Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infinera Mtc 9 Firmware CRITICAL 9.8
CVE-2025-27019

Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system acces…

Fix: 23.0+
Fix from $2,300 2025-12-08
Simple Php Blog CRITICAL 9.8
CVE-2025-14227

A security flaw has been discovered in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This issue affects some unknown pro…

Fix: after 2025-01-22
Fix from $2,300 2025-12-08
Student Management System CRITICAL 9.8
CVE-2025-14226

A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The…

Mitigation only
Fix from $2,300 2025-12-08
Dm2 Firmware CRITICAL 9.8
CVE-2025-14224

A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the componen…

Fix: after 1.9.12
Fix from $2,300 2025-12-08
Simple Leave Manager CRITICAL 9.8
CVE-2025-14223

A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /req…

Mitigation only
Fix from $2,300 2025-12-08
Currency Exchange System CRITICAL 9.8
CVE-2025-14218

A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editother…

Mitigation only
Fix from $2,300 2025-12-08
Currency Exchange System CRITICAL 9.8
CVE-2025-14217

A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipul…

Mitigation only
Fix from $2,300 2025-12-08
Currency Exchange System CRITICAL 9.8
CVE-2025-14216

A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing of the file /viewserial.php.…

Mitigation only
Fix from $2,300 2025-12-08
Currency Exchange System CRITICAL 9.8
CVE-2025-14215

A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the file /edit.php. The manipulat…

Mitigation only
Fix from $2,300 2025-12-08
Advanced Library Management System CRITICAL 9.8
CVE-2025-14212

A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /memb…

Mitigation only
Fix from $2,300 2025-12-08
Advanced Library Management System CRITICAL 9.8
CVE-2025-14211

A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of t…

Mitigation only
Fix from $2,300 2025-12-08
Advanced Library Management System CRITICAL 9.8
CVE-2025-14210

A security vulnerability has been detected in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /dele…

Mitigation only
Fix from $2,300 2025-12-08
School File Management System CRITICAL 9.8
CVE-2025-14209

A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the file /update_query.php. This m…

Mitigation only
Fix from $2,300 2025-12-08
Unclassified CRITICAL 9.3
CVE-2023-53769

In the Linux kernel, the following vulnerability has been resolved: virt/coco/sev-guest: Double-buffer messages The encryption algorithms read and …

No fix yet
Fix from $2,300 2025-12-08
Unclassified CRITICAL 9.8
CVE-2023-53751

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname TCP_Server…

No fix yet
Fix from $2,300 2025-12-08
Unclassified CRITICAL 9.8
CVE-2025-40320

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_info_compound When smb2_query…

No fix yet
Fix from $2,300 2025-12-08
Verysync CRITICAL 9.8
CVE-2025-14199

A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text…

Fix: after 2.21.3
Fix from $2,300 2025-12-07
512w Firmware CRITICAL 9.8
CVE-2025-14191

A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. Affected by this issue is the function strcpy of the file /goform/formP2PLimitCon…

Fix: after 1.7.7-171114
Fix from $2,300 2025-12-07
Media Convergence System CRITICAL 9.8
CVE-2025-14182

A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the file /sobey-mchEditor/waterm…

Mitigation only
Fix from $2,300 2025-12-07
520w Firmware CRITICAL 9.8
CVE-2025-14141

A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formArpBindConfig. Executing man…

Mitigation only
Fix from $2,300 2025-12-06
Unclassified CRITICAL 9.8
CVE-2025-12673

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() f…

Mitigation only
Fix from $2,300 2025-12-06
Arrayos Ag CRITICAL 9.8
CVE-2025-66644 KEV

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

Fix: 9.4.5.9+
Fix from $2,300 2025-12-05
Cpp Httplib CRITICAL 9.8
CVE-2025-66570

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP he…

Fix: 0.27.0+
Fix from $2,300 2025-12-05
Tuui CRITICAL 9.6
CVE-2025-66562

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exi…

Fix: 1.3.4+
Fix from $2,300 2025-12-05
Wise Deviceon Server CRITICAL 9.8
CVE-2025-34256

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secre…

Fix: 5.4+
Fix from $2,300 2025-12-05
Unclassified CRITICAL 9.3
CVE-2020-36877

ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary…

No fix yet
Fix from $2,300 2025-12-05
Br 6478ac V3 Firmware CRITICAL 9.8
CVE-2025-14094EPSS 20%

A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulatio…

Mitigation only
Fix from $2,300 2025-12-05
Br 6478ac V3 Firmware CRITICAL 9.8
CVE-2025-14093EPSS 20%

A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The …

Mitigation only
Fix from $2,300 2025-12-05
X210 Firmware CRITICAL 9.6
CVE-2025-64054

A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially exec…

No fix yet
Fix from $2,300 2025-12-05
Unclassified CRITICAL 9.8
CVE-2025-12374

The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerab…

Mitigation only
Fix from $2,300 2025-12-05