NVD · CISA KEV · CERT-In

CVE Tracker

Vulnerabilities ranked for Indian enterprises. Filter by severity, exploitation status and CERT-In advisories; sign in for WhatsApp/email alerts on your product stack.

Exploited (KEV)🇮🇳 CERT-InClear filters
10.0CVE-2025-60206Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows…Unknown10.0CVE-2025-57870A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux…Arcgis Server10.0CVE-2025-49060Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows…Unknown10.0CVE-2025-48106Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows…Unknown10.0CVE-2025-9846Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information…Unknown10.0CVE-2025-2857Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a…Firefox10.0CVE-2020-0796A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1…Windows 10 1903KEV9.9CVE-2025-61913Flowise is a drag & drop user interface to build a customized large language model flow.Flowise9.9CVE-2025-58048Paymenter is a free and open-source webshop solution for hostings.Unknown9.8CVE-2026-1842Microsoft Message Queuing Remote Code ExecutionMicrosoft MSMQKEVCERT-In9.8CVE-2025-64055An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network…X210 Firmware9.8CVE-2024-32641Masa CMS is an open source Enterprise Content Management platform.Masacms9.8CVE-2025-41013SQL injection vulnerability in TCMAN GIM v11 in version 20250304.Gim9.8CVE-2025-11788Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2.Sge-Plc1000 Firmware9.8CVE-2025-11786Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2.Sge-Plc1000 Firmware9.8CVE-2025-11784Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2.Sge-Plc1000 Firmware9.8CVE-2025-11783Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2.Sge-Plc1000 Firmware9.8CVE-2025-11782Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2.Sge-Plc1000 Firmware9.8CVE-2025-11779Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2.Sge-Plc1000 Firmware9.8CVE-2025-41742Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized…Sprecon-E-C Firmware9.8CVE-2025-64130Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a…Unknown9.8CVE-2025-36386IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to…Maximo Application Suite9.8CVE-2025-9967The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account…Unknown9.8CVE-2025-9286The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to…Unknown9.8CVE-2025-59741Operating system command injection vulnerability in AndSoft's e-TMS v25.03.E-Tms9.8CVE-2025-59834ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB.Adb Mcp Server9.8CVE-2025-41715The database for the web application is exposed without authentication, allowing an unauthenticated remote…Unknown9.8CVE-2025-6544A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read…H2o9.8CVE-2025-10156An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of…Picklescan9.8CVE-2025-58434Flowise is a drag & drop user interface to build a customized large language model flow.Flowise9.8CVE-2025-40690SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul.Online Fire Reporting System9.8CVE-2025-8570The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT…Unknown9.8CVE-2025-10220Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft…Axxon One9.8CVE-2025-58462OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via…Foiaxpress Public Access Link9.8CVE-2025-9994The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication…Unknown9.8CVE-2025-8359The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and…Unknown9.8CVE-2025-58371Roo Code is an AI-powered autonomous coding agent that lives in users' editors.Roo Code9.8CVE-2025-57819FreePBX is an open-source web-based graphical user interface.FreepbxKEV9.8CVE-2025-54738Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster…Unknown9.8CVE-2025-54725Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows…Unknown9.8CVE-2025-34523A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of…Udp9.8CVE-2025-34522A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data…Udp9.8CVE-2025-34520An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated…Udp9.8CVE-2025-9187Memory safety bugs present in Firefox 141 and Thunderbird 141.Firefox9.8CVE-2025-9179An attacker was able to perform memory corruption in the GMP process which processes encrypted media.Firefox9.8CVE-2025-8042Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads.Firefox9.8CVE-2025-55031Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey…Firefox9.8CVE-2025-54143Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected…Firefox9.8CVE-2025-8044Memory safety bugs present in Firefox 140 and Thunderbird 140.Firefox9.8CVE-2025-8043Focus incorrectly truncated URLs towards the beginning instead of around the origin.Firefox9.8CVE-2025-8038Thunderbird ignored paths when checking the validity of navigations in a frame.Firefox9.8CVE-2025-8031The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP…Firefox9.8CVE-2025-8028On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from…Firefox9.8CVE-2025-6433If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was…Firefox9.8CVE-2025-6424A use-after-free in FontFaceSet resulted in a potentially exploitable crash.Firefox9.8CVE-2025-49710An integer overflow was present in `OrderedHashTable` used by the JavaScript engine.Firefox9.8CVE-2025-49709Certain canvas operations could have lead to memory corruption.Firefox9.8CVE-2025-4918An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object.Firefox9.8CVE-2025-26319FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in…Flowise9.8CVE-2025-1942When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be…Firefox9.8CVE-2025-1020Memory safety bugs present in Firefox 134 and Thunderbird 134.Firefox9.8CVE-2025-1017Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6.Firefox9.8CVE-2025-1016Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6,…Firefox9.8CVE-2025-1009An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable…Firefox9.8CVE-2024-49568In the Linux kernel, the following vulnerability has been resolved: net/smc: check…Linux Kernel9.8CVE-2024-47408In the Linux kernel, the following vulnerability has been resolved: net/smc: check smcd_v2_ext_offset…Linux Kernel9.8CVE-2025-0247Memory safety bugs present in Firefox 133 and Thunderbird 133.Firefox9.8CVE-2018-19949If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.QtsKEV9.8CVE-1999-0199manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified…Glibc9.8CVE-2020-12812An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may…FortiosKEV9.8CVE-2019-2725Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web…Agile Product Lifecycle ManagementKEV9.8CVE-2018-19323The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57,…Aorus Graphics EngineKEV9.8CVE-2018-7602A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x.DrupalKEV9.8CVE-2016-1019Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service…Flash Player Desktop RuntimeKEV9.8CVE-2012-1710Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware…Fusion MiddlewareKEV9.8CVE-2010-2861Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and…ColdfusionKEV9.6CVE-2024-45538Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM)…Diskstation Manager9.6CVE-2025-66301Grav is a file-based Web platform.Grav9.6CVE-2025-9804An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission…Api Control Plane9.6CVE-2025-59434Flowise is a drag & drop user interface to build a customized large language model flow.Unknown9.6CVE-2025-58255Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Images…Unknown9.4CVE-2025-10644Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability.Repairit9.3CVE-2025-47569Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in…Unknown9.3CVE-2025-54720Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in…Unknown9.1CVE-2025-41744Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote…Sprecon-E-C Firmware9.1CVE-2025-13872Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26…Opinio9.1CVE-2025-12106Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a…Openvpn9.1CVE-2025-37729Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE)…Elastic Cloud Enterprise9.1CVE-2025-10890Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker…Chrome9.1CVE-2025-10643Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability.Repairit9.1CVE-2025-9943An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the…Unknown9.1CVE-2025-10134The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion…Unknown9.1CVE-2025-54145The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious…Firefox9.1CVE-2025-8037Setting a nameless cookie with an equals sign in the value shadowed other cookies.Firefox9.1CVE-2025-6427An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating…Firefox9.1CVE-2025-49796A vulnerability was found in libxml2.Unknown9.1CVE-2025-49794A use-after-free vulnerability was found in libxml2.Unknown9.1CVE-2025-4083A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which…Firefox9.1CVE-2025-1941Under certain circumstances, a user opt-in setting that Focus should require authentication before use…Firefox9.0CVE-2025-3500Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege…Antivirus