Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Medivision Digital Signage Firmware CRITICAL 9.8
CVE-2020-36902

UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulatin…

Mitigation only
Fix from $2,300 2025-12-10
Qihang Media Web Digital Signage CRITICAL 9.1
CVE-2020-36898

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers t…

No fix yet
Fix from $2,300 2025-12-10
Qihang Media Web Digital Signage CRITICAL 9.8
CVE-2020-36897

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to u…

Mitigation only
Fix from $2,300 2025-12-10
I Media Server Digital Signage CRITICAL 9.8
CVE-2020-36892

Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attack…

Mitigation only
Fix from $2,300 2025-12-10
Snc Dh120t Firmware CRITICAL 9.8
CVE-2020-36885

Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execut…

Fix: after 1.82.01
Fix from $2,300 2025-12-10
Chancms CRITICAL 9.8
CVE-2025-65602

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST…

Mitigation only
Fix from $2,300 2025-12-10
Experience Manager CRITICAL 9.3
CVE-2025-64539

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrar…

Fix: 6.5.24.0 / 2025.12.0+
Fix from $2,300 2025-12-10
Experience Manager CRITICAL 9.3
CVE-2025-64538

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrar…

Fix: 6.5.24.0 / 2025.12.0+
Fix from $2,300 2025-12-10
Experience Manager CRITICAL 9.3
CVE-2025-64537

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrar…

Fix: 6.5.24.0 / 2025.12.0+
Fix from $2,300 2025-12-10
Unclassified CRITICAL 9.4
CVE-2025-13607

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

Mitigation only
Fix from $2,300 2025-12-10
Datagear CRITICAL 9.1
CVE-2025-65792

DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.

No fix yet
Fix from $2,300 2025-12-10
Rmm CRITICAL 9.8
CVE-2025-34394

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently p…

Fix: 2025.1.1+
Fix from $2,300 2025-12-10
Rmm CRITICAL 9.8
CVE-2025-34393

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-contro…

Fix: 2025.1.1+
Fix from $2,300 2025-12-10
Rmm CRITICAL 9.8
CVE-2025-34392EPSS 25%

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlle…

Fix: 2025.1.1+
Fix from $2,300 2025-12-10
X5000r Firmware CRITICAL 9.8
CVE-2025-13184EPSS 11%

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V…

Mitigation only
Fix from $2,300 2025-12-10
Unclassified CRITICAL 9.3
CVE-2025-13953

Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method.…

Mitigation only
Fix from $2,300 2025-12-10
0852 1328 Firmware CRITICAL 9.8
CVE-2025-41732

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buf…

Fix: 02.64+
Fix from $2,300 2025-12-10
0852 1328 Firmware CRITICAL 9.8
CVE-2025-41730

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack bu…

Fix: 02.64+
Fix from $2,300 2025-12-10
Enterprise Linux CRITICAL 9.8
CVE-2025-14087

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potenti…

Fix: 2.86.3+
Fix from $2,300 2025-12-10
Unclassified CRITICAL 9.3
CVE-2025-13955

Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain …

Mitigation only
Fix from $2,300 2025-12-10
Unclassified CRITICAL 9.3
CVE-2025-13954

Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full a…

Mitigation only
Fix from $2,300 2025-12-10
Unclassified CRITICAL 9.8
CVE-2025-13613

The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugi…

Mitigation only
Fix from $2,300 2025-12-10
Pipeshub CRITICAL 9.8
CVE-2025-67506

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/…

Patch available
Fix from $2,300 2025-12-10
Coldfusion CRITICAL 9.1
CVE-2025-61811

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code…

Mitigation only
Fix from $2,300 2025-12-10
Coldfusion CRITICAL 9.1
CVE-2025-61809

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security f…

Mitigation only
Fix from $2,300 2025-12-10
Coldfusion CRITICAL 9.1
CVE-2025-61808EPSS 10%

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could …

Mitigation only
Fix from $2,300 2025-12-10
Freepbx CRITICAL 9.8
CVE-2025-66039

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a…

Fix: 16.0.44 / 17.0.23+
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.8
CVE-2025-67489

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution…

Patch available
Fix from $2,300 2025-12-09
Minidvblinux CRITICAL 9.8
CVE-2023-53774

MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV …

Fix: after 5.4
Fix from $2,300 2025-12-09
Minidvblinux CRITICAL 9.8
CVE-2023-53771

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Att…

Fix: after 5.4
Fix from $2,300 2025-12-09