Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-40343

In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twice When forcefully shutting …

No fix yet
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14330

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun…

Fix: 140.6.0 / 146.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14326

Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.

Fix: 146.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14324

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund…

Fix: 115.31.0 / 140.6.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14321

Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 1…

Fix: 140.6.0 / 146.0+
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.3
CVE-2025-14310

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb.This issue affects rethinkdb: before 2.4.4.

Patch available
Fix from $2,300 2025-12-09
Robocode CRITICAL 9.8
CVE-2025-14308

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate t…

Patch available
Fix from $2,300 2025-12-09
Robocode CRITICAL 9.1
CVE-2025-14306

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly …

Patch available
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.8
CVE-2025-12504

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection. Thi…

Mitigation only
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.6
CVE-2025-11022

Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.  This CSRF vulnerability resulting …

Mitigation only
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.8
CVE-2022-50666

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix QP destroy to wait for all references dropped. Delay QP destroy c…

No fix yet
Fix from $2,300 2025-12-09
Deepchat CRITICAL 9.6
CVE-2025-66481

DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through impro…

Fix: after 0.5.1
Fix from $2,300 2025-12-09
Employee Profile Management System CRITICAL 9.8
CVE-2025-14285

A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_personnel.php. Th…

Mitigation only
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.8
CVE-2023-53794

In the Linux kernel, the following vulnerability has been resolved: cifs: fix session state check in reconnect to avoid use-after-free issue Don't …

No fix yet
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.1
CVE-2025-65849

A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of-Work nonce …

Mitigation only
Fix from $2,300 2025-12-08
Nutshell CRITICAL 9.1
CVE-2025-65548

NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage w…

Fix: 0.18.0+
Fix from $2,300 2025-12-08
Patients Waiting Area Queue Management System CRITICAL 9.8
CVE-2025-64081

SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to e…

Mitigation only
Fix from $2,300 2025-12-08
Student Management System CRITICAL 9.8
CVE-2025-14258

A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2025-12-08
Android CRITICAL 9.8
CVE-2025-48626

In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to r…

Patch available
Fix from $2,300 2025-12-08
Student Management System CRITICAL 9.8
CVE-2025-14257

A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /newrecord.php. Executing manipulati…

Mitigation only
Fix from $2,300 2025-12-08
Student Management System CRITICAL 9.8
CVE-2025-14256

A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performin…

Mitigation only
Fix from $2,300 2025-12-08
Emlog CRITICAL 9.1
CVE-2025-61318

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.ph…

No fix yet
Fix from $2,300 2025-12-08
Online Ordering System CRITICAL 9.8
CVE-2025-14251

A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the c…

Mitigation only
Fix from $2,300 2025-12-08
Online Ordering System CRITICAL 9.8
CVE-2025-14250

A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function of the file /user_contact.php…

Mitigation only
Fix from $2,300 2025-12-08
Online Ordering System CRITICAL 9.8
CVE-2025-14249

A security flaw has been discovered in code-projects Online Ordering System 1.0. The affected element is an unknown function of the file /user_school…

Mitigation only
Fix from $2,300 2025-12-08
Simple Shopping Cart CRITICAL 9.8
CVE-2025-14248

A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulati…

Mitigation only
Fix from $2,300 2025-12-08
Simple Shopping Cart CRITICAL 9.8
CVE-2025-14247

A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php.…

Mitigation only
Fix from $2,300 2025-12-08
Simple Shopping Cart CRITICAL 9.8
CVE-2025-14246

A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file /Customers/settings.php. Per…

Mitigation only
Fix from $2,300 2025-12-08
Ideacms CRITICAL 9.8
CVE-2025-14245

A vulnerability has been found in IdeaCMS up to 1.8. This affects the function whereRaw of the file app/common/logic/index/Coupon.php. Such manipulat…

Fix: after 1.8
Fix from $2,300 2025-12-08
Infinera Mtc 9 Firmware CRITICAL 9.8
CVE-2025-27020

Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file …

Fix: 23.0+
Fix from $2,300 2025-12-08