Search
66,771 CVEs
CVEs (66,771, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 66,771 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-38496 | MEDIUM | Patched | 5.5 | 2025-07-28 | In the Linux kernel, the following vulnerability has been resolved: dm-bufio: fix sched in atomic context If "try_verify_in_tasklet" is set for dm-verity, DM_BUFIO_CLIENT… |
| CVE-2025-38497 | HIGH | Patched | 7.1 | 2025-07-28 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Fix OOB read on empty string write When writing an empty string to either 'qw_s… |
| CVE-2025-5997 | HIGH | Patched | 8.8 | 2025-07-28 | Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro: before 7.5.4.2. |
| CVE-2025-8274 | HIGH | 7.3 | 2025-07-28 | A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the fi… | |
| CVE-2025-4056 | HIGH | Patched | 7.5 | 2025-07-28 | A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines. |
| CVE-2025-54569 | MEDIUM | Patched | 4.5 | 2025-07-28 | In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation. |
| CVE-2025-8275 | MEDIUM | 5.3 | 2025-07-28 | A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown functionality of the… | |
| CVE-2025-24485 | MEDIUM | 5.8 | 2025-07-28 | A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP request can lead to SSRF. An … | |
| CVE-2025-26469 | CRITICAL | 9.3 | 2025-07-28 | An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted appli… | |
| CVE-2025-27724 | CRITICAL | 9.3 | 2025-07-28 | A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated c… | |
| CVE-2025-30124 | CRITICAL | 9.8 | 2025-07-28 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is written onto the SD card in cle… | |
| CVE-2025-30126 | MEDIUM | 5.3 | 2025-07-28 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a remote attacker can disable recordin… | |
| CVE-2025-30133 | CRITICAL | 9.8 | 2025-07-28 | An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authen… | |
| CVE-2025-32731 | MEDIUM | 6.1 | 2025-07-28 | A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream MedDream PACS Premium 7.3.5.860. A specially crafted ma… | |
| CVE-2025-53695 | NONE | — | 2025-07-28 | OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware. | |
| CVE-2025-8279 | HIGH | Patched | 8.7 | 2025-07-28 | Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution |
| CVE-2025-30125 | CRITICAL | 9.8 | 2025-07-28 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-def… | |
| CVE-2025-53696 | NONE | Patched | — | 2025-07-28 | iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious… |
| CVE-2025-54418 | CRITICAL | Patched | 9.8 | 2025-07-28 | CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler fo… |
| CVE-2024-49342 | HIGH | 7.5 | 2025-07-28 | IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | |
| CVE-2024-49343 | MEDIUM | 5.4 | 2025-07-28 | IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the… | |
| CVE-2025-2297 | HIGH | Patched | 7.8 | 2025-07-28 | Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry unde… |
| CVE-2025-6250 | MEDIUM | Patched | 6.7 | 2025-07-28 | Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is dis… |
| CVE-2025-50490 | HIGH | 7.5 | 2025-07-28 | Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijack… | |
| CVE-2025-50493 | HIGH | 7.5 | 2025-07-28 | Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijac… |