Search
78,402 CVEs
EOL hidden · Show all products
CVEs (78,402, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 78,402 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-10073 | MEDIUM | Patched | 4.3 | 2025-09-08 | A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing manipulation can lead to improper… |
| CVE-2025-10074 | LOW | Patched | 3.5 | 2025-09-08 | A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the argument… |
| CVE-2025-10075 | LOW | 3.5 | 2025-09-08 | A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulati… | |
| CVE-2025-10076 | HIGH | 7.3 | 2025-09-08 | A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argum… | |
| CVE-2025-10077 | HIGH | 7.3 | 2025-09-08 | A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of … | |
| CVE-2025-10078 | HIGH | 7.3 | 2025-09-08 | A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the … | |
| CVE-2025-10079 | HIGH | 7.3 | 2025-09-08 | A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of the argu… | |
| CVE-2025-10080 | LOW | 3.1 | 2025-09-08 | A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/d… | |
| CVE-2025-10081 | MEDIUM | 4.7 | 2025-09-08 | A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation of the argument websit… | |
| CVE-2025-10082 | HIGH | 7.3 | 2025-09-08 | A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the a… | |
| CVE-2025-10083 | MEDIUM | 6.3 | 2025-09-08 | A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/profile.php. … | |
| CVE-2025-10084 | MEDIUM | Patched | 4.3 | 2025-09-08 | A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /api/logs/error/1 of the component SysLogController. T… |
| CVE-2025-58422 | LOW | 3.1 | 2025-09-08 | RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the val… | |
| CVE-2025-10085 | MEDIUM | 6.3 | 2025-09-08 | A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manage_website.php. The mani… | |
| CVE-2025-10086 | MEDIUM | 6.3 | 2025-09-08 | A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionCont… | |
| CVE-2025-8085 | HIGH | Patched | 8.6 | 2025-09-08 | The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make reques… |
| CVE-2025-10087 | MEDIUM | 4.7 | 2025-09-08 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/profit_report.php. Suc… | |
| CVE-2025-10088 | LOW | 3.5 | 2025-09-08 | A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argumen… | |
| CVE-2025-41664 | HIGH | 7.5 | 2025-09-08 | A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the run… | |
| CVE-2025-41682 | HIGH | 8.8 | 2025-09-08 | An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password. | |
| CVE-2025-41708 | HIGH | 7.4 | 2025-09-08 | Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn se… | |
| CVE-2025-58782 | MEDIUM | Patched | 6.5 | 2025-09-08 | Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through … |
| CVE-2019-25225 | MEDIUM | Patched | 6.1 | 2025-09-08 | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using th… |
| CVE-2025-10090 | HIGH | Patched | 7.3 | 2025-09-08 | A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.departments/GetTreeDate.aspx. Executing manipulation of… |
| CVE-2014-125128 | MEDIUM | Patched | 6.1 | 2025-09-08 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribu… |