie…

Mitigation only
Fix from $2,300 2025-12-17
Ulicms CRITICAL 9.8
CVE-2023-53923

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserC…

Mitigation only
Fix from $2,300 2025-12-17
Tinywebgallery CRITICAL 9.8
CVE-2023-53922

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload …

Mitigation only
Fix from $2,300 2025-12-17
Sitemagic Cms CRITICAL 9.8
CVE-2023-53921

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. …

Mitigation only
Fix from $2,300 2025-12-17
Ulicms CRITICAL 9.8
CVE-2023-53914

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in …

Mitigation only
Fix from $2,300 2025-12-17
Freerdp CRITICAL 9.1
CVE-2025-68118

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling co…

Fix: 3.20.0+
Fix from $2,300 2025-12-17
Capstone CRITICAL 9.8
CVE-2025-68114

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.…

Fix: 6.0.0+
Fix from $2,300 2025-12-17
Drivelock CRITICAL 9.8
CVE-2025-67791

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentica…

Fix: after 25.1.6
Fix from $2,300 2025-12-17
Online Cake Ordering System CRITICAL 9.8
CVE-2025-14832

A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduc…

Mitigation only
Fix from $2,300 2025-12-17
Drivelock CRITICAL 9.8
CVE-2025-67793

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" …

Fix: 25.1.6+
Fix from $2,300 2025-12-17
Homarr CRITICAL 9.0
CVE-2025-67493

Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access …

Fix: 1.45.3+
Fix from $2,300 2025-12-17
Riot CRITICAL 9.8
CVE-2025-66647

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de…

Fix: 2025.10+
Fix from $2,300 2025-12-17
Safari CRITICAL 9.8
CVE-2025-43526

This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web…

Fix: 26.2+
Fix from $2,300 2025-12-17
Ipados CRITICAL 9.8
CVE-2025-43428

A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. P…

Fix: 26.2+
Fix from $2,300 2025-12-17
Drivelock CRITICAL 9.6
CVE-2025-67787

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a…

Mitigation only
Fix from $2,300 2025-12-17
Drivelock CRITICAL 9.9
CVE-2025-67781

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileg…

Fix: 24.1.6 / 24.2.7+
Fix from $2,300 2025-12-17
Ac10 Firmware CRITICAL 9.8
CVE-2025-67073

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial o…

Mitigation only
Fix from $2,300 2025-12-17
Avideo CRITICAL 9.1
CVE-2025-34434

AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints respon…

Fix: 20.0+
Fix from $2,300 2025-12-17
Churchcrm CRITICAL 9.8
CVE-2025-62521

ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM'…

Fix: 5.21.0+
Fix from $2,300 2025-12-17
Pagekit CRITICAL 9.8
CVE-2025-67165

An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.

Mitigation only
Fix from $2,300 2025-12-17
Pagekit CRITICAL 9.9
CVE-2025-67164

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2025-12-17
Asyncos CRITICAL 10.0
CVE-2025-20393 KEVEPSS 30%

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could …

Fix: 15.0.2-007 / 15.0.5-016+
Fix from $2,300 2025-12-17
Unclassified CRITICAL 10.0
CVE-2025-44005EPSS 9%

An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol a…

Mitigation only
Fix from $2,300 2025-12-17
Api Orchestrator CRITICAL 9.8
CVE-2022-23851

Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).

Fix: 0.19.3+
Fix from $2,300 2025-12-17
Apache Airflow Providers Edge3 CRITICAL 9.8
CVE-2025-67895

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on …

Fix: 2.0.0+
Fix from $2,300 2025-12-17
Live Update CRITICAL 9.8
CVE-2025-59374 KEV

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a sup…

Fix: 3.6.8+
Fix from $2,300 2025-12-17