Search
66,771 CVEs
CVEs (66,771, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 66,771 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-36548 | HIGH | 8.3 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A sp… | |
| CVE-2025-41420 | CRITICAL | 9.6 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted… | |
| CVE-2025-46410 | CRITICAL | 9.6 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A… | |
| CVE-2025-46993 | MEDIUM | Patched | 5.4 | 2025-07-24 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to … |
| CVE-2025-46996 | MEDIUM | Patched | 5.4 | 2025-07-24 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to … |
| CVE-2025-47061 | MEDIUM | Patched | 5.4 | 2025-07-24 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to … |
| CVE-2025-48732 | HIGH | 7.3 | 2025-07-24 | An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code exe… | |
| CVE-2025-50128 | CRITICAL | 9.6 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially c… | |
| CVE-2025-53084 | CRITICAL | 9.0 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTT… | |
| CVE-2025-45702 | MEDIUM | 6.5 | 2025-07-24 | SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext. | |
| CVE-2025-5039 | HIGH | Patched | 7.8 | 2025-07-24 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the curren… |
| CVE-2025-8115 | LOW | 3.5 | 2025-07-24 | A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of t… | |
| CVE-2025-6998 | NONE | Patched | — | 2025-07-24 | ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via speciall… |
| CVE-2025-31952 | HIGH | 7.1 | 2025-07-24 | HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthoriz… | |
| CVE-2025-31953 | HIGH | 7.1 | 2025-07-24 | HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties. | |
| CVE-2025-31955 | HIGH | 7.6 | 2025-07-24 | HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system. | |
| CVE-2025-6260 | CRITICAL | 9.8 | 2025-07-24 | The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the … | |
| CVE-2025-7404 | CRITICAL | Patched | 9.8 | 2025-07-24 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This … |
| CVE-2025-8123 | MEDIUM | Patched | 6.3 | 2025-07-24 | A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulati… |
| CVE-2025-22165 | HIGH | Patched | 7.3 | 2025-07-24 | This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability,… |
| CVE-2025-32429 | CRITICAL | Patched | 9.8 | 2025-07-24 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2… |
| CVE-2025-3614 | MEDIUM | Patched | 6.4 | 2025-07-24 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up… |
| CVE-2025-53940 | NONE | Patched | — | 2025-07-24 | Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In versions 6.1.0-alpha.4 a… |
| CVE-2025-54369 | NONE | Patched | — | 2025-07-24 | Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original respo… |
| CVE-2025-54379 | CRITICAL | Patched | 9.8 | 2025-07-24 | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical … |