Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-53959 FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll i… Filezilla Client Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2023-53951 Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can l… Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2023-53950 InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions throug… Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2023-53948 Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary… Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14968 A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown functionality of the file /marke… Simple Stock System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14967 A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file … Student Management System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14964 A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manip… T10 Firmware Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14961 A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unknown function of the file /edit… Simple Blood Donor Management System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14960 A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unknown function of the file /ed… Simple Blood Donor Management System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14959 A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of the file /market/signup.php. E… Simple Stock System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.6 CVE-2025-66580 Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS)… Dive 0.11.1+ Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-63665 An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into… Gt Edge Ai 2.0.12+ Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-58053 Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a s… Galette 1.2.0+ Fix from $2,3002025-12-19 CRITICAL 9.1 CVE-2024-49587 Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission… Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.3 CVE-2025-34433 AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installati… Patch available Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14952 A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Perfo… Supplier Management System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14951 A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unknown function of the file /ho… Scholars Tracking System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14950 A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.ph… Scholars Tracking System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.1 CVE-2025-1928 Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows … Online Food Delivery System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14940 A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /admin/delete_u… Scholars Tracking System Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-67843 A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to e… Mintlify 2025-11-15+ Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-14733 KEVEPSS 27% An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code… Fireware 12.5.15 / 12.11.6+ Fix from $2,3002025-12-19 CRITICAL 9.6 CVE-2025-64675 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp… Azure Cosmos Db Mitigation only Fix from $2,3002025-12-19 CRITICAL 9.1 CVE-2025-68398 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i… Weblate 5.15.1+ Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-65041 Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. Partner Center Mitigation only Fix from $2,3002025-12-18 CRITICAL 10.0 CVE-2025-65037 Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. Azure Container Apps Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.1 CVE-2025-34449 Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deseriali… Scrcpy 3.3.4+ Fix from $2,3002025-12-18 CRITICAL 9.1 CVE-2025-14850 Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files. Webaccess\/scada Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-14849 Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. Webaccess\/scada Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2023-53941EPSS 6% EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by i… Webserver Mitigation only Fix from $2,3002025-12-18