Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-49460 | MEDIUM | Patched | 4.3 | 2025-09-09 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2025-49461 | MEDIUM | Patched | 4.3 | 2025-09-09 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2025-54258 | HIGH | Patched | 7.8 | 2025-09-09 | Substance3D - Modeler versions 1.22.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current… |
| CVE-2025-54259 | HIGH | Patched | 7.8 | 2025-09-09 | Substance3D - Modeler versions 1.22.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the conte… |
| CVE-2025-54260 | HIGH | Patched | 7.8 | 2025-09-09 | Substance3D - Modeler versions 1.22.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end… |
| CVE-2025-58131 | MEDIUM | Patched | 6.6 | 2025-09-09 | Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) … |
| CVE-2025-58134 | MEDIUM | Patched | 4.3 | 2025-09-09 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access. |
| CVE-2025-58135 | MEDIUM | Patched | 5.3 | 2025-09-09 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2025-59036 | MEDIUM | Patched | 5.5 | 2025-09-09 | Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the authentication logic will cause API tokens that were… |
| CVE-2025-9997 | NONE | — | 2025-09-09 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is … | |
| CVE-2025-10172 | HIGH | Patched | 8.8 | 2025-09-09 | A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/formPictureUrl. Executing manipulation of the argument … |
| CVE-2025-58447 | CRITICAL | Patched | 9.8 | 2025-09-09 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-based buffer overflow … |
| CVE-2025-58448 | CRITICAL | Patched | 9.1 | 2025-09-09 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL Injection in the PartyB… |
| CVE-2025-58750 | HIGH | Patched | 8.2 | 2025-09-09 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0cc348b are missing a bound check in `chcl… |
| CVE-2025-59038 | NONE | — | 2025-09-09 | Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9.2 may have been briefly compromised by a malware ca… | |
| CVE-2025-59039 | NONE | — | 2025-09-09 | Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This … | |
| CVE-2025-59042 | NONE | — | 2025-09-09 | PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during the bootstrap process of… | |
| CVE-2025-59044 | MEDIUM | Patched | 4.4 | 2025-09-09 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display name when … |
| CVE-2025-59046 | CRITICAL | 9.8 | 2025-09-09 | The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the branch name on the comman… | |
| CVE-2025-10195 | MEDIUM | 5.3 | 2025-09-10 | A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such… | |
| CVE-2025-10197 | MEDIUM | 6.3 | 2025-09-10 | A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability is an unknown functionality of the file /templates/… | |
| CVE-2025-8388 | MEDIUM | 6.4 | 2025-09-10 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_url’ parameter in … | |
| CVE-2025-10001 | HIGH | 7.2 | 2025-09-10 | The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functional… | |
| CVE-2025-10040 | HIGH | 7.7 | 2025-09-10 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ftp_… | |
| CVE-2025-10049 | HIGH | 7.2 | 2025-09-10 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the HdnMediaSelection_image field i… |