Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2025-67968 Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue a… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.3 CVE-2025-67945 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2025-67944 Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-67617 Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a t… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-62056 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <=… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-62050 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.… Mitigation only Fix from $2,3002026-01-22 CRITICAL 10.0 CVE-2025-50002 Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects … Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.3 CVE-2025-49055 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-ca… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24009 Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML… Docling Core 2.48.4+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-69764 Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buff… Ax3 Firmware Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-23760 KEVEPSS 96% SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passw… Smartermail 100.0.9511+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-1325 A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-1324EPSS 7% A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-64097 NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vulnerability present starting … Nerveshub 2.3.0+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-1331 MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execu… Meetinghub Paperless Meetings 2025-12-10+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-0920 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24042 Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthentica… Appsmith after 1.94 Fix from $2,3002026-01-22 CRITICAL 9.6 CVE-2026-24002 Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases w… Grist Core 1.7.9+ Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2026-23966 sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists … Sm Crypto 0.3.14+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-23958 Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT s… Dataease 2.10.19+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-27378 AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this … On Prem Enterprise Server 7.0.6+ Fix from $2,3002026-01-22 CRITICAL 9.0 CVE-2026-23873 hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Form… Hustoj after 26.01.31 Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-23736 seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to im… Seroval 1.4.1+ Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2026-23524 Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from th… Reverb 1.7.0+ Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2026-23518 Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows … Fleet 4.53.3 / 4.75.2+ Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2026-22807 vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging … Vllm 0.14.0+ Fix from $2,3002026-01-21 CRITICAL 9.6 CVE-2026-22793 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsi… 5ire 0.15.3+ Fix from $2,3002026-01-21 CRITICAL 9.6 CVE-2026-22792 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe HTML renderi… 5ire 0.15.3+ Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2025-69766 Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buff… Ax3 Firmware Mitigation only Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2025-69763 Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remot… Ax3 Firmware Mitigation only Fix from $2,3002026-01-21