Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Directory Kit CRITICAL 9.8
CVE-2025-13390

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect impleme…

Fix: after 1.4.4
Fix from $2,300 2025-12-03
Unclassified CRITICAL 9.8
CVE-2025-13342

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to…

Mitigation only
Fix from $2,300 2025-12-03
Unclassified CRITICAL 9.8
CVE-2025-13486EPSS 68%

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_…

Mitigation only
Fix from $2,300 2025-12-03
Unclassified CRITICAL 9.3
CVE-2025-13658

A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence o…

Mitigation only
Fix from $2,300 2025-12-02
Unclassified CRITICAL 9.8
CVE-2025-13542

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlm…

Mitigation only
Fix from $2,300 2025-12-02
Unclassified CRITICAL 9.3
CVE-2025-13510

The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated u…

Mitigation only
Fix from $2,300 2025-12-02
Esp Idf CRITICAL 9.1
CVE-2025-66409

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on …

Fix: after 5.5.1
Fix from $2,300 2025-12-02
Asyncmy CRITICAL 9.8
CVE-2025-65896

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

Fix: after 0.2.10
Fix from $2,300 2025-12-02
Online Medicine Guide CRITICAL 9.8
CVE-2025-60736

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

Mitigation only
Fix from $2,300 2025-12-02
R15 Firmware CRITICAL 9.8
CVE-2025-60854

A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in…

Fix: after 1.20.01
Fix from $2,300 2025-12-02
Terminalfour CRITICAL 9.8
CVE-2025-58386

In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks.…

Fix: 8.4.1.2+
Fix from $2,300 2025-12-02
Dcat Admin CRITICAL 9.8
CVE-2025-65656

dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

Fix: after 2.2.3
Fix from $2,300 2025-12-02
Edoc Doctor Appointment System CRITICAL 9.8
CVE-2025-65358

Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

Mitigation only
Fix from $2,300 2025-12-02
Unclassified CRITICAL 9.0
CVE-2025-13828

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settin…

Mitigation only
Fix from $2,300 2025-12-02
Nshield 5c Firmware CRITICAL 9.1
CVE-2025-59703

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Pro…

Fix: 13.6.12 / 13.9.0+
Fix from $2,300 2025-12-02
Nshield 5c Firmware CRITICAL 9.8
CVE-2025-59695

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS r…

Fix: 13.6.12 / 13.9.0+
Fix from $2,300 2025-12-02
Nshield 5c Firmware CRITICAL 9.8
CVE-2025-59693

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.…

Fix: 13.6.12 / 13.9.0+
Fix from $2,300 2025-12-02
Gim CRITICAL 9.8
CVE-2025-41013

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete datab…

Fix: 2025-04-01+
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11788

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimite…

Mitigation only
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11786

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter …

Mitigation only
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11785

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited use…

Mitigation only
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11784

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user…

Mitigation only
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11783

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copy…

Mitigation only
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11782

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string…

Mitigation only
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11780

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user i…

Mitigation only
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11779

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is appli…

Mitigation only
Fix from $2,300 2025-12-02
Sge Plc1000 Firmware CRITICAL 9.8
CVE-2025-11778

Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption thr…

Mitigation only
Fix from $2,300 2025-12-02
Sprecon E C Firmware CRITICAL 9.1
CVE-2025-41744

Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communicatio…

Mitigation only
Fix from $2,300 2025-12-02
Sprecon E C Firmware CRITICAL 9.8
CVE-2025-41742

Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic key…

Mitigation only
Fix from $2,300 2025-12-02
Opinio CRITICAL 9.1
CVE-2025-13872

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an atta…

Mitigation only
Fix from $2,300 2025-12-02