Search
78,484 CVEs
CVEs (78,484, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 78,484 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-57817 | HIGH | Patched | 7.2 | 2025-09-08 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly aut… |
| CVE-2025-58365 | NONE | Patched | — | 2025-09-08 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, the blog application in XWiki allowed remote code exec… |
| CVE-2025-58444 | NONE | Patched | — | 2025-09-08 | The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development to… |
| CVE-2025-58449 | NONE | — | 2025-09-08 | Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permiss… | |
| CVE-2025-58450 | NONE | — | 2025-09-08 | pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible in versions prior to 2.0.0-rc3. The validation pres… | |
| CVE-2025-58451 | NONE | — | 2025-09-08 | Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially exponential worst-case complexity. This could cause … | |
| CVE-2025-10109 | HIGH | 7.3 | 2025-09-08 | A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Execu… | |
| CVE-2025-10110 | MEDIUM | Patched | 6.3 | 2025-09-08 | A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html l… |
| CVE-2025-10111 | HIGH | 7.3 | 2025-09-08 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instru… | |
| CVE-2025-1761 | MEDIUM | Patched | 5.9 | 2025-09-08 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. |
| CVE-2025-58452 | MEDIUM | Patched | 6.1 | 2025-09-08 | WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the listar_despachos.php endpoint of the WeGIA ap… |
| CVE-2025-58453 | HIGH | Patched | 8.2 | 2025-09-08 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior in the endpoint /WeGIA/html/memorando/ex… |
| CVE-2025-58454 | HIGH | Patched | 8.2 | 2025-09-08 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior inthe endpoint /WeGIA/html/memorando/lis… |
| CVE-2025-58745 | CRITICAL | Patched | 9.9 | 2025-09-08 | WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only check MIM… |
| CVE-2025-58746 | CRITICAL | 9.0 | 2025-09-08 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to ver… | |
| CVE-2025-58751 | MEDIUM | Patched | 5.3 | 2025-09-08 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were ser… |
| CVE-2025-58752 | MEDIUM | Patched | 5.3 | 2025-09-08 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.… |
| CVE-2025-10112 | HIGH | 7.3 | 2025-09-09 | A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/… | |
| CVE-2025-10113 | HIGH | 7.3 | 2025-09-09 | A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index… | |
| CVE-2025-43763 | MEDIUM | Patched | 6.5 | 2025-09-09 | A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024… |
| CVE-2025-58755 | HIGH | Patched | 8.8 | 2025-09-09 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compress… |
| CVE-2025-58756 | HIGH | Patched | 8.8 | 2025-09-09 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map_location=tor… |
| CVE-2025-58757 | HIGH | Patched | 8.8 | 2025-09-09 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in `monai/data/utils.p… |
| CVE-2025-10114 | HIGH | 7.3 | 2025-09-09 | A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument Name … | |
| CVE-2025-10115 | HIGH | 7.3 | 2025-09-09 | A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName cau… |