Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-67910 Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.3 CVE-2025-23993 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allow… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-23504 Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This … Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-0700 A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/ch… Intern Membership Management System Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2019-25296 The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_uploa… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.1 CVE-2026-21881 Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass wh… Kanboard 1.2.49+ Fix from $2,3002026-01-08 CRITICAL 9.9 CVE-2026-21877EPSS 5% n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us… N8n 1.121.3+ Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-21875 ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the ad… Clipbucket 5.5.2-191+ Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-21869 llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input … Llama.cpp Mitigation only Fix from $2,3002026-01-08 CRITICAL 10.0 CVE-2026-21858EPSS 78% n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underly… N8n 1.121.0+ Fix from $2,3002026-01-08 CRITICAL 9.3 CVE-2025-15346 A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to n… Patch available Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2019-25282 V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipulate the 'parent' GET paramet… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2019-25268 NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening applicatio… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2017-20216EPSS 11% FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerF… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2025-69264 pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing t… Pnpm 10.26.0+ Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2026-22189 The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounde… Panda3d after 1.10.16 Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2025-68705EPSS 7% RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerabi… Rustfs Patch available Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2026-21854 The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpo… Tarkov Data Manager 2025-01-02+ Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2026-21679 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to… Iccdev 2.3.1.2+ Fix from $2,3002026-01-07 CRITICAL 10.0 CVE-2025-61492 A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via… Terminal Controller Mcp Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.6 CVE-2025-12543 A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr… Build Of Apache Camel 2.2.39 / 2.3.21+ Fix from $2,3002026-01-07 CRITICAL 9.2 CVE-2026-22542 An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the… Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.2 CVE-2026-22540 The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board … Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2025-47552 Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery… Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.3 CVE-2025-32303 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.Th… Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.3 CVE-2026-0650 OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of p… Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2026-0643 A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=re… House Rental And Property Listing Project Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.1 CVE-2025-68637 The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration expos… Uniffle 0.10.0+ Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2025-15018 The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This… Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2025-15471EPSS 13% A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation… Tew 713re Firmware Mitigation only Fix from $2,3002026-01-07