Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-69288 Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule … Titra 0.99.49+ Fix from $2,3002025-12-31 CRITICAL 9.8 CVE-2025-69286 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm i… Ragflow 0.22.0+ Fix from $2,3002025-12-31 CRITICAL 9.8 CVE-2025-34468 libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-contro… Libcoap after 4.3.5 Fix from $2,3002025-12-31 CRITICAL 9.8 CVE-2025-15391 A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipul… Dir 806a Firmware Mitigation only Fix from $2,3002025-12-31 CRITICAL 9.8 CVE-2025-15114 Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInf… Lares Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.3 CVE-2025-15113 Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers t… Lares Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15111 Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrati… Lares Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 10.0 CVE-2024-58338 Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the trace… Flamingo Xl Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2023-54327 Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords thro… Lan Controller Firmware after 1.58a Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2023-53983 Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can… Flamingo Xl Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2022-50803 JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privi… Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2022-50796 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path tr… Impact Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2022-50794 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers … Impact Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2022-50696 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal… First Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2022-50694 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to ma… Impact Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2022-50691 MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root throug… Minidvblinux Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15357 A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of th… Di 7400g\+ Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-50343 An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the … Matio Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15354 A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/add_admin.php. Ex… Society Management System Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15353 A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of the file /admin/edit_admin_q… Society Management System Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15263 A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin … Simple Php Cms Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.1 CVE-2025-56332 Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Default Configuration Pangolin 1.7.0+ Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-68926EPSS 31% RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardc… Rustfs Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-66848 JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and ea… Ax1800 Firmware after 4.5.1.r4533 Fix from $2,3002025-12-30 CRITICAL 9.6 CVE-2025-52835 Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a Web Shell to a Web Server.This… Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15257EPSS 5% A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formR… Br 6208ac Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15256 A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the com… Br 6208ac Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15255 A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHa… W6 S Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2023-54292 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix data race on CQP request done KCSAN detects a data race on cqp_… Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2023-54280 In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_… No fix yet Fix from $2,3002025-12-30