Search
28,483 CVEs · High severity
CVEs (28,483, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 28,483 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-10076 | HIGH | 7.3 | 2025-09-08 | A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argum… | |
| CVE-2025-10077 | HIGH | 7.3 | 2025-09-08 | A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of … | |
| CVE-2025-10078 | HIGH | 7.3 | 2025-09-08 | A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the … | |
| CVE-2025-10079 | HIGH | 7.3 | 2025-09-08 | A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of the argu… | |
| CVE-2025-10082 | HIGH | 7.3 | 2025-09-08 | A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the a… | |
| CVE-2025-8085 | HIGH | Patched | 8.6 | 2025-09-08 | The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make reques… |
| CVE-2025-41664 | HIGH | 7.5 | 2025-09-08 | A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the run… | |
| CVE-2025-41682 | HIGH | 8.8 | 2025-09-08 | An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password. | |
| CVE-2025-41708 | HIGH | 7.4 | 2025-09-08 | Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn se… | |
| CVE-2025-10090 | HIGH | Patched | 7.3 | 2025-09-08 | A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.departments/GetTreeDate.aspx. Executing manipulation of… |
| CVE-2025-10091 | HIGH | Patched | 7.3 | 2025-09-08 | A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the… |
| CVE-2025-10092 | HIGH | Patched | 7.3 | 2025-09-08 | A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the compone… |
| CVE-2025-36853 | HIGH | 7.5 | 2025-09-08 | A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow conditio… | |
| CVE-2025-36854 | HIGH | 8.1 | 2025-09-08 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body,… | |
| CVE-2025-36855 | HIGH | 8.8 | 2025-09-08 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/… | |
| CVE-2022-50238 | HIGH | 7.4 | 2025-09-08 | The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online… | |
| CVE-2025-40928 | HIGH | 7.5 | 2025-09-08 | JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact | |
| CVE-2025-40930 | HIGH | 7.5 | 2025-09-08 | JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other… | |
| CVE-2025-55998 | HIGH | 8.1 | 2025-09-08 | A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser… | |
| CVE-2025-56630 | HIGH | Patched | 7.3 | 2025-09-08 | FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file. |
| CVE-2025-59033 | HIGH | 7.4 | 2025-09-08 | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of th… | |
| CVE-2025-10100 | HIGH | 7.3 | 2025-09-08 | A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of the file /admin_class.php?action=login. Performing ma… | |
| CVE-2025-56265 | HIGH | 8.8 | 2025-09-08 | An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a craft… | |
| CVE-2025-10102 | HIGH | 7.3 | 2025-09-08 | A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function of the file /index.php. Performing manipulation of th… | |
| CVE-2025-10103 | HIGH | 7.3 | 2025-09-08 | A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /home.php. Executing manipulation of the argum… |