Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2025-41006 Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’. Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-69270 Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.Thi… Dx Netops Spectrum 24.3.9+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-69269 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, L… Dx Netops Spectrum 23.3.7+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2025-52694EPSS 39% Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vu… Iot Edge Linux Docker 2.0.2 / 3.4.15+ Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2026-0852 A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PH… Online Music Site Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2026-0851 A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/Adm… Online Music Site Mitigation only Fix from $2,3002026-01-12 CRITICAL 9.8 CVE-2026-0821 A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file qui… Quickjs after 0.11.0 Fix from $2,3002026-01-10 CRITICAL 9.8 CVE-2025-15503 A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function o… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-10 CRITICAL 9.8 CVE-2025-15502EPSS 6% A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionContro… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-10 CRITICAL 9.8 CVE-2026-22685 DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension i… Devtoys 2.0.9.0+ Fix from $2,3002026-01-10 CRITICAL 9.8 CVE-2026-22687 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables th… Weknora 0.2.5+ Fix from $2,3002026-01-10 CRITICAL 10.0 CVE-2025-65091 XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONServi… Full Calendar Macro 2.4.5+ Fix from $2,3002026-01-10 CRITICAL 9.1 CVE-2025-61686EPSS 17% React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node … React Router\/node 2.17.2 / 7.9.4+ Fix from $2,3002026-01-10 CRITICAL 9.1 CVE-2026-22600 OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun… Openproject 16.6.4+ Fix from $2,3002026-01-10 CRITICAL 9.8 CVE-2025-15501EPSS 7% A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of th… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2026-22584 Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code… Uni2ts 2.0.0+ Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15500EPSS 6% A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file … Operation And Maintenance Management System after 3.0.8 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15499EPSS 5% A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN o… Operation And Maintenance Management System after 3.0.8 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-70161EPSS 25% EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the … Br 6208ac Firmware Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-69542EPSS 9% A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease r… Dir 895la1 Firmware Mitigation only Fix from $2,3002026-01-09 CRITICAL 10.0 CVE-2025-69426 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an … Mitigation only Fix from $2,3002026-01-09 CRITICAL 10.0 CVE-2025-69425 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privile… Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15496 A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of th… Yshopmall after 1.9.1 Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-15493 A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMa… Docsys after 2.02.36 Fix from $2,3002026-01-09 CRITICAL 9.3 CVE-2020-36875 AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The pl… Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-14598 BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables ar… Bet E Portal Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.3 CVE-2025-7072 The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an una… Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-66050 Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is… Ip7137 Firmware Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-64093 Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device. Icx500 Firmware 1.4.3.3+ Fix from $2,3002026-01-09 CRITICAL 9.6 CVE-2025-13761 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unau… GitLab 18.6.3+ Fix from $2,3002026-01-09