Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-56333 An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component Pangolin 1.7.0+ Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15195 A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/ad… Assessment Management Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15194 A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the… Dir 600 Firmware Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.0 CVE-2025-68929 Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tri… Frappe 14.99.6 / 15.88.1+ Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-65570 A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array ele… Jsish Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-57460 File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell. Machpanel Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15186 A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file … Refugee Food Management System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15185 A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ho… Refugee Food Management System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15184 A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the file /home/refugeesreport2.p… Refugee Food Management System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15183 A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown function of the file /home/vi… Refugee Food Management System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15182 A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of the file /home/served.php. Ex… Refugee Food Management System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15181 A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unknown function of the file /hom… Refugee Food Management System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15228 BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and exe… Bpmflowwebkit 5.0.5+ Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15226 WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdo… Wmpro after 5.2 Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15069 Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 3.0.1 Web Fax 4.0+ Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15068 Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification through Manipulation.This issue… Web Fax 4.0+ Fix from $2,3002025-12-29 CRITICAL 10.0 CVE-2025-52691 KEVEPSS 86% Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po… Smartermail 100.0.9413+ Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15168 A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such mani… Student Management System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15167 A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This… Online Cake Ordering System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15166 A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file /updatesupplier.php?action=ed… Online Cake Ordering System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15165 A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown function of the file /updatecustom… Online Cake Ordering System Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15127 A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is so… Hotels Server after 2019-03-23 Fix from $2,3002025-12-28 CRITICAL 9.8 CVE-2025-54322EPSS 15% Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and… Sxzos after 2025-12-26 Fix from $2,3002025-12-27 CRITICAL 9.8 CVE-2025-68952 Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnera… Eigent Mitigation only Fix from $2,3002025-12-27 CRITICAL 9.8 CVE-2025-68932 FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() a… Freshrss 1.28.0+ Fix from $2,3002025-12-27 CRITICAL 9.1 CVE-2025-66203 StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault… Streamvault 251126+ Fix from $2,3002025-12-27 CRITICAL 9.9 CVE-2025-68668EPSS 13% n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node… N8n 2.0.0+ Fix from $2,3002025-12-26 CRITICAL 9.8 CVE-2024-44065 Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter. Cloudlog Mitigation only Fix from $2,3002025-12-26 CRITICAL 9.3 CVE-2025-13158 Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object proto… Mitigation only Fix from $2,3002025-12-26 CRITICAL 9.8 CVE-2025-13915EPSS 9% IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acce… Api Connect after 10.0.8.5 Fix from $2,3002025-12-26