Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-53433 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes EasyEat easyeat… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.1 CVE-2025-68435 Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication… Zerobyte 0.18.5+ Fix from $2,3002025-12-17 CRITICAL 9.1 CVE-2025-68145EPSS 7% In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository… Model Context Protocol Servers 2025.12.18+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-14833 A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /… Online Appointment Booking System Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2023-53926 PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database querie… Simple Cms Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2023-53923 UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserC… Ulicms Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2023-53922 TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload … Tinywebgallery Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2023-53921 SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. … Sitemagic Cms Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2023-53914 UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in … Ulicms Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.1 CVE-2025-68118 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling co… Freerdp 3.20.0+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-68114 Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.… Capstone 6.0.0+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-67791 An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentica… Drivelock after 25.1.6 Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-14832 A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduc… Online Cake Ordering System Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-67793 An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" … Drivelock 25.1.6+ Fix from $2,3002025-12-17 CRITICAL 9.0 CVE-2025-67493 Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access … Homarr 1.45.3+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-66647 RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de… Riot 2025.10+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-43526 This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web… Safari 26.2+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-43428 A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. P… Ipados 26.2+ Fix from $2,3002025-12-17 CRITICAL 9.6 CVE-2025-67787 An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a… Drivelock Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.9 CVE-2025-67781 An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileg… Drivelock 24.1.6 / 24.2.7+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-67073 A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial o… Ac10 Firmware Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.1 CVE-2025-34434 AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints respon… Avideo 20.0+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-62521 ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM'… Churchcrm 5.21.0+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-67165 An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges. Pagekit Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.9 CVE-2025-67164 An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c… Pagekit Mitigation only Fix from $2,3002025-12-17 CRITICAL 10.0 CVE-2025-20393 KEVEPSS 30% A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could … Asyncos 15.0.2-007 / 15.0.5-016+ Fix from $2,3002025-12-17 CRITICAL 10.0 CVE-2025-44005EPSS 9% An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol a… Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2022-23851 Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI). Api Orchestrator 0.19.3+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-67895 Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on … Apache Airflow Providers Edge3 2.0.0+ Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-59374 KEV "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a sup… Live Update 3.6.8+ Fix from $2,3002025-12-17