Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-55243 HIGH Patched 7.5 2025-09-09 Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-55245 HIGH Patched 7.8 2025-09-09 Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally.
CVE-2025-55316 HIGH Patched 7.8 2025-09-09 External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
CVE-2025-55317 HIGH Patched 7.8 2025-09-09 Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
CVE-2025-57057 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This vulnerability allows attackers to c…
CVE-2025-57058 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and pModule parameters. This vulnera…
CVE-2025-57059 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerability allows attackers to cause …
CVE-2025-57061 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, v6 and remark parameters. This v…
CVE-2025-57062 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vulnerability allows attackers to…
CVE-2025-57063 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function. This vulnerability allows attac…
CVE-2025-57064 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to…
CVE-2025-57069 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnerability allows attackers to ca…
CVE-2025-57070 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulnerability allows attackers to c…
CVE-2025-57071 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulnerability allows attackers to cau…
CVE-2025-57072 HIGH Patched 7.5 2025-09-09 Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute function. This vulnerability allows att…
CVE-2025-57087 HIGH Patched 7.5 2025-09-09 Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attacker…
CVE-2025-57538 MEDIUM 5.4 2025-09-09 A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authe…
CVE-2025-57539 MEDIUM 5.4 2025-09-09 A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated user…
CVE-2025-57540 MEDIUM 5.4 2025-09-09 A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. A…
CVE-2025-58215 NONE — 2025-09-09 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston ziston allows PHP Local File Inclusio…
CVE-2025-58975 NONE — 2025-09-09 Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: …
CVE-2025-58976 NONE — 2025-09-09 Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Cont…
CVE-2025-58977 NONE — 2025-09-09 Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Server Side Request Forgery.This issue affects WP eBay …
CVE-2025-58978 NONE — 2025-09-09 Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.Th…
CVE-2025-58979 NONE — 2025-09-09 Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BerqWP: from n/a t…