Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-34176 | MEDIUM | Patched | 4.3 | 2025-09-09 | In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is dire… |
| CVE-2025-34177 | MEDIUM | Patched | 5.4 | 2025-09-09 | In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed… |
| CVE-2025-34178 | MEDIUM | Patched | 5.4 | 2025-09-09 | In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed… |
| CVE-2025-43491 | CRITICAL | Patched | 9.8 | 2025-09-09 | A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privilege… |
| CVE-2025-44593 | MEDIUM | Patched | 6.1 | 2025-09-09 | Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vuln… |
| CVE-2025-44595 | MEDIUM | Patched | 6.1 | 2025-09-09 | Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}. |
| CVE-2025-54083 | NONE | — | 2025-09-09 | Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin access to the web interface.This issue affects GigaCent… | |
| CVE-2025-54084 | NONE | — | 2025-09-09 | OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute ar… | |
| CVE-2025-54239 | MEDIUM | Patched | 5.5 | 2025-09-09 | After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive inf… |
| CVE-2025-54240 | MEDIUM | Patched | 5.5 | 2025-09-09 | After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive inf… |
| CVE-2025-54241 | MEDIUM | Patched | 5.5 | 2025-09-09 | After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive inf… |
| CVE-2025-54243 | HIGH | Patched | 7.8 | 2025-09-09 | Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu… |
| CVE-2025-54244 | HIGH | Patched | 7.8 | 2025-09-09 | Substance3D - Viewer versions 0.25.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of … |
| CVE-2025-54245 | HIGH | Patched | 7.8 | 2025-09-09 | Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the cu… |
| CVE-2025-57633 | CRITICAL | 9.8 | 2025-09-09 | A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /ftp.html endpoint's "Up… | |
| CVE-2025-58462 | CRITICAL | Patched | 9.8 | 2025-09-09 | OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, o… |
| CVE-2025-58763 | HIGH | Patched | 8.0 | 2025-09-09 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows attackers with adminis… |
| CVE-2025-58765 | HIGH | Patched | 7.1 | 2025-09-09 | wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 erro… |
| CVE-2025-58768 | CRITICAL | Patched | 9.6 | 2025-09-09 | DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `… |
| CVE-2025-59037 | NONE | Patched | — | 2025-09-09 | DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with… |
| CVE-2025-7746 | NONE | — | 2025-09-09 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicio… | |
| CVE-2025-9996 | NONE | — | 2025-09-09 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause the execution of any shell command … | |
| CVE-2025-10171 | HIGH | Patched | 8.8 | 2025-09-09 | A vulnerability was detected in UTT 1250GW up to 3.2.2-200710. This vulnerability affects the function sub_453DC of the file /goform/formConfigApConfTemp. Performing manipu… |
| CVE-2025-49458 | MEDIUM | Patched | 6.5 | 2025-09-09 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2025-49459 | HIGH | 7.8 | 2025-09-09 | Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authenticated user to conduct an escalation of privilege via … |