Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gin Vue Admin CRITICAL 9.1
CVE-2025-66410

Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causi…

Fix: after 2.8.6
Fix from $2,300 2025-12-01
Gateway CRITICAL 9.8
CVE-2025-66405

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by priori…

Fix: 1.14.0+
Fix from $2,300 2025-12-01
Mcp Watch CRITICAL 9.8
CVE-2025-66401

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critica…

Fix: after 0.1.2
Fix from $2,300 2025-12-01
Grav CRITICAL 9.6
CVE-2025-66301

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /…

Fix: 1.8.0+
Fix from $2,300 2025-12-01
Frappe CRITICAL 9.8
CVE-2025-66205

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to…

Fix: 14.99.2 / 15.86.0+
Fix from $2,300 2025-12-01
Publiccms CRITICAL 9.1
CVE-2025-65836

PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

No fix yet
Fix from $2,300 2025-12-01
Mjobtime CRITICAL 9.8
CVE-2025-51683

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POS…

Mitigation only
Fix from $2,300 2025-12-01
Mjobtime CRITICAL 9.8
CVE-2025-51682

mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to administrative f…

Mitigation only
Fix from $2,300 2025-12-01
Antivirus CRITICAL 9.8
CVE-2025-3500

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: fro…

Fix: 25.3+
Fix from $2,300 2025-12-01
Blood Bank Management System CRITICAL 9.8
CVE-2025-63531

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properl…

Mitigation only
Fix from $2,300 2025-12-01
Openvpn CRITICAL 9.1
CVE-2025-12106

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

Mitigation only
Fix from $2,300 2025-12-01
Mogublog CRITICAL 9.8
CVE-2025-13815

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This man…

Fix: after 5.2
Fix from $2,300 2025-12-01
Mogublog CRITICAL 9.8
CVE-2025-13814

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the fil…

Fix: after 5.2
Fix from $2,300 2025-12-01
Nutzboot CRITICAL 9.8
CVE-2025-13806

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo…

Fix: after 2.6.0
Fix from $2,300 2025-12-01
B Qe2w401 Firmware CRITICAL 9.8
CVE-2025-13800EPSS 9%

A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The ma…

Fix: after 250814-r037c
Fix from $2,300 2025-12-01
B Qe2w401 Firmware CRITICAL 9.8
CVE-2025-13799EPSS 9%

A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.c…

Fix: after 250814-r037c
Fix from $2,300 2025-12-01
B Qe2w401 Firmware CRITICAL 9.8
CVE-2025-13798EPSS 7%

A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulat…

Fix: after 250814-r037c
Fix from $2,300 2025-12-01
B Qe2w401 Firmware CRITICAL 9.8
CVE-2025-13797EPSS 7%

A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cg…

Fix: after 250814-r037c
Fix from $2,300 2025-12-01
Unclassified CRITICAL 9.1
CVE-2025-35028EPSS 5%

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI…

Mitigation only
Fix from $2,300 2025-11-30
Chanjet Crm CRITICAL 9.8
CVE-2025-13788

A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. Th…

Fix: after 2025-11-06
Fix from $2,300 2025-11-30
Zentao CRITICAL 9.1
CVE-2025-13787

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the compo…

Fix: 21.7.7+
Fix from $2,300 2025-11-30
Wtcms CRITICAL 9.8
CVE-2025-13786

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. P…

Fix: after 2019-12-20
Fix from $2,300 2025-11-30
Wtcms CRITICAL 9.8
CVE-2025-13783

A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of…

Fix: after 2019-12-20
Fix from $2,300 2025-11-30
Wtcms CRITICAL 9.8
CVE-2025-13782

A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the f…

Fix: after 2019-12-20
Fix from $2,300 2025-11-30
Unclassified CRITICAL 9.8
CVE-2025-13615

The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the p…

Mitigation only
Fix from $2,300 2025-11-30
Ais Catcher CRITICAL 9.8
CVE-2025-66216

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message cla…

Fix: 0.64+
Fix from $2,300 2025-11-29
Willitmerge CRITICAL 9.8
CVE-2025-66219

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability i…

Fix: after 0.2.1
Fix from $2,300 2025-11-29
Fonttools CRITICAL 9.8
CVE-2025-66034

fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontT…

Fix: 4.60.2+
Fix from $2,300 2025-11-29
Pubnet CRITICAL 9.8
CVE-2025-65112

PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated use…

Fix: 1.1.4+
Fix from $2,300 2025-11-29
Unclassified CRITICAL 9.4
CVE-2025-66385

UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role s…

Patch available
Fix from $2,300 2025-11-28