Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-27019 Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system acces… Infinera Mtc 9 Firmware 23.0+ Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14227 A security flaw has been discovered in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This issue affects some unknown pro… Simple Php Blog after 2025-01-22 Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14226 A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The… Student Management System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14224 A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the componen… Dm2 Firmware after 1.9.12 Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14223 A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /req… Simple Leave Manager Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14218 A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editother… Currency Exchange System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14217 A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipul… Currency Exchange System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14216 A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing of the file /viewserial.php.… Currency Exchange System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14215 A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the file /edit.php. The manipulat… Currency Exchange System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14212 A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /memb… Advanced Library Management System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14211 A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of t… Advanced Library Management System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14210 A security vulnerability has been detected in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /dele… Advanced Library Management System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14209 A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the file /update_query.php. This m… School File Management System Mitigation only Fix from $2,3002025-12-08 CRITICAL 9.3 CVE-2023-53769 In the Linux kernel, the following vulnerability has been resolved: virt/coco/sev-guest: Double-buffer messages The encryption algorithms read and … No fix yet Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2023-53751 In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname TCP_Server… No fix yet Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-40320 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_info_compound When smb2_query… No fix yet Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14199 A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text… Verysync after 2.21.3 Fix from $2,3002025-12-07 CRITICAL 9.8 CVE-2025-14191 A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. Affected by this issue is the function strcpy of the file /goform/formP2PLimitCon… 512w Firmware after 1.7.7-171114 Fix from $2,3002025-12-07 CRITICAL 9.8 CVE-2025-14182 A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the file /sobey-mchEditor/waterm… Media Convergence System Mitigation only Fix from $2,3002025-12-07 CRITICAL 9.8 CVE-2025-14141 A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formArpBindConfig. Executing man… 520w Firmware Mitigation only Fix from $2,3002025-12-06 CRITICAL 9.8 CVE-2025-12673 The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() f… Mitigation only Fix from $2,3002025-12-06 CRITICAL 9.8 CVE-2025-66644 KEV Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. Arrayos Ag 9.4.5.9+ Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-66570 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP he… Cpp Httplib 0.27.0+ Fix from $2,3002025-12-05 CRITICAL 9.6 CVE-2025-66562 TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exi… Tuui 1.3.4+ Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-34256 Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secre… Wise Deviceon Server 5.4+ Fix from $2,3002025-12-05 CRITICAL 9.3 CVE-2020-36877 ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary… No fix yet Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-14094EPSS 20% A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulatio… Br 6478ac V3 Firmware Mitigation only Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-14093EPSS 20% A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The … Br 6478ac V3 Firmware Mitigation only Fix from $2,3002025-12-05 CRITICAL 9.6 CVE-2025-64054 A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially exec… X210 Firmware No fix yet Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-12374 The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerab… Mitigation only Fix from $2,3002025-12-05