Search
78,484 CVEs
CVEs (78,484, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 78,484 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-10099 | LOW | Patched | 2.4 | 2025-09-08 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_usuario_cad.php of… |
| CVE-2025-10100 | HIGH | 7.3 | 2025-09-08 | A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of the file /admin_class.php?action=login. Performing ma… | |
| CVE-2025-56265 | HIGH | 8.8 | 2025-09-08 | An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a craft… | |
| CVE-2025-56266 | CRITICAL | 9.8 | 2025-09-08 | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL. | |
| CVE-2025-56267 | CRITICAL | 9.8 | 2025-09-08 | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file. | |
| CVE-2025-57285 | CRITICAL | 9.8 | 2025-09-08 | codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled direc… | |
| CVE-2024-48341 | LOW | 3.7 | 2025-09-08 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop | |
| CVE-2025-10102 | HIGH | 7.3 | 2025-09-08 | A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function of the file /index.php. Performing manipulation of th… | |
| CVE-2025-10103 | HIGH | 7.3 | 2025-09-08 | A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /home.php. Executing manipulation of the argum… | |
| CVE-2025-43722 | MEDIUM | Patched | 6.7 | 2025-09-08 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially e… |
| CVE-2025-55849 | HIGH | Patched | 8.4 | 2025-09-08 | WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee |
| CVE-2025-9112 | HIGH | 8.8 | 2025-09-08 | The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure_temp_file_uploader' function in all versions u… | |
| CVE-2025-9113 | CRITICAL | 9.8 | 2025-09-08 | The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'doccure_temp_upload_to_media' function in all vers… | |
| CVE-2025-9114 | CRITICAL | 9.8 | 2025-09-08 | The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0. This is due to the plugin providing user-controlled… | |
| CVE-2025-10104 | HIGH | 7.3 | 2025-09-08 | A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /review_search.php. The manipulatio… | |
| CVE-2025-52389 | HIGH | 8.8 | 2025-09-08 | An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other users via a cr… | |
| CVE-2025-53838 | MEDIUM | Patched | 5.4 | 2025-09-08 | LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discovered in versions prior to 2.1.9 that allows an attack… |
| CVE-2025-54994 | NONE | — | 2025-09-08 | @akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written in a way that is vulnera… | |
| CVE-2025-10105 | MEDIUM | Patched | 6.3 | 2025-09-08 | A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the file /cms/article/search. This manipulation of the ar… |
| CVE-2025-52288 | HIGH | Patched | 7.5 | 2025-09-08 | Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) component, in Open5GS thru 2… |
| CVE-2025-10106 | MEDIUM | Patched | 6.3 | 2025-09-08 | A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword … |
| CVE-2025-10108 | HIGH | 7.3 | 2025-09-08 | A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manip… | |
| CVE-2025-57766 | MEDIUM | Patched | 4.8 | 2025-09-08 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vu… |
| CVE-2025-57815 | MEDIUM | Patched | 6.5 | 2025-09-08 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic… |
| CVE-2025-57816 | HIGH | Patched | 7.5 | 2025-09-08 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with… |