Search
66,781 CVEs
CVEs (66,781, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 66,781 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58384 | CRITICAL | Patched | 10.0 | 2025-09-26 | In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library in the Watchdoc administration … |
| CVE-2025-9846 | CRITICAL | Patched | 10.0 | 2025-09-23 | Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command Injection. This issue af… |
| CVE-2025-9962 | NONE | — | 2025-09-23 | A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authentication.This issue affects P series: P – V2001.A.C518o2 un… | |
| CVE-2025-9588 | CRITICAL | Patched | 10.0 | 2025-09-23 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows Command In… |
| CVE-2025-59528 | CRITICAL | Patched | 10.0 | 2025-09-22 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP nod… |
| CVE-2025-10035 | CRITICAL | Patched | 10.0 | 2025-09-18 | A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitra… |
| CVE-2025-41243 | CRITICAL | 10.0 | 2025-09-16 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following ar… | |
| CVE-2025-10264 | CRITICAL | 10.0 | 2025-09-12 | Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remoter attackers to access the system configur… | |
| CVE-2025-58321 | CRITICAL | Patched | 10.0 | 2025-09-11 | Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability. |
| CVE-2025-55730 | CRITICAL | 10.0 | 2025-09-09 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing esc… | |
| CVE-2025-55727 | CRITICAL | Patched | 10.0 | 2025-09-09 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing esc… |
| CVE-2025-55728 | CRITICAL | Patched | 10.0 | 2025-09-09 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing esc… |
| CVE-2025-55729 | CRITICAL | 10.0 | 2025-09-09 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing esc… | |
| CVE-2025-55051 | CRITICAL | 10.0 | 2025-09-09 | CWE-1392: Use of Default Credentials | |
| CVE-2025-54261 | CRITICAL | 10.0 | 2025-09-09 | ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability tha… | |
| CVE-2025-42944 | CRITICAL | 10.0 | 2025-09-09 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to a… | |
| CVE-2025-58367 | NONE | Patched | — | 2025-09-05 | DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnerable to class pollution via the Delta class construct… |
| CVE-2025-54914 | CRITICAL | 10.0 | 2025-09-04 | Azure Networking Elevation of Privilege Vulnerability | |
| CVE-2025-55241 | CRITICAL | 10.0 | 2025-09-04 | Azure Entra ID Elevation of Privilege Vulnerability | |
| CVE-2010-10016 | NONE | — | 2025-08-30 | BS.Player version 2.57 (build 1051) contains a vulnerability in its playlist import functionality. When processing .m3u files, the application fails to properly validate th… | |
| CVE-2009-20011 | NONE | — | 2025-08-30 | ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads… | |
| CVE-2025-34160 | NONE | — | 2025-08-27 | AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/ServiceAgent/start_service… | |
| CVE-2025-34163 | NONE | — | 2025-08-27 | Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation and access control. An a… | |
| CVE-2024-13980 | NONE | — | 2025-08-27 | H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper … | |
| CVE-2024-13981 | NONE | — | 2025-08-27 | LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerability in its UploadFile.d… |