Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-68775 In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations leak socket When a handshake r… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-65783 An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to … Hub Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.0 CVE-2025-12548 A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltratio… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.3 CVE-2026-22755EPSS 21% Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-0892 Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 147.0+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-0884 Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 1… Firefox 140.7.0 / 147.0+ Fix from $2,3002026-01-13 CRITICAL 10.0 CVE-2026-0881 Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. Firefox 147.0+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-0879 Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firef… Firefox 115.32.0 / 140.7.0+ Fix from $2,3002026-01-13 CRITICAL 9.1 CVE-2025-11250 Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations. Manageengine Adselfservice Plus 6.5+ Fix from $2,3002026-01-13 CRITICAL 10.0 CVE-2025-40805 Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to c… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.1 CVE-2025-14829 The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This ma… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-10915 The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check. Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.9 CVE-2026-0501 Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute cra… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.1 CVE-2026-0491 SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw en… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-22214 RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds… Riot 2025.10+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2026-22213 RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability… Riot 2025.10+ Fix from $2,3002026-01-12 CRITICAL 9.4 CVE-2025-67146 Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) train… Gym Management System No fix yet Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-29329 Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary… F\@st 3686 Firmware Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-12420EPSS 47% A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform t… Now Assist Ai Agents 3.15.2 / 4.0.4+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-67147 Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1… Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-66802 Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into … Covid 19 Contact Tracing System Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.1 CVE-2025-51567 A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary… Online Exam System No fix yet Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2026-22785 orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation l… Orval 7.18.0+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2026-22781 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via … Tinyweb 1.98+ Fix from $2,3002026-01-12 CRITICAL 9.9 CVE-2026-22252 LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without valida… Librechat Patch available Fix from $2,3002026-01-12 CRITICAL 9.1 CVE-2025-68472EPSS 19% MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the f… Mindsdb 25.11.1+ Fix from $2,3002026-01-12 CRITICAL 10.0 CVE-2025-63314 A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user pas… Cm3 Acora Cms Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-46070 An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component Botmanager Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.9 CVE-2025-46066 An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges Director No fix yet Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-65552 D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not impl… Zx G12 Firmware Mitigation only Fix from $2,3002026-01-12