Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

66,781 CVEs

CVEs (66,781, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 66,781 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2024-13984 NONE — 2025-08-27 QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attack…
CVE-2024-13985 NONE — 2025-08-27 A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handl…
CVE-2023-7309 NONE — 2025-08-27 A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), af…
CVE-2025-9118 NONE — 2025-08-25 A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' reposit…
CVE-2022-31491 CRITICAL Patched 10.0 2025-08-22 Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via…
CVE-2025-43300 CRITICAL Patched 10.0 2025-08-21 An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 an…
CVE-2025-49410 CRITICAL 10.0 2025-08-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testimonials allows Stored XSS. This issue affects TC Tes…
CVE-2025-49408 CRITICAL 10.0 2025-08-20 Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data. This issue affects Templately: from n/a t…
CVE-2025-50567 CRITICAL 10.0 2025-08-19 Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interp…
CVE-2025-20265 CRITICAL 10.0 2025-08-14 A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject a…
CVE-2012-10058 NONE — 2025-08-13 RabidHamster R4 v1.25 contains a stack-based buffer overflow vulnerability due to unsafe use of sprintf() when logging malformed HTTP requests. A remote attacker can exploi…
CVE-2011-10017 NONE &mdash; 2025-08-13 Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input &hellip;
CVE-2011-10011 NONE &mdash; 2025-08-13 WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly in&hellip;
CVE-2011-10013 NONE &mdash; 2025-08-13 Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to halt execution after a&hellip;
CVE-2025-34153 NONE &mdash; 2025-08-13 Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET &hellip;
CVE-2012-10044 NONE &mdash; 2025-08-08 MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application fails to perform authentication or authorization chec&hellip;
CVE-2012-10047 NONE &mdash; 2025-08-08 Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is &hellip;
CVE-2025-53767 CRITICAL 10.0 2025-08-07 Azure OpenAI Elevation of Privilege Vulnerability
CVE-2013-10066 NONE &mdash; 2025-08-05 An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to&hellip;
CVE-2013-10070 NONE &mdash; 2025-08-05 PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A&hellip;
CVE-2012-10035 NONE &mdash; 2025-08-05 Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unau&hellip;
CVE-2012-10025 NONE &mdash; 2025-08-05 The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP conf&hellip;
CVE-2012-10026 NONE &mdash; 2025-08-05 The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly valid&hellip;
CVE-2025-54253 CRITICAL Patched 10.0 2025-08-05 Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could lever&hellip;
CVE-2025-54119 CRITICAL Patched 10.0 2025-08-05 ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a query p&hellip;