Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,797 CVEs · Low severity

CVEs (2,797, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 2,797 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-10074 LOW Patched 3.5 2025-09-08 A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the argument…
CVE-2025-10075 LOW 3.5 2025-09-08 A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulati…
CVE-2025-10080 LOW 3.1 2025-09-08 A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/d…
CVE-2025-58422 LOW 3.1 2025-09-08 RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the val…
CVE-2025-10088 LOW 3.5 2025-09-08 A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argumen…
CVE-2025-51586 LOW Patched 3.7 2025-09-08 An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password…
CVE-2025-10099 LOW Patched 2.4 2025-09-08 A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_usuario_cad.php of…
CVE-2024-48341 LOW 3.7 2025-09-08 dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop
CVE-2025-10117 LOW 3.5 2025-09-09 A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add New Task. E…
CVE-2025-42913 LOW 3.1 2025-09-09 Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and p…
CVE-2025-42914 LOW 3.1 2025-09-09 Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and p…
CVE-2025-42927 LOW 3.4 2025-09-09 SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdat…
CVE-2025-8889 LOW Patched 3.8 2025-09-09 The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the …
CVE-2025-9111 LOW Patched 3.5 2025-09-09 The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perfo…
CVE-2025-40802 LOW 3.1 2025-09-09 A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to hi…
CVE-2025-40803 LOW 3.1 2025-09-09 A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical information from the device. This…
CVE-2025-59014 LOW Patched 2.7 2025-09-09 An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a deni…
CVE-2025-8277 LOW 3.1 2025-09-09 A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these re…
CVE-2025-10222 LOW Patched 3.3 2025-09-10 Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows all…
CVE-2025-10216 LOW 2.6 2025-09-10 A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The…
CVE-2025-10234 LOW Patched 2.4 2025-09-11 A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point_edit.shtm of the component Data Point Edit Module. …
CVE-2025-10235 LOW Patched 2.4 2025-09-11 A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. This manipulation of…
CVE-2025-6088 LOW Patched 3.1 2025-09-11 In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if th…
CVE-2025-10246 LOW 3.5 2025-09-11 A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /…
CVE-2025-10252 LOW 3.1 2025-09-11 A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deseriali…