Search
78,484 CVEs
CVEs (78,484, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 78,484 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-10220 | CRITICAL | Patched | 9.8 | 2025-09-10 | Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker … |
| CVE-2025-10221 | MEDIUM | Patched | 5.5 | 2025-09-10 | Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms a… |
| CVE-2025-10222 | LOW | Patched | 3.3 | 2025-09-10 | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows all… |
| CVE-2025-10223 | MEDIUM | Patched | 5.4 | 2025-09-10 | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker t… |
| CVE-2025-10224 | MEDIUM | Patched | 5.4 | 2025-09-10 | Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be de… |
| CVE-2025-10225 | HIGH | Patched | 7.5 | 2025-09-10 | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on W… |
| CVE-2025-10226 | CRITICAL | Patched | 9.8 | 2025-09-10 | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote a… |
| CVE-2025-10227 | MEDIUM | Patched | 4.6 | 2025-09-10 | Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker wi… |
| CVE-2025-7718 | HIGH | 8.8 | 2025-09-10 | The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and incl… | |
| CVE-2025-10231 | HIGH | Patched | 7.0 | 2025-09-10 | An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands… |
| CVE-2025-56404 | HIGH | 7.5 | 2025-09-10 | An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation. | |
| CVE-2025-56405 | HIGH | 7.5 | 2025-09-10 | An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol. | |
| CVE-2025-56406 | HIGH | 7.5 | 2025-09-10 | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's positi… | |
| CVE-2025-56407 | HIGH | 8.8 | 2025-09-10 | A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.p… | |
| CVE-2025-56413 | HIGH | 8.8 | 2025-09-10 | OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/… | |
| CVE-2025-56466 | HIGH | 7.5 | 2025-09-10 | Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information. | |
| CVE-2025-56578 | MEDIUM | 5.7 | 2025-09-10 | An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authentication mechanisms | |
| CVE-2025-20159 | MEDIUM | 5.3 | 2025-09-10 | A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass … | |
| CVE-2025-20248 | MEDIUM | 6.0 | 2025-09-10 | A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verificati… | |
| CVE-2025-20340 | HIGH | 7.4 | 2025-09-10 | A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a broadcast st… | |
| CVE-2025-29592 | MEDIUM | 5.6 | 2025-09-10 | oasys v1.1 is vulnerable to Directory Traversal in ProcedureController. | |
| CVE-2025-43725 | HIGH | Patched | 7.8 | 2025-09-10 | Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker … |
| CVE-2025-43884 | HIGH | Patched | 8.2 | 2025-09-10 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')… |
| CVE-2025-43885 | HIGH | Patched | 7.8 | 2025-09-10 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')… |
| CVE-2025-43886 | MEDIUM | Patched | 4.4 | 2025-09-10 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerability. A high privileged attacker with local access cou… |