Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-36902 UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulatin… Medivision Digital Signage Firmware Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.1 CVE-2020-36898 QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers t… Qihang Media Web Digital Signage No fix yet Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2020-36897 QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to u… Qihang Media Web Digital Signage Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2020-36892 Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attack… I Media Server Digital Signage Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2020-36885 Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execut… Snc Dh120t Firmware after 1.82.01 Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-65602 A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST… Chancms Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.3 CVE-2025-64539 Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrar… Experience Manager 6.5.24.0 / 2025.12.0+ Fix from $2,3002025-12-10 CRITICAL 9.3 CVE-2025-64538 Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrar… Experience Manager 6.5.24.0 / 2025.12.0+ Fix from $2,3002025-12-10 CRITICAL 9.3 CVE-2025-64537 Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrar… Experience Manager 6.5.24.0 / 2025.12.0+ Fix from $2,3002025-12-10 CRITICAL 9.4 CVE-2025-13607 A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL. Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.1 CVE-2025-65792 DataGear v5.5.0 is vulnerable to Arbitrary File Deletion. Datagear No fix yet Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-34394 Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently p… Rmm 2025.1.1+ Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-34393 Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-contro… Rmm 2025.1.1+ Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-34392EPSS 25% Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlle… Rmm 2025.1.1+ Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-13184EPSS 11% Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V… X5000r Firmware Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.3 CVE-2025-13953 Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method.… Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-41732 An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buf… 0852 1328 Firmware 02.64+ Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-41730 An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack bu… 0852 1328 Firmware 02.64+ Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-14087 A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potenti… Enterprise Linux 2.86.3+ Fix from $2,3002025-12-10 CRITICAL 9.3 CVE-2025-13955 Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain … Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.3 CVE-2025-13954 Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full a… Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-13613 The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugi… Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-67506 PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/… Pipeshub Patch available Fix from $2,3002025-12-10 CRITICAL 9.1 CVE-2025-61811 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code… Coldfusion Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.1 CVE-2025-61809 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security f… Coldfusion Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.1 CVE-2025-61808EPSS 10% ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could … Coldfusion Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-66039 FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a… Freepbx 16.0.44 / 17.0.23+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-67489 @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution… Patch available Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2023-53774 MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV … Minidvblinux after 5.4 Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2023-53771 MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Att… Minidvblinux after 5.4 Fix from $2,3002025-12-09