Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2025-14700EPSS 7% An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remot… Crafty Controller Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.1 CVE-2025-53619 An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file … Grassroots Dicom Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.1 CVE-2025-53618 An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file … Grassroots Dicom Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.1 CVE-2025-48429 An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file ca… Grassroots Dicom No fix yet Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-65834 Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulated widt… Shotcut Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.9 CVE-2025-68270 The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are a… Patch available Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-62864 Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly form… Ampereone A192 32m Firmware 4.4.5.2 / 5.4.5.1+ Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-62863 Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly form… Ampereone A192 32m Firmware 4.4.5.2 / 5.4.5.1+ Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-46295 Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the t… Filemaker Server 22.0.4+ Fix from $2,3002025-12-16 CRITICAL 9.0 CVE-2025-33210 NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution. Isaac Lab 2.3.0+ Fix from $2,3002025-12-16 CRITICAL 10.0 CVE-2025-63414 A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command exec… Allsky Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-50401 Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password. D196g Firmware Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-50398 Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_password. D196g Firmware Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-37164 KEVEPSS 90% A remote code execution issue exists in HPE OneView. Oneview after 10.20.00 Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2023-53899 PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Att… Podcast Generator Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2023-53895 PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization throug… Pimp My Log Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2023-53894 phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash vali… Phpfilemanager Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-68315 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free_nid_list As reported, on-di… No fix yet Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-68301 In the Linux kernel, the following vulnerability has been resolved: net: atlantic: fix fragment overflow handling in RX path The atlantic driver ca… Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-68285 In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop i… No fix yet Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-68284 In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() Th… Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.1 CVE-2025-65319 When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-Web tag, wh… Bluemail after 1.140.103 Fix from $2,3002025-12-16 CRITICAL 9.1 CVE-2025-65318 When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, whi… Canary Mail after 5.1.40 Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-68263 In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() w… Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-68192 In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup Raw IP pack… No fix yet Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-40350 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ XDP … No fix yet Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-62849 An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab… Qts Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-59385 An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then … Qts Mitigation only Fix from $2,3002025-12-16 CRITICAL 9.6 CVE-2025-67744 DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerab… Deepchat 0.5.3+ Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-64725 Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15… Weblate 5.15+ Fix from $2,3002025-12-15