Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

66,771 CVEs

CVEs (66,771, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 66,771 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-50494 HIGH 7.5 2025-07-28 Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.
CVE-2025-54527 MEDIUM Patched 6.1 2025-07-28 In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
CVE-2025-54528 MEDIUM Patched 5.4 2025-07-28 In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
CVE-2025-54529 LOW Patched 3.7 2025-07-28 In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
CVE-2025-54530 HIGH Patched 7.5 2025-07-28 In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
CVE-2025-54531 HIGH Patched 7.7 2025-07-28 In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
CVE-2025-54532 MEDIUM Patched 4.3 2025-07-28 In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
CVE-2025-54533 MEDIUM Patched 4.3 2025-07-28 In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
CVE-2025-54534 MEDIUM Patched 4.8 2025-07-28 In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
CVE-2025-54535 MEDIUM Patched 5.8 2025-07-28 In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
CVE-2025-54536 MEDIUM Patched 5.4 2025-07-28 In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
CVE-2025-54537 MEDIUM Patched 5.5 2025-07-28 In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
CVE-2025-54538 MEDIUM Patched 5.5 2025-07-28 In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
CVE-2025-7676 NONE Patched — 2025-07-28 DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same d…
CVE-2025-43023 CRITICAL Patched 9.1 2025-07-28 A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak…
CVE-2025-50488 HIGH 7.1 2025-07-28 Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijack…
CVE-2025-50489 HIGH 7.5 2025-07-28 Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.
CVE-2025-50491 HIGH 7.1 2025-07-28 Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.
CVE-2025-50492 HIGH 7.5 2025-07-28 Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.
CVE-2025-54298 NONE — 2025-07-28 A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.
CVE-2025-54299 NONE — 2025-07-28 A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.
CVE-2025-50484 HIGH 7.1 2025-07-28 Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.
CVE-2025-50487 HIGH 7.1 2025-07-28 Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hija…
CVE-2025-8194 HIGH 7.5 2025-07-28 There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with nega…
CVE-2025-8283 LOW 3.7 2025-07-28 A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return exter…