Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,484 CVEs

CVEs (78,484, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 78,484 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-10073 MEDIUM Patched 4.3 2025-09-08 A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing manipulation can lead to improper…
CVE-2025-10074 LOW Patched 3.5 2025-09-08 A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the argument…
CVE-2025-10075 LOW 3.5 2025-09-08 A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulati…
CVE-2025-10076 HIGH 7.3 2025-09-08 A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argum…
CVE-2025-10077 HIGH 7.3 2025-09-08 A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of …
CVE-2025-10078 HIGH 7.3 2025-09-08 A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the …
CVE-2025-10079 HIGH 7.3 2025-09-08 A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of the argu…
CVE-2025-10080 LOW 3.1 2025-09-08 A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/d…
CVE-2025-10081 MEDIUM 4.7 2025-09-08 A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation of the argument websit…
CVE-2025-10082 HIGH 7.3 2025-09-08 A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the a…
CVE-2025-10083 MEDIUM 6.3 2025-09-08 A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/profile.php. …
CVE-2025-10084 MEDIUM Patched 4.3 2025-09-08 A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /api/logs/error/1 of the component SysLogController. T…
CVE-2025-58422 LOW 3.1 2025-09-08 RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the val…
CVE-2025-10085 MEDIUM 6.3 2025-09-08 A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manage_website.php. The mani…
CVE-2025-10086 MEDIUM 6.3 2025-09-08 A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionCont…
CVE-2025-8085 HIGH Patched 8.6 2025-09-08 The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make reques…
CVE-2025-10087 MEDIUM 4.7 2025-09-08 A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/profit_report.php. Suc…
CVE-2025-10088 LOW 3.5 2025-09-08 A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argumen…
CVE-2025-41664 HIGH 7.5 2025-09-08 A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the run…
CVE-2025-41682 HIGH 8.8 2025-09-08 An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.
CVE-2025-41708 HIGH 7.4 2025-09-08 Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn se…
CVE-2025-58782 MEDIUM Patched 6.5 2025-09-08 Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through …
CVE-2019-25225 MEDIUM Patched 6.1 2025-09-08 `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using th…
CVE-2025-10090 HIGH Patched 7.3 2025-09-08 A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.departments/GetTreeDate.aspx. Executing manipulation of…
CVE-2014-125128 MEDIUM Patched 6.1 2025-09-08 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribu…