Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

23,330 CVEs · High severity

CVEs (23,330, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 23,330 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-26397 HIGH Patched 7.8 2025-07-24 SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escal…
CVE-2025-7640 HIGH 8.1 2025-07-24 The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to missing or incorrect n…
CVE-2025-7695 HIGH 8.8 2025-07-24 The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST endpoint in ver…
CVE-2025-33109 HIGH 7.5 2025-07-24 IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or …
CVE-2025-51087 HIGH 8.6 2025-07-24 Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.
CVE-2025-25214 HIGH 8.8 2025-07-24 A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series of specially crafted HT…
CVE-2025-36548 HIGH 8.3 2025-07-24 A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A sp…
CVE-2025-48732 HIGH 7.3 2025-07-24 An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code exe…
CVE-2025-5039 HIGH Patched 7.8 2025-07-24 A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the curren…
CVE-2025-31952 HIGH 7.1 2025-07-24 HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthoriz…
CVE-2025-31953 HIGH 7.1 2025-07-24 HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
CVE-2025-31955 HIGH 7.6 2025-07-24 HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
CVE-2025-22165 HIGH Patched 7.3 2025-07-24 This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability,…
CVE-2015-10144 HIGH Patched 8.8 2025-07-25 The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions…
CVE-2025-8131 HIGH 8.8 2025-07-25 A vulnerability was found in Tenda AC20 16.03.08.05. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /goform/SetSta…
CVE-2025-5831 HIGH Patched 8.8 2025-07-25 The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function in all versions up to,…
CVE-2025-5835 HIGH Patched 8.8 2025-07-25 The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis() function in all vers…
CVE-2025-8136 HIGH 8.8 2025-07-25 A vulnerability, which was classified as critical, was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected is an unknown function of the file /boafrm/formFilter of the c…
CVE-2025-8137 HIGH 8.8 2025-07-25 A vulnerability has been found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /bo…
CVE-2025-8138 HIGH 8.8 2025-07-25 A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formOn…
CVE-2023-7306 HIGH 7.5 2025-07-25 The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() funct…
CVE-2025-8139 HIGH 8.8 2025-07-25 A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been classified as critical. This affects an unknown part of the file /boafrm/formPortFw of the com…
CVE-2025-8140 HIGH 8.8 2025-07-25 A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formWlanMult…
CVE-2025-8183 HIGH 7.5 2025-07-25 NULL Pointer Dereference in µD3TN via non-singleton destination Endpoint Identifier allows remote attacker to reliably cause DoS
CVE-2025-38357 HIGH Patched 7.8 2025-07-25 In the Linux kernel, the following vulnerability has been resolved: fuse: fix runtime warning on truncate_folio_batch_exceptionals() The WARN_ON_ONCE is introduced on tru…