Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Online Student Enrollment System CRITICAL 9.8
CVE-2025-14583

A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing …

Mitigation only
Fix from $2,300 2025-12-12
Centrestack CRITICAL 9.8
CVE-2025-14611 KEVEPSS 53%

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degr…

Fix: 16.12.10420.56791+
Fix from $2,300 2025-12-12
Student Management System CRITICAL 9.8
CVE-2025-14578

A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /update_account…

Mitigation only
Fix from $2,300 2025-12-12
Unclassified CRITICAL 9.8
CVE-2024-58311

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique id…

Mitigation only
Fix from $2,300 2025-12-12
Unclassified CRITICAL 9.8
CVE-2024-58299

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers …

Mitigation only
Fix from $2,300 2025-12-12
Unclassified CRITICAL 9.8
CVE-2024-14010

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Att…

Mitigation only
Fix from $2,300 2025-12-12
Advanced Library Management System CRITICAL 9.8
CVE-2025-14571

A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the f…

Mitigation only
Fix from $2,300 2025-12-12
Advanced Library Management System CRITICAL 9.8
CVE-2025-14570

A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file…

Mitigation only
Fix from $2,300 2025-12-12
Plesk CRITICAL 9.1
CVE-2025-66430

Plesk 18.0 has Incorrect Access Control.

Fix: 18.0.73.5 / 18.0.74.2+
Fix from $2,300 2025-12-12
Mineadmin CRITICAL 9.8
CVE-2025-65854

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeo…

Fix: 3.0+
Fix from $2,300 2025-12-12
Courseselectionsystem CRITICAL 9.8
CVE-2025-14566

A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknow…

Fix: after 2017-06-18
Fix from $2,300 2025-12-12
Courseselectionsystem CRITICAL 9.8
CVE-2025-14565

A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown fun…

Fix: after 2017-06-18
Fix from $2,300 2025-12-12
Streampark CRITICAL 9.8
CVE-2025-54947

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…

Fix: 2.1.7+
Fix from $2,300 2025-12-12
Fineract CRITICAL 9.1
CVE-2025-58130

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in ver…

Fix: 1.12.1+
Fix from $2,300 2025-12-12
Fireshare CRITICAL 9.8
CVE-2025-67728

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Publi…

Fix: 1.3.0+
Fix from $2,300 2025-12-12
Parse Server CRITICAL 9.8
CVE-2025-67727

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI …

Fix: after 8.5.0
Fix from $2,300 2025-12-12
Unclassified CRITICAL 9.8
CVE-2025-14344

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'p…

Mitigation only
Fix from $2,300 2025-12-12
Unclassified CRITICAL 9.8
CVE-2025-12963

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via a…

Mitigation only
Fix from $2,300 2025-12-12
Maxkb CRITICAL 10.0
CVE-2025-66419

MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environmen…

Fix: 2.4.0+
Fix from $2,300 2025-12-11
Sandboxie CRITICAL 10.0
CVE-2025-64721

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the SYSTEM-le…

Fix: 1.16.7+
Fix from $2,300 2025-12-11
Xbtitfm CRITICAL 9.8
CVE-2024-58309

xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malic…

Mitigation only
Fix from $2,300 2025-12-11
Quick Cms CRITICAL 9.8
CVE-2024-58308

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login f…

Mitigation only
Fix from $2,300 2025-12-11
Unclassified CRITICAL 9.3
CVE-2024-58301

Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user in…

No fix yet
Fix from $2,300 2025-12-11
Unclassified CRITICAL 9.2
CVE-2024-58298

Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicio…

No fix yet
Fix from $2,300 2025-12-11
Unclassified CRITICAL 9.3
CVE-2024-58290

Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queri…

No fix yet
Fix from $2,300 2025-12-11
Unclassified CRITICAL 9.3
CVE-2024-58286

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path s…

No fix yet
Fix from $2,300 2025-12-11
Daqfactory CRITICAL 9.8
CVE-2025-66590

In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write …

Fix: 21.1+
Fix from $2,300 2025-12-11
Daqfactory CRITICAL 9.1
CVE-2025-66589

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read da…

Fix: 21.1+
Fix from $2,300 2025-12-11
Daqfactory CRITICAL 9.8
CVE-2025-66588

In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by an attacker which can lead to …

Fix: 21.1+
Fix from $2,300 2025-12-11
Class And Exam Timetable Management System CRITICAL 9.8
CVE-2025-14537

A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some unknown functionality of the …

Mitigation only
Fix from $2,300 2025-12-11