Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-68359 In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of qgroup record after failure to add delayed ref head I… Mitigation only Fix from $2,3002025-12-24 CRITICAL 9.3 CVE-2023-53996 In the Linux kernel, the following vulnerability has been resolved: x86/sev: Make enc_dec_hypercall() accept a size instead of npages enc_dec_hyper… Mitigation only Fix from $2,3002025-12-24 CRITICAL 9.8 CVE-2023-53867 In the Linux kernel, the following vulnerability has been resolved: ceph: fix potential use-after-free bug when trimming caps When trimming the cap… Mitigation only Fix from $2,3002025-12-24 CRITICAL 9.8 CVE-2025-13773 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, … Mitigation only Fix from $2,3002025-12-24 CRITICAL 9.6 CVE-2025-68669 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerabil… 5ire 0.15.2+ Fix from $2,3002025-12-23 CRITICAL 9.9 CVE-2025-68667 Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows a remote, unauthenticated att… Patch available Fix from $2,3002025-12-23 CRITICAL 9.1 CVE-2025-68665 LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0… Langchain.js 0.3.37 / 0.3.80+ Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-15049 A vulnerability was identified in code-projects Online Farm System 1.0. Affected is an unknown function of the file /addProduct.php. The manipulation… Online Farm System Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-15048EPSS 12% A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request… Wh450 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-15047 A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Han… Wh450 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-15046 A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component H… Wh450 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-14500 IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary cod… Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-15045 A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit of the component HTTP Request… Wh450 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-15044 A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetting. The manipulation of the a… Wh450 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 10.0 CVE-2025-14931 Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot… Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-65354 Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST pa… Event Management Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-51511 Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads. Cadmium Cms Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-33224 NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this… Isaac Launchable Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-33223 NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this… Isaac Launchable Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-33222 NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerab… Isaac Launchable Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-29229 linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. E5600 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-29228 Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. E5600 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 10.0 CVE-2024-57521 SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.ja… Ruoyi after 4.7.9 Fix from $2,3002025-12-23 CRITICAL 10.0 CVE-2025-67109 Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute command… Cyclone Data Distribution Service 0.10.5+ Fix from $2,3002025-12-23 CRITICAL 10.0 CVE-2025-67108 eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections. Fast Dds Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-50526 Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function. Ex8000 Firmware Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-68341 In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix race As explain in commit fa34… Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-14388 The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including… Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-15034 A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the file /record.php. The manipula… Student Management System Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2025-68615EPSS 43% net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd … Debian Linux 5.9.5+ Fix from $2,3002025-12-23