Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Server CRITICAL 9.9
CVE-2025-12421

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code…

Fix: 10.5.13 / 10.11.5+
Fix from $2,300 2025-11-27
Mattermost Server CRITICAL 9.9
CVE-2025-12419

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during O…

Fix: 10.5.13 / 10.11.5+
Fix from $2,300 2025-11-27
Unclassified CRITICAL 9.3
CVE-2025-8890

Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks. In order…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified CRITICAL 9.3
CVE-2025-12140

The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter' parameter. The appl…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified CRITICAL 9.8
CVE-2025-13675

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified CRITICAL 9.8
CVE-2025-13540

The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified CRITICAL 9.8
CVE-2025-13539

The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the pl…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified CRITICAL 9.8
CVE-2025-13538

The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'finda…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified CRITICAL 9.2
CVE-2024-5539

The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass …

Mitigation only
Fix from $2,300 2025-11-27
\ CRITICAL 9.3
CVE-2025-40934

XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the…

Fix: after 0.67
Fix from $2,300 2025-11-26
Hashtech CRITICAL 9.8
CVE-2025-65276

An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru comm…

Fix: after 2021-07-02
Fix from $2,300 2025-11-26
Imonnit CRITICAL 9.8
CVE-2025-50433

An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over ar…

Mitigation only
Fix from $2,300 2025-11-26
Classroomio CRITICAL 9.1
CVE-2025-65669

An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authent…

No fix yet
Fix from $2,300 2025-11-26
Ncp Secure Entry Client CRITICAL 9.8
CVE-2025-26155

NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 9.8
CVE-2025-64130

Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScrip…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 10.0
CVE-2025-64128

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 10.0
CVE-2025-64127

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are l…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 10.0
CVE-2025-64126

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without…

Mitigation only
Fix from $2,300 2025-11-26
Youlai Boot CRITICAL 9.8
CVE-2025-55469

Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

Mitigation only
Fix from $2,300 2025-11-26
Ussd Gateway CRITICAL 9.8
CVE-2025-65236

OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpan…

Mitigation only
Fix from $2,300 2025-11-26
Ussd Gateway CRITICAL 9.8
CVE-2025-65235

OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSu…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 9.8
CVE-2025-62354

Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands…

Mitigation only
Fix from $2,300 2025-11-26
Fac1200r Firmware CRITICAL 9.8
CVE-2025-50402

FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.

Mitigation only
Fix from $2,300 2025-11-26
Fac1200r Firmware CRITICAL 9.8
CVE-2025-50399

FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.

Mitigation only
Fix from $2,300 2025-11-26
Druid CRITICAL 9.8
CVE-2025-59390

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is…

Fix: 35.0.0+
Fix from $2,300 2025-11-26
Faction CRITICAL 9.8
CVE-2025-66022

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fra…

Fix: 1.7.1+
Fix from $2,300 2025-11-26
Unclassified CRITICAL 9.3
CVE-2025-66266

The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace…

Mitigation only
Fix from $2,300 2025-11-26
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66262

Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300…

Mitigation only
Fix from $2,300 2025-11-26
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66261

Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30…

Mitigation only
Fix from $2,300 2025-11-26
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66259

Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions …

Mitigation only
Fix from $2,300 2025-11-26