Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-47415 | NONE | Patched | — | 2025-09-09 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects … |
| CVE-2025-53913 | NONE | — | 2025-09-09 | Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G,… | |
| CVE-2025-53914 | NONE | — | 2025-09-09 | Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, … | |
| CVE-2025-54255 | MEDIUM | Patched | 4.0 | 2025-09-09 | Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a se… |
| CVE-2025-54257 | HIGH | Patched | 7.8 | 2025-09-09 | Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in… |
| CVE-2025-55053 | MEDIUM | 6.5 | 2025-09-09 | CWE-328: Use of Weak Hash | |
| CVE-2025-55054 | MEDIUM | 6.1 | 2025-09-09 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') | |
| CVE-2025-58063 | HIGH | 7.1 | 2025-09-09 | CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plugin contains a TTL confusion vulnerability where lea… | |
| CVE-2025-58180 | HIGH | Patched | 8.8 | 2025-09-09 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticat… |
| CVE-2025-58430 | MEDIUM | Patched | 6.1 | 2025-09-09 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session cookie `ses… |
| CVE-2025-58435 | NONE | — | 2025-09-09 | Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was highe… | |
| CVE-2025-58442 | MEDIUM | 5.3 | 2025-09-09 | Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in erro… | |
| CVE-2025-58753 | HIGH | Patched | 7.5 | 2025-09-09 | Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was cre… |
| CVE-2025-58758 | MEDIUM | Patched | 5.1 | 2025-09-09 | TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the `.env` file to exist when loading e… |
| CVE-2025-58759 | MEDIUM | Patched | 5.1 | 2025-09-09 | TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly strip inline comments inside .env values. This could … |
| CVE-2025-58760 | HIGH | Patched | 8.6 | 2025-09-09 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2.15.3 and earlier is vulnerable to path traversal, al… |
| CVE-2025-58761 | HIGH | Patched | 8.6 | 2025-09-09 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Tautulli v2.15.3 and prior is vulnerable to path trave… |
| CVE-2025-58762 | CRITICAL | Patched | 9.1 | 2025-09-09 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the `pms_imag… |
| CVE-2025-7635 | HIGH | 7.7 | 2025-09-09 | Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE. | |
| CVE-2025-10159 | CRITICAL | 9.8 | 2025-09-09 | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7… | |
| CVE-2025-10169 | HIGH | Patched | 8.8 | 2025-09-09 | A weakness has been identified in UTT 1200GW up to 3.0.0-170831. Affected by this issue is some unknown functionality of the file /goform/ConfigWirelessBase. This manipulat… |
| CVE-2025-10170 | HIGH | Patched | 8.8 | 2025-09-09 | A security vulnerability has been detected in UTT 1200GW up to 3.0.0-170831. This affects the function sub_4B48F8 of the file /goform/formApLbConfig. Such manipulation of t… |
| CVE-2025-23342 | HIGH | Patched | 8.2 | 2025-09-09 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of this vulnerability may lead to cod… |
| CVE-2025-23343 | HIGH | Patched | 7.6 | 2025-09-09 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A successful exploit of this vulnerability may lead to inf… |
| CVE-2025-23344 | HIGH | Patched | 7.3 | 2025-09-09 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privileged user. A successful exploit of this vulnerabili… |