Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2025-69366 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Emerce Core emerce-core allows Bli… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69365 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Uroan Core uroan-core allows Blind… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69337 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Wolmart Core wolmart-core allows Bli… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69329 Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < … Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69310 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodly Core woodly-core allows Bli… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69309 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasplate Core saasplate-core allo… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69308 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestbyte Core nestbyte-core allows… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69307 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medinik Core medinik-core allows B… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69306 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Electio Core electio-core allows B… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69305 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete Core crete-core allows Blind… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69304 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allmart allmart-core allows Blind … Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69301 Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <=… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2025-69295 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.9 CVE-2025-68549 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affe… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-68541 Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-67997 Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-67996 Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-67995 Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a throu… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.9 CVE-2025-67979 Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows … Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.5 CVE-2026-21627 The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain c… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-10970 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL … Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.1 CVE-2026-26988EPSS 7% LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in th… Librenms 26.2.0+ Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-26974 Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically imports **/*.plugin.{js,mjs} file… Slyde 0.0.5+ Fix from $2,3002026-02-20 CRITICAL 10.0 CVE-2025-30416 Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Window… Cyber Protect Mitigation only Fix from $2,3002026-02-20 CRITICAL 10.0 CVE-2025-30412 Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Wind… Cyber Protect Mitigation only Fix from $2,3002026-02-20 CRITICAL 10.0 CVE-2025-30411 Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Wind… Cyber Protect Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-30410 Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Lin… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-27002 OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Doc… Openclaw 2026.2.15+ Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-27476 RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 … Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-67305 In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all… Ruckus Network Director 4.5.0.56+ Fix from $2,3002026-02-19