Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-69079 Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue af… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-69052 Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-n… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-68986 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a Web Server.This issue affects … Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-68910 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious Files.This issue affects Blogzee:… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-68909 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious Files.This issue affects Blog… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-68869 Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privilege Escalation.This issue aff… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.3 CVE-2025-68857 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Downloads paid-downloads allows … Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.3 CVE-2025-68034 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp all… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.4 CVE-2025-68018 Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.0 CVE-2025-68015 Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scan… Mitigation only Fix from $2,3002026-01-22 CRITICAL 10.0 CVE-2025-68001 Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a Web Shell to a Web Server.Thi… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-67968 Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue a… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.3 CVE-2025-67945 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2025-67944 Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-67617 Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a t… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-62056 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <=… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-62050 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.… Mitigation only Fix from $2,3002026-01-22 CRITICAL 10.0 CVE-2025-50002 Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects … Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.3 CVE-2025-49055 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-ca… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24009 Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML… Docling Core 2.48.4+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-69764 Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buff… Ax3 Firmware Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-23760 KEVEPSS 96% SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passw… Smartermail 100.0.9511+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-1325 A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-1324EPSS 7% A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-64097 NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vulnerability present starting … Nerveshub 2.3.0+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-1331 MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execu… Meetinghub Paperless Meetings 2025-12-10+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-0920 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24042 Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthentica… Appsmith after 1.94 Fix from $2,3002026-01-22 CRITICAL 9.6 CVE-2026-24002 Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases w… Grist Core 1.7.9+ Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2026-23966 sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists … Sm Crypto 0.3.14+ Fix from $2,3002026-01-22