Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-55243 | HIGH | Patched | 7.5 | 2025-09-09 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-55245 | HIGH | Patched | 7.8 | 2025-09-09 | Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55316 | HIGH | Patched | 7.8 | 2025-09-09 | External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55317 | HIGH | Patched | 7.8 | 2025-09-09 | Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. |
| CVE-2025-57057 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This vulnerability allows attackers to c… |
| CVE-2025-57058 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and pModule parameters. This vulnera… |
| CVE-2025-57059 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerability allows attackers to cause … |
| CVE-2025-57061 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, v6 and remark parameters. This v… |
| CVE-2025-57062 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vulnerability allows attackers to… |
| CVE-2025-57063 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function. This vulnerability allows attac… |
| CVE-2025-57064 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to… |
| CVE-2025-57069 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnerability allows attackers to ca… |
| CVE-2025-57070 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulnerability allows attackers to c… |
| CVE-2025-57071 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulnerability allows attackers to cau… |
| CVE-2025-57072 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute function. This vulnerability allows att… |
| CVE-2025-57087 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attacker… |
| CVE-2025-57538 | MEDIUM | 5.4 | 2025-09-09 | A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authe… | |
| CVE-2025-57539 | MEDIUM | 5.4 | 2025-09-09 | A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated user… | |
| CVE-2025-57540 | MEDIUM | 5.4 | 2025-09-09 | A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. A… | |
| CVE-2025-58215 | NONE | — | 2025-09-09 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston ziston allows PHP Local File Inclusio… | |
| CVE-2025-58975 | NONE | — | 2025-09-09 | Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: … | |
| CVE-2025-58976 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Cont… | |
| CVE-2025-58977 | NONE | — | 2025-09-09 | Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Server Side Request Forgery.This issue affects WP eBay … | |
| CVE-2025-58978 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.Th… | |
| CVE-2025-58979 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BerqWP: from n/a t… |