Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-29089 | HIGH | 7.5 | 2025-09-09 | An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information | |
| CVE-2025-43775 | MEDIUM | Patched | 5.4 | 2025-09-09 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q… |
| CVE-2025-43781 | MEDIUM | Patched | 6.1 | 2025-09-09 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 … |
| CVE-2025-54242 | HIGH | Patched | 7.8 | 2025-09-09 | Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current us… |
| CVE-2025-54256 | HIGH | Patched | 8.6 | 2025-09-09 | Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in arbitrary code execution in the context… |
| CVE-2025-55047 | HIGH | 8.4 | 2025-09-09 | CWE-798 Use of Hard-coded Credentials | |
| CVE-2025-55048 | CRITICAL | 9.8 | 2025-09-09 | Multiple CWE-78 | |
| CVE-2025-55049 | CRITICAL | 9.1 | 2025-09-09 | Use of Default Cryptographic Key (CWE-1394) | |
| CVE-2025-55050 | CRITICAL | 9.8 | 2025-09-09 | CWE-1242: Inclusion of Undocumented Features | |
| CVE-2025-55051 | CRITICAL | 10.0 | 2025-09-09 | CWE-1392: Use of Default Credentials | |
| CVE-2025-55052 | MEDIUM | 4.3 | 2025-09-09 | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor | |
| CVE-2025-55727 | CRITICAL | Patched | 10.0 | 2025-09-09 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing esc… |
| CVE-2025-55728 | CRITICAL | Patched | 10.0 | 2025-09-09 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing esc… |
| CVE-2025-55729 | CRITICAL | 10.0 | 2025-09-09 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing esc… | |
| CVE-2025-55730 | CRITICAL | 10.0 | 2025-09-09 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing esc… | |
| CVE-2025-57060 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This vulnerability allows attackers to… |
| CVE-2025-57278 | HIGH | 8.8 | 2025-09-09 | The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates fr… | |
| CVE-2025-34172 | MEDIUM | Patched | 6.1 | 2025-09-09 | In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enab… |
| CVE-2025-34173 | MEDIUM | Patched | 4.3 | 2025-09-09 | In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before bein… |
| CVE-2025-34174 | MEDIUM | Patched | 5.4 | 2025-09-09 | In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/st… |
| CVE-2025-34175 | MEDIUM | Patched | 6.1 | 2025-09-09 | In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strin… |
| CVE-2025-36011 | MEDIUM | Patched | 4.3 | 2025-09-09 | IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cook… |
| CVE-2025-36125 | MEDIUM | 6.4 | 2025-09-09 | IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed a… | |
| CVE-2025-43786 | MEDIUM | Patched | 5.3 | 2025-09-09 | Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through… |
| CVE-2025-44594 | CRITICAL | Patched | 9.1 | 2025-09-09 | halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url. |