Search
29,735 CVEs · Medium severity
CVEs (29,735, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 29,735 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-10073 | MEDIUM | Patched | 4.3 | 2025-09-08 | A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing manipulation can lead to improper… |
| CVE-2025-10081 | MEDIUM | 4.7 | 2025-09-08 | A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation of the argument websit… | |
| CVE-2025-10083 | MEDIUM | 6.3 | 2025-09-08 | A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/profile.php. … | |
| CVE-2025-10084 | MEDIUM | Patched | 4.3 | 2025-09-08 | A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /api/logs/error/1 of the component SysLogController. T… |
| CVE-2025-10085 | MEDIUM | 6.3 | 2025-09-08 | A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manage_website.php. The mani… | |
| CVE-2025-10086 | MEDIUM | 6.3 | 2025-09-08 | A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionCont… | |
| CVE-2025-10087 | MEDIUM | 4.7 | 2025-09-08 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/profit_report.php. Suc… | |
| CVE-2025-58782 | MEDIUM | Patched | 6.5 | 2025-09-08 | Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through … |
| CVE-2019-25225 | MEDIUM | Patched | 6.1 | 2025-09-08 | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using th… |
| CVE-2014-125128 | MEDIUM | Patched | 6.1 | 2025-09-08 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribu… |
| CVE-2025-10093 | MEDIUM | 5.3 | 2025-09-08 | A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php of the component Devic… | |
| CVE-2025-3212 | MEDIUM | Patched | 5.3 | 2025-09-08 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-… |
| CVE-2025-40929 | MEDIUM | 5.6 | 2025-09-08 | Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspe… | |
| CVE-2025-10096 | MEDIUM | Patched | 6.3 | 2025-09-08 | A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Executing manipulation of… |
| CVE-2025-10097 | MEDIUM | 6.3 | 2025-09-08 | A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app/api/function/execute/route.ts. The manipulation of … | |
| CVE-2025-10098 | MEDIUM | 6.3 | 2025-09-08 | A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of … | |
| CVE-2025-43722 | MEDIUM | Patched | 6.7 | 2025-09-08 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially e… |
| CVE-2025-53838 | MEDIUM | Patched | 5.4 | 2025-09-08 | LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discovered in versions prior to 2.1.9 that allows an attack… |
| CVE-2025-10105 | MEDIUM | Patched | 6.3 | 2025-09-08 | A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the file /cms/article/search. This manipulation of the ar… |
| CVE-2025-10106 | MEDIUM | Patched | 6.3 | 2025-09-08 | A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument keyword … |
| CVE-2025-57766 | MEDIUM | Patched | 4.8 | 2025-09-08 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vu… |
| CVE-2025-57815 | MEDIUM | Patched | 6.5 | 2025-09-08 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic… |
| CVE-2025-10110 | MEDIUM | Patched | 6.3 | 2025-09-08 | A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html l… |
| CVE-2025-1761 | MEDIUM | Patched | 5.9 | 2025-09-08 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. |
| CVE-2025-58452 | MEDIUM | Patched | 6.1 | 2025-09-08 | WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the listar_despachos.php endpoint of the WeGIA ap… |