Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-13313

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is …

Mitigation only
Fix from $2,300 2025-12-05
Lara Dashboard CRITICAL 9.8
CVE-2025-66509

LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowin…

Fix: after 2.3.0
Fix from $2,300 2025-12-04
Remote Keyboard Desktop CRITICAL 9.8
CVE-2025-66576

Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthentic…

Mitigation only
Fix from $2,300 2025-12-04
Unclassified CRITICAL 9.3
CVE-2025-66571

UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter…

No fix yet
Fix from $2,300 2025-12-04
All Rut22gw Firmware CRITICAL 9.8
CVE-2025-29269

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

Mitigation only
Fix from $2,300 2025-12-04
All Rut22gw Firmware CRITICAL 9.8
CVE-2025-29268EPSS 8%

ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

Mitigation only
Fix from $2,300 2025-12-04
Carelink Network CRITICAL 9.8
CVE-2025-12995

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determi…

Fix: 2025-12-04+
Fix from $2,300 2025-12-04
Rs232\/485 To Wifi Eth \(b\) Firmware CRITICAL 9.8
CVE-2025-63362

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to…

Mitigation only
Fix from $2,300 2025-12-04
Magic B0 Firmware CRITICAL 9.8
CVE-2025-14015

A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulatio…

Fix: after 100R002
Fix from $2,300 2025-12-04
Tika CRITICAL 9.8
CVE-2025-66516EPSS 80%

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…

Fix: 3.2.2+
Fix from $2,300 2025-12-04
Unclassified CRITICAL 9.8
CVE-2025-40261

In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_f…

Mitigation only
Fix from $2,300 2025-12-04
Unclassified CRITICAL 9.8
CVE-2025-40258

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-fr…

No fix yet
Fix from $2,300 2025-12-04
Unclassified CRITICAL 9.8
CVE-2025-40257

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptcp_pm_del_add_timer() can call…

No fix yet
Fix from $2,300 2025-12-04
Unclassified CRITICAL 9.8
CVE-2025-40252

In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_t…

Mitigation only
Fix from $2,300 2025-12-04
Laravel File Manager CRITICAL 9.1
CVE-2025-65346

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive con…

Fix: after 3.3.1
Fix from $2,300 2025-12-04
Ion Torrent Onetouch 2 Firmware CRITICAL 9.8
CVE-2025-54304

An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The d…

Mitigation only
Fix from $2,300 2025-12-04
Torrent Suite Software CRITICAL 9.8
CVE-2025-54303

The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The iona…

Mitigation only
Fix from $2,300 2025-12-04
Ion Torrent Onetouch 2 Firmware CRITICAL 9.8
CVE-2025-53963

An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The r…

Mitigation only
Fix from $2,300 2025-12-04
Diskstation Manager CRITICAL 9.6
CVE-2024-45538

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Sy…

Fix: 3.1.4-23079 / 7.2.1-69057-2+
Fix from $2,300 2025-12-04
Xunruicms CRITICAL 9.8
CVE-2025-14004

A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add…

Fix: after 4.7.1
Fix from $2,300 2025-12-04
X210 Firmware CRITICAL 9.8
CVE-2025-64055

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the d…

Mitigation only
Fix from $2,300 2025-12-03
Cal.com CRITICAL 9.8
CVE-2025-66489

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verificati…

Fix: 5.9.8+
Fix from $2,300 2025-12-03
Deepchat CRITICAL 9.6
CVE-2025-66222

DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the M…

Fix: after 0.5.0
Fix from $2,300 2025-12-03
Online CRITICAL 9.8
CVE-2025-66208

Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online.…

Fix: 25.04.702+
Fix from $2,300 2025-12-03
Claude Code CRITICAL 9.8
CVE-2025-66032

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible …

Fix: 1.0.93+
Fix from $2,300 2025-12-03
Mcp Gateway CRITICAL 9.6
CVE-2025-64443

MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming t…

Fix: 0.28.0+
Fix from $2,300 2025-12-03
Unclassified CRITICAL 9.3
CVE-2025-34319

TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vul…

Mitigation only
Fix from $2,300 2025-12-03
Masacms CRITICAL 9.8
CVE-2024-32641EPSS 12%

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code …

Fix: 7.2.8 / 7.3.13+
Fix from $2,300 2025-12-03
React CRITICAL 10.0
CVE-2025-55182 KEVEPSS 100%

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the …

Fix: 15.0.5 / 15.1.9+
Fix from $2,300 2025-12-03
Erpnext CRITICAL 9.0
CVE-2025-65267

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. …

Mitigation only
Fix from $2,300 2025-12-03