Search
66,781 CVEs
CVEs (66,781, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 66,781 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13984 | NONE | — | 2025-08-27 | QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attack… | |
| CVE-2024-13985 | NONE | — | 2025-08-27 | A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handl… | |
| CVE-2023-7309 | NONE | — | 2025-08-27 | A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), af… | |
| CVE-2025-9118 | NONE | — | 2025-08-25 | A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' reposit… | |
| CVE-2022-31491 | CRITICAL | Patched | 10.0 | 2025-08-22 | Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via… |
| CVE-2025-43300 | CRITICAL | Patched | 10.0 | 2025-08-21 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 an… |
| CVE-2025-49410 | CRITICAL | 10.0 | 2025-08-20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testimonials allows Stored XSS. This issue affects TC Tes… | |
| CVE-2025-49408 | CRITICAL | 10.0 | 2025-08-20 | Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data. This issue affects Templately: from n/a t… | |
| CVE-2025-50567 | CRITICAL | 10.0 | 2025-08-19 | Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interp… | |
| CVE-2025-20265 | CRITICAL | 10.0 | 2025-08-14 | A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject a… | |
| CVE-2012-10058 | NONE | — | 2025-08-13 | RabidHamster R4 v1.25 contains a stack-based buffer overflow vulnerability due to unsafe use of sprintf() when logging malformed HTTP requests. A remote attacker can exploi… | |
| CVE-2011-10017 | NONE | — | 2025-08-13 | Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input … | |
| CVE-2011-10011 | NONE | — | 2025-08-13 | WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly in… | |
| CVE-2011-10013 | NONE | — | 2025-08-13 | Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to halt execution after a… | |
| CVE-2025-34153 | NONE | — | 2025-08-13 | Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET … | |
| CVE-2012-10044 | NONE | — | 2025-08-08 | MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application fails to perform authentication or authorization chec… | |
| CVE-2012-10047 | NONE | — | 2025-08-08 | Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is … | |
| CVE-2025-53767 | CRITICAL | 10.0 | 2025-08-07 | Azure OpenAI Elevation of Privilege Vulnerability | |
| CVE-2013-10066 | NONE | — | 2025-08-05 | An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to… | |
| CVE-2013-10070 | NONE | — | 2025-08-05 | PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A… | |
| CVE-2012-10035 | NONE | — | 2025-08-05 | Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unau… | |
| CVE-2012-10025 | NONE | — | 2025-08-05 | The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP conf… | |
| CVE-2012-10026 | NONE | — | 2025-08-05 | The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly valid… | |
| CVE-2025-54253 | CRITICAL | Patched | 10.0 | 2025-08-05 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could lever… |
| CVE-2025-54119 | CRITICAL | Patched | 10.0 | 2025-08-05 | ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a query p… |