Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-34176 MEDIUM Patched 4.3 2025-09-09 In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is dire…
CVE-2025-34177 MEDIUM Patched 5.4 2025-09-09 In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed…
CVE-2025-34178 MEDIUM Patched 5.4 2025-09-09 In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed…
CVE-2025-43491 CRITICAL Patched 9.8 2025-09-09 A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privilege…
CVE-2025-44593 MEDIUM Patched 6.1 2025-09-09 Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vuln…
CVE-2025-44595 MEDIUM Patched 6.1 2025-09-09 Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
CVE-2025-54083 NONE — 2025-09-09 Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin access to the web interface.This issue affects GigaCent…
CVE-2025-54084 NONE — 2025-09-09 OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute ar…
CVE-2025-54239 MEDIUM Patched 5.5 2025-09-09 After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive inf…
CVE-2025-54240 MEDIUM Patched 5.5 2025-09-09 After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive inf…
CVE-2025-54241 MEDIUM Patched 5.5 2025-09-09 After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive inf…
CVE-2025-54243 HIGH Patched 7.8 2025-09-09 Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu…
CVE-2025-54244 HIGH Patched 7.8 2025-09-09 Substance3D - Viewer versions 0.25.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …
CVE-2025-54245 HIGH Patched 7.8 2025-09-09 Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu…
CVE-2025-57633 CRITICAL 9.8 2025-09-09 A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /ftp.html endpoint's "Up…
CVE-2025-58462 CRITICAL Patched 9.8 2025-09-09 OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, o…
CVE-2025-58763 HIGH Patched 8.0 2025-09-09 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows attackers with adminis…
CVE-2025-58765 HIGH Patched 7.1 2025-09-09 wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 erro…
CVE-2025-58768 CRITICAL Patched 9.6 2025-09-09 DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `…
CVE-2025-59037 NONE Patched — 2025-09-09 DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with…
CVE-2025-7746 NONE — 2025-09-09 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicio…
CVE-2025-9996 NONE — 2025-09-09 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the execution of any shell command …
CVE-2025-10171 HIGH Patched 8.8 2025-09-09 A vulnerability was detected in UTT 1250GW up to 3.2.2-200710. This vulnerability affects the function sub_453DC of the file /goform/formConfigApConfTemp. Performing manipu…
CVE-2025-49458 MEDIUM Patched 6.5 2025-09-09 Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access.
CVE-2025-49459 HIGH 7.8 2025-09-09 Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authenticated user to conduct an escalation of privilege via …