Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2025-59947 NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shar… Nanomq 0.24.4+ Fix from $2,3002025-12-15 CRITICAL 9.1 CVE-2025-55895 TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Atta… A3300r Firmware No fix yet Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2023-53877 Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. At… Bus Reservation System Mitigation only Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2023-53874 GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the applicati… Gom Player Mitigation only Fix from $2,3002025-12-15 CRITICAL 9.3 CVE-2023-53872 Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execute arbitrary system commands.… No fix yet Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2023-53871 Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. At… Soosyze Mitigation only Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-65213 MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_singl… Torch Musa Mitigation only Fix from $2,3002025-12-15 CRITICAL 9.1 CVE-2025-66844 In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the con… Grav 1.7.49.5+ Fix from $2,3002025-12-15 CRITICAL 9.1 CVE-2025-13888 A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated per… Patch available Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14156EPSS 7% The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is … Mitigation only Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14711 A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the fi… Hotels Server after 2019-03-23 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14710 A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /… Hotels Server after 2019-03-23 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14709EPSS 6% A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14707EPSS 19% A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the c… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14706EPSS 19% A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the compo… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14705EPSS 17% A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulati… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14704EPSS 12% A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The m… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 CRITICAL 9.0 CVE-2025-67906 In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. Misp 2.5.28+ Fix from $2,3002025-12-15 CRITICAL 9.8 CVE-2025-14673 A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/… Snap7 Rs after 1.142.1 Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14672 A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Exe… Snap7 Rs after 1.142.1 Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14668 A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. P… Advanced Online Examination System Mitigation only Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14667 A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/… Covid Tracking System Mitigation only Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14666 A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. … Covid Tracking System Mitigation only Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14665 A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP… Wh450 Firmware Mitigation only Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14664 A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.p… Supplier Management System Mitigation only Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14661 A vulnerability has been found in itsourcecode Student Managemen System 1.0. Affected by this issue is some unknown functionality of the file /advise… Student Management System Mitigation only Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14659 A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The man… Dir 868l B1 Firmware after 203b03 Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14653 A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /addrecord.php. This manipu… Student Management System Mitigation only Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14652 A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?ac… Online Cake Ordering System Mitigation only Fix from $2,3002025-12-14 CRITICAL 9.8 CVE-2025-14650 A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing mani… Online Cake Ordering System Mitigation only Fix from $2,3002025-12-14