Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-56157 Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE:… Dify after 1.5.1 Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-64236 Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: fr… No fix yet Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-14879EPSS 7% A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Reques… Wh450 Firmware Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-63389 A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp… Ollama after 0.12.3 Fix from $2,3002025-12-18 CRITICAL 9.1 CVE-2025-63388 A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoin… Dify Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.1 CVE-2025-63386 A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implemen… Dify Patch available Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-14878 A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HT… Wh450 Firmware Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-14877 A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The… Supplier Management System Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-7358 Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. This issue affects SoliClub: b… Soliclub 5.3.7+ Fix from $2,3002025-12-18 CRITICAL 9.4 CVE-2025-65008 In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in the adm.cgi endpoint, the mal… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-14860 Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. Firefox 146.0.1+ Fix from $2,3002025-12-18 CRITICAL 9.3 CVE-2025-10910 A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.1 CVE-2025-66078 Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote … Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.0 CVE-2025-66074 Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webho… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.9 CVE-2025-64374 Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors:… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-64233 Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.9 CVE-2025-64231 Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordp… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-64227 Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue af… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-64206 Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0. Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-64188 Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through … Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-60180 Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue af… Wp Gravity Forms Salesforce 1.5.2+ Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-60178 Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravit… Wp Gravity Forms Hubspot 1.2.7+ Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-60174 Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.Thi… Wp Gravity Forms Constant Contact Plugin after 1.1.2 Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-60091 Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects W… Wp Gravity Forms Zoho Crm And Bigin 1.3.0+ Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-60090 Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gr… Wp Gravity Forms Insightly 1.1.7+ Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-60089 Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affect… Wp Gravity Forms Freshdesk Plugin 1.3.6+ Fix from $2,3002025-12-18 CRITICAL 9.3 CVE-2025-60062 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-wit… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.3 CVE-2025-58951 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management fo… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-58935 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Lunna lunna allo… Lunna after 1.15 Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-54723 Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue affects DentiCare: from n/a thro… Mitigation only Fix from $2,3002025-12-18