Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2025-30996 Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Fol… Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-14942 wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or tr… Wolfssh 1.4.22+ Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-60534 Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order t… Cobalt X1 Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-39477 Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2026-0640 A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation… Ac23 Firmware Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-65212 An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie ver… Hy511 Firmware 2.1+ Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-60262 An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability … Mc102 G Firmware Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2020-36925 Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass a… Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2020-36923 Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. … Bravia Signage after 1.7.8 Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2020-36912 Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manip… Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-15001 The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.… Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-14996 The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up… Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2026-21675 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulner… Iccdev 2.3.1.1+ Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-15385 Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects co… Boomplay after 7.4.63 Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-15444 Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodi… Crypt\ 0.000042+ Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2026-0607 A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executi… Online Music Site Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2026-0606 A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Album… Online Music Site Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.3 CVE-2026-0625 Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows… Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.1 CVE-2025-68456 Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trig… Craft Cms 4.16.17 / 5.8.21+ Fix from $2,3002026-01-05 CRITICAL 9.3 CVE-2025-65110 Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 an… Vega 5.6.3 / 6.1.2+ Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2026-0605 A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the … Online Music Site Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.1 CVE-2025-67397 An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload in… Passy Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.1 CVE-2025-27807 An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24… Exynos 990 Firmware Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.1 CVE-2025-61781 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo… Opencti 6.8.1+ Fix from $2,3002026-01-05 CRITICAL 9.6 CVE-2025-55204 muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in.… Muffon 2.3.0+ Fix from $2,3002026-01-05 CRITICAL 9.6 CVE-2025-59467 A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Adm… Argentina Afip Invoices 1.3.0+ Fix from $2,3002026-01-05 CRITICAL 9.3 CVE-2025-39484 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue … Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2025-14346EPSS 6% WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pa… Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2026-0597 A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_pr… Supplier Management System Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2025-15029EPSS 12% Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules)… Awie 24.04.3 / 24.10.3+ Fix from $2,3002026-01-05