Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-66410 Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causi… Gin Vue Admin after 2.8.6 Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-66405 Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by priori… Gateway 1.14.0+ Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-66401 MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critica… Mcp Watch after 0.1.2 Fix from $2,3002025-12-01 CRITICAL 9.6 CVE-2025-66301 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /… Grav 1.8.0+ Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-66205 Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to… Frappe 14.99.2 / 15.86.0+ Fix from $2,3002025-12-01 CRITICAL 9.1 CVE-2025-65836 PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController. Publiccms No fix yet Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-51683 A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POS… Mjobtime Mitigation only Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-51682 mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to administrative f… Mjobtime Mitigation only Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-3500 Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: fro… Antivirus 25.3+ Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-63531 A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properl… Blood Bank Management System Mitigation only Fix from $2,3002025-12-01 CRITICAL 9.1 CVE-2025-12106 Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses Openvpn Mitigation only Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13815 A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This man… Mogublog after 5.2 Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13814 A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the fil… Mogublog after 5.2 Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13806 A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo… Nutzboot after 2.6.0 Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13800EPSS 9% A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The ma… B Qe2w401 Firmware after 250814-r037c Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13799EPSS 9% A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.c… B Qe2w401 Firmware after 250814-r037c Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13798EPSS 7% A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulat… B Qe2w401 Firmware after 250814-r037c Fix from $2,3002025-12-01 CRITICAL 9.8 CVE-2025-13797EPSS 7% A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cg… B Qe2w401 Firmware after 250814-r037c Fix from $2,3002025-12-01 CRITICAL 9.1 CVE-2025-35028EPSS 5% By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI… Mitigation only Fix from $2,3002025-11-30 CRITICAL 9.8 CVE-2025-13788 A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. Th… Chanjet Crm after 2025-11-06 Fix from $2,3002025-11-30 CRITICAL 9.1 CVE-2025-13787 A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the compo… Zentao 21.7.7+ Fix from $2,3002025-11-30 CRITICAL 9.8 CVE-2025-13786 A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. P… Wtcms after 2019-12-20 Fix from $2,3002025-11-30 CRITICAL 9.8 CVE-2025-13783 A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of… Wtcms after 2019-12-20 Fix from $2,3002025-11-30 CRITICAL 9.8 CVE-2025-13782 A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the f… Wtcms after 2019-12-20 Fix from $2,3002025-11-30 CRITICAL 9.8 CVE-2025-13615 The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the p… Mitigation only Fix from $2,3002025-11-30 CRITICAL 9.8 CVE-2025-66216 AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message cla… Ais Catcher 0.64+ Fix from $2,3002025-11-29 CRITICAL 9.8 CVE-2025-66219 willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability i… Willitmerge after 0.2.1 Fix from $2,3002025-11-29 CRITICAL 9.8 CVE-2025-66034 fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontT… Fonttools 4.60.2+ Fix from $2,3002025-11-29 CRITICAL 9.8 CVE-2025-65112 PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated use… Pubnet 1.1.4+ Fix from $2,3002025-11-29 CRITICAL 9.4 CVE-2025-66385 UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role s… Patch available Fix from $2,3002025-11-28