Search
78,484 CVEs
CVEs (78,484, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 78,484 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-10091 | HIGH | Patched | 7.3 | 2025-09-08 | A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the… |
| CVE-2025-5993 | NONE | — | 2025-09-08 | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and cons… | |
| CVE-2025-10092 | HIGH | Patched | 7.3 | 2025-09-08 | A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the compone… |
| CVE-2025-10093 | MEDIUM | 5.3 | 2025-09-08 | A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php of the component Devic… | |
| CVE-2025-40641 | NONE | — | 2025-09-08 | Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS due to lack of proper validation of user input by s… | |
| CVE-2025-40642 | NONE | — | 2025-09-08 | Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search. | |
| CVE-2025-3212 | MEDIUM | Patched | 5.3 | 2025-09-08 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-… |
| CVE-2025-22956 | CRITICAL | Patched | 9.8 | 2025-09-08 | OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState … |
| CVE-2025-36853 | HIGH | 7.5 | 2025-09-08 | A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow conditio… | |
| CVE-2025-36854 | HIGH | 8.1 | 2025-09-08 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body,… | |
| CVE-2025-36855 | HIGH | 8.8 | 2025-09-08 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/… | |
| CVE-2022-50238 | HIGH | 7.4 | 2025-09-08 | The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online… | |
| CVE-2025-40928 | HIGH | 7.5 | 2025-09-08 | JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact | |
| CVE-2025-40929 | MEDIUM | 5.6 | 2025-09-08 | Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspe… | |
| CVE-2025-40930 | HIGH | 7.5 | 2025-09-08 | JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other… | |
| CVE-2025-52161 | CRITICAL | 9.8 | 2025-09-08 | Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| CVE-2025-55998 | HIGH | 8.1 | 2025-09-08 | A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser… | |
| CVE-2025-56630 | HIGH | Patched | 7.3 | 2025-09-08 | FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file. |
| CVE-2025-57141 | CRITICAL | 9.8 | 2025-09-08 | rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc. | |
| CVE-2025-59033 | HIGH | 7.4 | 2025-09-08 | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of th… | |
| CVE-2025-7709 | NONE | — | 2025-09-08 | An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into … | |
| CVE-2025-10096 | MEDIUM | Patched | 6.3 | 2025-09-08 | A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Executing manipulation of… |
| CVE-2025-10097 | MEDIUM | 6.3 | 2025-09-08 | A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app/api/function/execute/route.ts. The manipulation of … | |
| CVE-2025-10098 | MEDIUM | 6.3 | 2025-09-08 | A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of … | |
| CVE-2025-51586 | LOW | Patched | 3.7 | 2025-09-08 | An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password… |