Search
66,771 CVEs
CVEs (66,771, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 66,771 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-0249 | LOW | 3.3 | 2025-07-25 | HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data withou… | |
| CVE-2025-0250 | LOW | 2.2 | 2025-07-25 | HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner that may increas… | |
| CVE-2025-7742 | NONE | — | 2025-07-25 | An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST request to the devices non-vola… | |
| CVE-2025-8124 | MEDIUM | Patched | 6.3 | 2025-07-25 | A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /system/… |
| CVE-2025-0251 | LOW | 2.6 | 2025-07-25 | HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks. | |
| CVE-2025-0252 | LOW | 2.6 | 2025-07-25 | HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized acc… | |
| CVE-2025-0253 | LOW | 2.0 | 2025-07-25 | HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential v… | |
| CVE-2025-54558 | MEDIUM | Patched | 4.1 | 2025-07-25 | OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag. |
| CVE-2025-8125 | MEDIUM | Patched | 6.3 | 2025-07-25 | A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/role/auth… |
| CVE-2015-10143 | CRITICAL | Patched | 9.8 | 2025-07-25 | The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_sa… |
| CVE-2015-10144 | HIGH | Patched | 8.8 | 2025-07-25 | The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions… |
| CVE-2019-25224 | CRITICAL | Patched | 9.8 | 2025-07-25 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticat… |
| CVE-2025-54566 | MEDIUM | Patched | 4.2 | 2025-07-25 | hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327. |
| CVE-2025-54567 | MEDIUM | Patched | 4.2 | 2025-07-25 | hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327. |
| CVE-2025-8126 | MEDIUM | Patched | 6.3 | 2025-07-25 | A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipulation of the… |
| CVE-2025-54568 | LOW | Patched | 3.7 | 2025-07-25 | Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separately for each edge node. |
| CVE-2025-8127 | MEDIUM | Patched | 6.3 | 2025-07-25 | A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. This vulnerability affects unknown code of the file /system/user/list. The manipulation of… |
| CVE-2025-8128 | MEDIUM | 6.3 | 2025-07-25 | A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de48f7fbe98. This issue affects some unknown processing… | |
| CVE-2025-8129 | LOW | Patched | 3.5 | 2025-07-25 | A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP… |
| CVE-2025-8131 | HIGH | 8.8 | 2025-07-25 | A vulnerability was found in Tenda AC20 16.03.08.05. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /goform/SetSta… | |
| CVE-2025-8132 | MEDIUM | Patched | 5.4 | 2025-07-25 | A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function delfile of the file app/extend/utils.js… |
| CVE-2025-7022 | MEDIUM | 6.1 | 2025-07-25 | The My Reservation System WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scr… | |
| CVE-2025-8133 | MEDIUM | Patched | 6.3 | 2025-07-25 | A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function getArticle of the file app/modules/api/service/gather.j… |
| CVE-2025-8134 | MEDIUM | 6.3 | 2025-07-25 | A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-resu… | |
| CVE-2025-5831 | HIGH | Patched | 8.8 | 2025-07-25 | The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function in all versions up to,… |