Search
66,771 CVEs
CVEs (66,771, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 66,771 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-50494 | HIGH | 7.5 | 2025-07-28 | Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack. | |
| CVE-2025-54527 | MEDIUM | Patched | 6.1 | 2025-07-28 | In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions |
| CVE-2025-54528 | MEDIUM | Patched | 5.4 | 2025-07-28 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow |
| CVE-2025-54529 | LOW | Patched | 3.7 | 2025-07-28 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration |
| CVE-2025-54530 | HIGH | Patched | 7.5 | 2025-07-28 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions |
| CVE-2025-54531 | HIGH | Patched | 7.7 | 2025-07-28 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows |
| CVE-2025-54532 | MEDIUM | Patched | 4.3 | 2025-07-28 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies |
| CVE-2025-54533 | MEDIUM | Patched | 4.3 | 2025-07-28 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration |
| CVE-2025-54534 | MEDIUM | Patched | 4.8 | 2025-07-28 | In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page |
| CVE-2025-54535 | MEDIUM | Patched | 5.8 | 2025-07-28 | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms |
| CVE-2025-54536 | MEDIUM | Patched | 5.4 | 2025-07-28 | In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint |
| CVE-2025-54537 | MEDIUM | Patched | 5.5 | 2025-07-28 | In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots |
| CVE-2025-54538 | MEDIUM | Patched | 5.5 | 2025-07-28 | In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command |
| CVE-2025-7676 | NONE | Patched | — | 2025-07-28 | DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same d… |
| CVE-2025-43023 | CRITICAL | Patched | 9.1 | 2025-07-28 | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak… |
| CVE-2025-50488 | HIGH | 7.1 | 2025-07-28 | Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijack… | |
| CVE-2025-50489 | HIGH | 7.5 | 2025-07-28 | Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack. | |
| CVE-2025-50491 | HIGH | 7.1 | 2025-07-28 | Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack. | |
| CVE-2025-50492 | HIGH | 7.5 | 2025-07-28 | Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack. | |
| CVE-2025-54298 | NONE | — | 2025-07-28 | A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered. | |
| CVE-2025-54299 | NONE | — | 2025-07-28 | A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered. | |
| CVE-2025-50484 | HIGH | 7.1 | 2025-07-28 | Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack. | |
| CVE-2025-50487 | HIGH | 7.1 | 2025-07-28 | Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hija… | |
| CVE-2025-8194 | HIGH | 7.5 | 2025-07-28 | There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with nega… | |
| CVE-2025-8283 | LOW | 3.7 | 2025-07-28 | A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return exter… |