Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-13390 The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect impleme… Wp Directory Kit after 1.4.4 Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2025-13342 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to… Mitigation only Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2025-13486EPSS 68% The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_… Mitigation only Fix from $2,3002025-12-03 CRITICAL 9.3 CVE-2025-13658 A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence o… Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-13542 The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlm… Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.3 CVE-2025-13510 The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated u… Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.1 CVE-2025-66409 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on … Esp Idf after 5.5.1 Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-65896 SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys. Asyncmy after 0.2.10 Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-60736 code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter. Online Medicine Guide Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-60854 A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in… R15 Firmware after 1.20.01 Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-58386 In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks.… Terminalfour 8.4.1.2+ Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-65656 dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php. Dcat Admin after 2.2.3 Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-65358 Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php. Edoc Doctor Appointment System Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.0 CVE-2025-13828 SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settin… Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.1 CVE-2025-59703 Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Pro… Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-59695 Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS r… Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-59693 The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.… Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-41013 SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete datab… Gim 2025-04-01+ Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11788 Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimite… Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11786 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter … Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11785 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited use… Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11784 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user… Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11783 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copy… Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11782 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string… Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11780 Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user i… Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11779 Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is appli… Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-11778 Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption thr… Sge Plc1000 Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.1 CVE-2025-41744 Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communicatio… Sprecon E C Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.8 CVE-2025-41742 Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic key… Sprecon E C Firmware Mitigation only Fix from $2,3002025-12-02 CRITICAL 9.1 CVE-2025-13872 Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an atta… Opinio Mitigation only Fix from $2,3002025-12-02