Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-13313 The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is … Mitigation only Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-66509 LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowin… Lara Dashboard after 2.3.0 Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-66576 Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthentic… Remote Keyboard Desktop Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.3 CVE-2025-66571 UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter… No fix yet Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-29269 ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint. All Rut22gw Firmware Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-29268EPSS 8% ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library. All Rut22gw Firmware Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-12995 Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determi… Carelink Network 2025-12-04+ Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-63362 Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to… Rs232\/485 To Wifi Eth \(b\) Firmware Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-14015 A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulatio… Magic B0 Firmware after 100R002 Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-66516EPSS 80% Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a… Tika 3.2.2+ Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-40261 In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_f… Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-40258 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-fr… No fix yet Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-40257 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptcp_pm_del_add_timer() can call… No fix yet Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-40252 In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_t… Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.1 CVE-2025-65346 alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive con… Laravel File Manager after 3.3.1 Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-54304 An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The d… Ion Torrent Onetouch 2 Firmware Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-54303 The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The iona… Torrent Suite Software Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-53963 An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The r… Ion Torrent Onetouch 2 Firmware Mitigation only Fix from $2,3002025-12-04 CRITICAL 9.6 CVE-2024-45538 Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Sy… Diskstation Manager 3.1.4-23079 / 7.2.1-69057-2+ Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-14004 A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add… Xunruicms after 4.7.1 Fix from $2,3002025-12-04 CRITICAL 9.8 CVE-2025-64055 An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the d… X210 Firmware Mitigation only Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2025-66489 Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verificati… Cal.com 5.9.8+ Fix from $2,3002025-12-03 CRITICAL 9.6 CVE-2025-66222 DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the M… Deepchat after 0.5.0 Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2025-66208 Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online.… Online 25.04.702+ Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2025-66032 Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible … Claude Code 1.0.93+ Fix from $2,3002025-12-03 CRITICAL 9.6 CVE-2025-64443 MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming t… Mcp Gateway 0.28.0+ Fix from $2,3002025-12-03 CRITICAL 9.3 CVE-2025-34319 TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vul… Mitigation only Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2024-32641EPSS 12% Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code … Masacms 7.2.8 / 7.3.13+ Fix from $2,3002025-12-03 CRITICAL 10.0 CVE-2025-55182 KEVEPSS 100% A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the … React 15.0.5 / 15.1.9+ Fix from $2,3002025-12-03 CRITICAL 9.0 CVE-2025-65267 In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. … Erpnext Mitigation only Fix from $2,3002025-12-03