Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-42958 CRITICAL 9.1 2025-09-09 Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete…
CVE-2025-43778 MEDIUM Patched 6.1 2025-09-09 A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 2025.Q1.0 through 2025.Q1.16, 2024…
CVE-2025-10122 MEDIUM 4.7 2025-09-09 A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the arg…
CVE-2025-10123 HIGH Patched 7.3 2025-09-09 A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing m…
CVE-2025-43777 MEDIUM Patched 5.3 2025-09-09 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.1…
CVE-2025-9489 MEDIUM 5.0 2025-09-09 The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.2. This is due to the s…
CVE-2025-8889 LOW Patched 3.8 2025-09-09 The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the …
CVE-2025-9058 MEDIUM 6.4 2025-09-09 The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.5.2 due to insufficient input sanitizat…
CVE-2025-9061 MEDIUM 6.4 2025-09-09 The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.4.5 due to insufficient input sanitizat…
CVE-2025-9111 LOW Patched 3.5 2025-09-09 The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perfo…
CVE-2025-9539 HIGH 8.0 2025-09-09 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of d…
CVE-2025-9542 MEDIUM 5.4 2025-09-09 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modifi…
CVE-2025-10134 CRITICAL 9.1 2025-09-09 The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_…
CVE-2025-40594 MEDIUM 6.3 2025-09-09 A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 H&hellip;
CVE-2025-40757 MEDIUM 5.3 2025-09-09 A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). A&hellip;
CVE-2025-40795 CRITICAL Patched 9.8 2025-09-09 A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), Us&hellip;
CVE-2025-40796 HIGH Patched 7.5 2025-09-09 A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), Us&hellip;
CVE-2025-40797 HIGH Patched 7.5 2025-09-09 A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), Us&hellip;
CVE-2025-40798 HIGH Patched 7.5 2025-09-09 A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), Us&hellip;
CVE-2025-40802 LOW 3.1 2025-09-09 A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to hi&hellip;
CVE-2025-40803 LOW 3.1 2025-09-09 A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical information from the device. This&hellip;
CVE-2025-40804 CRITICAL 9.1 2025-09-09 A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authenticat&hellip;
CVE-2025-41701 HIGH 7.8 2025-09-09 An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. T&hellip;
CVE-2025-59013 MEDIUM Patched 6.1 2025-09-09 An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an a&hellip;
CVE-2025-59014 LOW Patched 2.7 2025-09-09 An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a deni&hellip;