Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-66039 FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a… Freepbx 16.0.44 / 17.0.23+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-67489 @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution… Patch available Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2023-53774 MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV … Minidvblinux after 5.4 Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2023-53771 MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Att… Minidvblinux after 5.4 Fix from $2,3002025-12-09 CRITICAL 9.9 CVE-2023-53739 Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration back… Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2021-47731 Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocu… Izero Box Full Firmware Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2021-47728 Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbit… Izero Box Full Firmware Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.3 CVE-2021-47708 COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL … No fix yet Fix from $2,3002025-12-09 CRITICAL 9.3 CVE-2021-47707 COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can … No fix yet Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-66456 Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 throug… Elysia 1.4.17+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-65741 Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of thi… Sublime Text 3 3.2.2+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-64113 Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (… Emby 4.9.1.90+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14337 A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /new_grade.php. This manipulat… Student Management System Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-65882 An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ip… Openmptcprouter after 0.64 Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14336 A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.ph… Student Management System Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14335 A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file … Student Management System Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14334 A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_adviser.php. Executing manipula… Student Management System Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.0 CVE-2025-64672 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19127.20378+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-59719EPSS 30% An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.… Fortiweb after 7.6.4 Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-59718 KEVEPSS 69% A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 … Fortiproxy 7.0.6 / 7.0.18+ Fix from $2,3002025-12-09 CRITICAL 9.3 CVE-2025-34414 Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 … Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-63742 SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain… Rockoa Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-67504 WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand(… Wbce Cms 1.6.5+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-66631 CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow t… Csla .net 6.0.0+ Fix from $2,3002025-12-09 CRITICAL 9.1 CVE-2025-66568 The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypa… Ruby Saml 1.18.0+ Fix from $2,3002025-12-09 CRITICAL 9.1 CVE-2025-66567 The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentic… Ruby Saml 1.18.0+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-66565 Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number ge… Utils after 1.2.0 Fix from $2,3002025-12-09 CRITICAL 9.1 CVE-2025-42928EPSS 9% Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The s… Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.9 CVE-2025-42880 Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled functio… Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-40938 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. Thi… Simatic Cn 4100 Firmware 4.0.1+ Fix from $2,3002025-12-09