Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-65856 Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated rem… Xm530v200 X6 Weq 8m Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2023-53980 ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Att… Projectsend Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2023-53968 Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting… Sft Dab 600\/c Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2023-53966 SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciou… Linkandshare Transmitter Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2023-53964 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attac… Impact Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2023-53963 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary s… Impact Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2023-53960 SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers t… First Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2023-53955 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and acces… Stream Extension Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-67418 ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative crede… Clipbucket after 5.5.2 Fix from $2,3002025-12-22 CRITICAL 9.6 CVE-2024-27708 Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via … Mynet after 26.06 Fix from $2,3002025-12-22 CRITICAL 10.0 CVE-2025-67288 An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this … Umbraco Cms Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.6 CVE-2025-67289 An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin… Erpnext No fix yet Fix from $2,3002025-12-22 CRITICAL 9.5 CVE-2025-11545 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a attacker may … Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.5 CVE-2025-11544 Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized fi… Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-15012 A vulnerability was determined in code-projects Refugee Food Management System 1.0. The affected element is an unknown function of the file /home/hom… Refugee Food Management System Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-12049 Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to… Mp 01 Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-11543 Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized fi… Np P502h Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-11542 Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs. Np P502h Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-11541 Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs. Np P502h Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-15016 Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit t… Enterprise Cloud Database Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-15011 A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.php. The manipulation of the … Simple Stock System Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-15010 A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulatio… Wh450 Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-15008 A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. … Wh450 Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-15007 A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of … Wh450 Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-15006 A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of … Wh450 Firmware Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-15002 A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.cla… Seacms after 13.3 Fix from $2,3002025-12-21 CRITICAL 9.8 CVE-2025-14990 A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /ad… Complete Online Beauty Parlor Management System Mitigation only Fix from $2,3002025-12-21 CRITICAL 9.8 CVE-2025-14989 A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the fi… Complete Online Beauty Parlor Management System Mitigation only Fix from $2,3002025-12-21 CRITICAL 9.8 CVE-2025-13619 The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUs… Mitigation only Fix from $2,3002025-12-20 CRITICAL 9.8 CVE-2025-13329 The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback fu… Mitigation only Fix from $2,3002025-12-20