Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2023-53739

Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration back…

Mitigation only
Fix from $2,300 2025-12-09
Izero Box Full Firmware CRITICAL 9.8
CVE-2021-47731

Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocu…

Mitigation only
Fix from $2,300 2025-12-09
Izero Box Full Firmware CRITICAL 9.8
CVE-2021-47728

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbit…

Mitigation only
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.3
CVE-2021-47708

COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL …

No fix yet
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.3
CVE-2021-47707

COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can …

No fix yet
Fix from $2,300 2025-12-09
Elysia CRITICAL 9.8
CVE-2025-66456

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 throug…

Fix: 1.4.17+
Fix from $2,300 2025-12-09
Sublime Text 3 CRITICAL 9.8
CVE-2025-65741

Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of thi…

Fix: 3.2.2+
Fix from $2,300 2025-12-09
Emby CRITICAL 9.8
CVE-2025-64113

Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (…

Fix: 4.9.1.90+
Fix from $2,300 2025-12-09
Student Management System CRITICAL 9.8
CVE-2025-14337

A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /new_grade.php. This manipulat…

Mitigation only
Fix from $2,300 2025-12-09
Openmptcprouter CRITICAL 9.8
CVE-2025-65882

An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ip…

Fix: after 0.64
Fix from $2,300 2025-12-09
Student Management System CRITICAL 9.8
CVE-2025-14336

A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.ph…

Mitigation only
Fix from $2,300 2025-12-09
Student Management System CRITICAL 9.8
CVE-2025-14335

A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2025-12-09
Student Management System CRITICAL 9.8
CVE-2025-14334

A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_adviser.php. Executing manipula…

Mitigation only
Fix from $2,300 2025-12-09
Sharepoint Server CRITICAL 9.0
CVE-2025-64672

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19127.20378+
Fix from $2,300 2025-12-09
Fortiweb CRITICAL 9.8
CVE-2025-59719EPSS 30%

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.…

Fix: after 7.6.4
Fix from $2,300 2025-12-09
Fortiproxy CRITICAL 9.8
CVE-2025-59718 KEVEPSS 69%

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 …

Fix: 7.0.6 / 7.0.18+
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.3
CVE-2025-34414

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 …

Mitigation only
Fix from $2,300 2025-12-09
Rockoa CRITICAL 9.8
CVE-2025-63742

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain…

Mitigation only
Fix from $2,300 2025-12-09
Wbce Cms CRITICAL 9.8
CVE-2025-67504

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand(…

Fix: 1.6.5+
Fix from $2,300 2025-12-09
Csla .net CRITICAL 9.8
CVE-2025-66631

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow t…

Fix: 6.0.0+
Fix from $2,300 2025-12-09
Ruby Saml CRITICAL 9.1
CVE-2025-66568

The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypa…

Fix: 1.18.0+
Fix from $2,300 2025-12-09
Ruby Saml CRITICAL 9.1
CVE-2025-66567

The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentic…

Fix: 1.18.0+
Fix from $2,300 2025-12-09
Utils CRITICAL 9.8
CVE-2025-66565

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number ge…

Fix: after 1.2.0
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.1
CVE-2025-42928EPSS 9%

Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The s…

Mitigation only
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.9
CVE-2025-42880

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled functio…

Mitigation only
Fix from $2,300 2025-12-09
Simatic Cn 4100 Firmware CRITICAL 9.8
CVE-2025-40938

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. Thi…

Fix: 4.0.1+
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.8
CVE-2025-40343

In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twice When forcefully shutting …

No fix yet
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14330

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun…

Fix: 140.6.0 / 146.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14326

Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.

Fix: 146.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14324

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund…

Fix: 115.31.0 / 140.6.0+
Fix from $2,300 2025-12-09