Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-64093 Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device. Icx500 Firmware 1.4.3.3+ Fix from $2,3002026-01-09 CRITICAL 9.6 CVE-2025-13761 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unau… GitLab 18.6.3+ Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-69194 A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Meta… Wget2 2.2.1+ Fix from $2,3002026-01-09 CRITICAL 9.1 CVE-2025-14741 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a … Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.1 CVE-2026-20973 Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory. Android Mitigation only Fix from $2,3002026-01-09 CRITICAL 10.0 CVE-2025-70974 Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, t… Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-14736 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is du… Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2026-0732EPSS 10% A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the ar… Di 8200g Firmware Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.4 CVE-2025-68717 KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /… Ks Wr3600 Firmware No fix yet Fix from $2,3002026-01-08 CRITICAL 9.1 CVE-2025-68715 An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /go… Pwru01 Firmware No fix yet Fix from $2,3002026-01-08 CRITICAL 9.4 CVE-2025-66916 The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expres… Ruoyi Vue Plus after 5.5.1 Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-66913 JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacke… Jimureport after 2.1.3 Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-67325 Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote … Qloapps after 1.7.0 Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-22234 OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predict… Ecase Portal 9.0.45.0+ Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-61548 SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions… Print Shop Pro Webdesk Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.1 CVE-2025-61546 There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed i… Print Shop Pro Webdesk No fix yet Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-61246 indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter. Online Shopping System Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.0 CVE-2025-59470 This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order para… Veeam Backup \& Replication 13.0.1.1071+ Fix from $2,3002026-01-08 CRITICAL 9.0 CVE-2025-59469 This vulnerability allows a Backup or Tape Operator to write files as root. Veeam Backup \& Replication 13.0.1.1071+ Fix from $2,3002026-01-08 CRITICAL 9.1 CVE-2025-59468 This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password paramet… Veeam Backup \& Replication 13.0.1.1071+ Fix from $2,3002026-01-08 CRITICAL 9.1 CVE-2025-56425 An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.18… Enaio 10.10.0.183 / 11.0.0.183+ Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-55125 This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. Veeam Backup \& Replication 13.0.1.1071+ Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-22043 RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in… Rustfs Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-22034 Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual patching system. On deployme… Snuffleupagus 0.13.0+ Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-21891 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application… Zimaos after 1.5.0 Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-69258 A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a ke… Apex Central Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-62877 Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x int… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.3 CVE-2025-67928 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allow… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.9 CVE-2025-67924 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affe… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-67911 Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newslet… Mitigation only Fix from $2,3002026-01-08