Search
23,330 CVEs · High severity
CVEs (23,330, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 23,330 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-26397 | HIGH | Patched | 7.8 | 2025-07-24 | SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escal… |
| CVE-2025-7640 | HIGH | 8.1 | 2025-07-24 | The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to missing or incorrect n… | |
| CVE-2025-7695 | HIGH | 8.8 | 2025-07-24 | The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST endpoint in ver… | |
| CVE-2025-33109 | HIGH | 7.5 | 2025-07-24 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or … | |
| CVE-2025-51087 | HIGH | 8.6 | 2025-07-24 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow. | |
| CVE-2025-25214 | HIGH | 8.8 | 2025-07-24 | A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series of specially crafted HT… | |
| CVE-2025-36548 | HIGH | 8.3 | 2025-07-24 | A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A sp… | |
| CVE-2025-48732 | HIGH | 7.3 | 2025-07-24 | An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code exe… | |
| CVE-2025-5039 | HIGH | Patched | 7.8 | 2025-07-24 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the curren… |
| CVE-2025-31952 | HIGH | 7.1 | 2025-07-24 | HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthoriz… | |
| CVE-2025-31953 | HIGH | 7.1 | 2025-07-24 | HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties. | |
| CVE-2025-31955 | HIGH | 7.6 | 2025-07-24 | HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system. | |
| CVE-2025-22165 | HIGH | Patched | 7.3 | 2025-07-24 | This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability,… |
| CVE-2015-10144 | HIGH | Patched | 8.8 | 2025-07-25 | The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions… |
| CVE-2025-8131 | HIGH | 8.8 | 2025-07-25 | A vulnerability was found in Tenda AC20 16.03.08.05. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /goform/SetSta… | |
| CVE-2025-5831 | HIGH | Patched | 8.8 | 2025-07-25 | The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function in all versions up to,… |
| CVE-2025-5835 | HIGH | Patched | 8.8 | 2025-07-25 | The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis() function in all vers… |
| CVE-2025-8136 | HIGH | 8.8 | 2025-07-25 | A vulnerability, which was classified as critical, was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected is an unknown function of the file /boafrm/formFilter of the c… | |
| CVE-2025-8137 | HIGH | 8.8 | 2025-07-25 | A vulnerability has been found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /bo… | |
| CVE-2025-8138 | HIGH | 8.8 | 2025-07-25 | A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formOn… | |
| CVE-2023-7306 | HIGH | 7.5 | 2025-07-25 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() funct… | |
| CVE-2025-8139 | HIGH | 8.8 | 2025-07-25 | A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been classified as critical. This affects an unknown part of the file /boafrm/formPortFw of the com… | |
| CVE-2025-8140 | HIGH | 8.8 | 2025-07-25 | A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formWlanMult… | |
| CVE-2025-8183 | HIGH | 7.5 | 2025-07-25 | NULL Pointer Dereference in µD3TN via non-singleton destination Endpoint Identifier allows remote attacker to reliably cause DoS | |
| CVE-2025-38357 | HIGH | Patched | 7.8 | 2025-07-25 | In the Linux kernel, the following vulnerability has been resolved: fuse: fix runtime warning on truncate_folio_batch_exceptionals() The WARN_ON_ONCE is introduced on tru… |