Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nanomq CRITICAL 9.0
CVE-2025-59947

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shar…

Fix: 0.24.4+
Fix from $2,300 2025-12-15
A3300r Firmware CRITICAL 9.1
CVE-2025-55895

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Atta…

No fix yet
Fix from $2,300 2025-12-15
Bus Reservation System CRITICAL 9.8
CVE-2023-53877

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. At…

Mitigation only
Fix from $2,300 2025-12-15
Gom Player CRITICAL 9.8
CVE-2023-53874

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the applicati…

Mitigation only
Fix from $2,300 2025-12-15
Unclassified CRITICAL 9.3
CVE-2023-53872

Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execute arbitrary system commands.…

No fix yet
Fix from $2,300 2025-12-15
Soosyze CRITICAL 9.8
CVE-2023-53871

Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. At…

Mitigation only
Fix from $2,300 2025-12-15
Torch Musa CRITICAL 9.8
CVE-2025-65213

MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_singl…

Mitigation only
Fix from $2,300 2025-12-15
Grav CRITICAL 9.1
CVE-2025-66844

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the con…

Fix: 1.7.49.5+
Fix from $2,300 2025-12-15
Unclassified CRITICAL 9.1
CVE-2025-13888

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated per…

Patch available
Fix from $2,300 2025-12-15
Unclassified CRITICAL 9.8
CVE-2025-14156EPSS 7%

The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is …

Mitigation only
Fix from $2,300 2025-12-15
Hotels Server CRITICAL 9.8
CVE-2025-14711

A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the fi…

Fix: after 2019-03-23
Fix from $2,300 2025-12-15
Hotels Server CRITICAL 9.8
CVE-2025-14710

A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /…

Fix: after 2019-03-23
Fix from $2,300 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14709EPSS 6%

A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14707EPSS 19%

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the c…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14706EPSS 19%

A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the compo…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14705EPSS 17%

A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulati…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14704EPSS 12%

A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The m…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
Misp CRITICAL 9.0
CVE-2025-67906

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

Fix: 2.5.28+
Fix from $2,300 2025-12-15
Snap7 Rs CRITICAL 9.8
CVE-2025-14673

A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/…

Fix: after 1.142.1
Fix from $2,300 2025-12-14
Snap7 Rs CRITICAL 9.8
CVE-2025-14672

A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Exe…

Fix: after 1.142.1
Fix from $2,300 2025-12-14
Advanced Online Examination System CRITICAL 9.8
CVE-2025-14668

A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. P…

Mitigation only
Fix from $2,300 2025-12-14
Covid Tracking System CRITICAL 9.8
CVE-2025-14667

A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/…

Mitigation only
Fix from $2,300 2025-12-14
Covid Tracking System CRITICAL 9.8
CVE-2025-14666

A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. …

Mitigation only
Fix from $2,300 2025-12-14
Wh450 Firmware CRITICAL 9.8
CVE-2025-14665

A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP…

Mitigation only
Fix from $2,300 2025-12-14
Supplier Management System CRITICAL 9.8
CVE-2025-14664

A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.p…

Mitigation only
Fix from $2,300 2025-12-14
Student Management System CRITICAL 9.8
CVE-2025-14661

A vulnerability has been found in itsourcecode Student Managemen System 1.0. Affected by this issue is some unknown functionality of the file /advise…

Mitigation only
Fix from $2,300 2025-12-14
Dir 868l B1 Firmware CRITICAL 9.8
CVE-2025-14659

A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The man…

Fix: after 203b03
Fix from $2,300 2025-12-14
Student Management System CRITICAL 9.8
CVE-2025-14653

A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /addrecord.php. This manipu…

Mitigation only
Fix from $2,300 2025-12-14
Online Cake Ordering System CRITICAL 9.8
CVE-2025-14652

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?ac…

Mitigation only
Fix from $2,300 2025-12-14
Online Cake Ordering System CRITICAL 9.8
CVE-2025-14650

A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing mani…

Mitigation only
Fix from $2,300 2025-12-14