Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

66,771 CVEs

CVEs (66,771, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 66,771 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-0765 MEDIUM Patched 4.3 2025-07-24 An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthori…
CVE-2025-1299 MEDIUM Patched 4.3 2025-07-24 An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting f…
CVE-2025-41240 CRITICAL 10.0 2025-07-24 Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versio…
CVE-2025-4393 MEDIUM 6.5 2025-07-24 Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload…
CVE-2025-4394 MEDIUM 6.8 2025-07-24 Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issu…
CVE-2025-4395 MEDIUM 6.8 2025-07-24 Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access…
CVE-2025-4968 MEDIUM Patched 6.4 2025-07-24 The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box,…
CVE-2025-4976 MEDIUM Patched 4.3 2025-07-24 An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, coul…
CVE-2025-7001 MEDIUM Patched 4.3 2025-07-24 An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged …
CVE-2025-7437 CRITICAL 9.8 2025-07-24 The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to…
CVE-2025-7852 CRITICAL 9.8 2025-07-24 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_…
CVE-2025-26397 HIGH Patched 7.8 2025-07-24 SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escal…
CVE-2025-7745 MEDIUM 5.8 2025-07-24 Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
CVE-2025-8009 MEDIUM 4.9 2025-07-24 The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get…
CVE-2025-8107 MEDIUM 6.3 2025-07-24 In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. …
CVE-2025-3669 MEDIUM 6.4 2025-07-24 The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's auto_qrcodesabb shortcode in all versions up to, an…
CVE-2025-4608 MEDIUM 6.4 2025-07-24 The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and includin…
CVE-2025-5084 MEDIUM Patched 6.1 2025-07-24 The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and includi…
CVE-2025-6262 MEDIUM 6.4 2025-07-24 The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai shortcode in all versions up to, and including, 0.4 d…
CVE-2025-6380 CRITICAL 9.8 2025-07-24 The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0.…
CVE-2025-6382 MEDIUM 6.4 2025-07-24 The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortcode in all versions up to, and including, 0.1.10. The…
CVE-2025-6385 MEDIUM 6.4 2025-07-24 The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 0.4.1 due to insufficient i…
CVE-2025-6387 MEDIUM 6.4 2025-07-24 The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.5 due to insufficient…
CVE-2025-6441 CRITICAL 9.8 2025-07-24 The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login…
CVE-2025-6539 MEDIUM 6.4 2025-07-24 The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.5 due to insuffic…