8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 5151-5200 of 8341 CVEs Page 104 of 167
CVE-2025-41687
Analyzed
9.8
Unknown Multiple Products

An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices.

2025-07-23
CVE-2025-41686
7.8
Unknown Multiple Products

A low-privileged local attacker can exploit improper permissions on nssm

2025-08-12
CVE-2025-41684
Analyzed
8.8
Unknown Multiple Products

An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user in...

2025-07-23
CVE-2025-41683
8.8
Unknown Multiple Products

An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user in...

2025-07-23
CVE-2025-41682
Analyzed
8.8
Unknown Multiple Products

An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password

2025-09-08
CVE-2025-41672
10
Unknown Multiple Products

A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.

2025-07-07
CVE-2025-41668
8.8
Unknown Multiple Products

A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and ex...

2025-07-08
CVE-2025-41667
8.8
Unknown Multiple Products

A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to...

2025-07-08
CVE-2025-41666
8.8
Unknown Multiple Products

A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file o...

2025-07-08
CVE-2025-41664
Analyzed
7.5
Unknown Multiple Products

A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission h...

2025-09-08
CVE-2025-41659
Analyzed
8.3
Unknown Multiple Products

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys

2025-08-05
CVE-2025-41656
10
Pilz GmbH & Co. KG IndustrialPI 4 with Firmware Bullseye

An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED...

2025-07-06
CVE-2025-41648
9.8
Unknown Multiple Products

An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all ava...

2025-07-06
CVE-2025-41459
7.8
Studio Multiple Products

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5

2025-07-22
CVE-2025-41430
7.5
Unknown Multiple Products

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate

2025-10-16
CVE-2025-41425
8.1
DuraComm Multiple Products

DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack

2025-07-23
CVE-2025-41420
Analyzed
9.6
Unknown Multiple Products

A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954f...

2025-07-25
CVE-2025-41392
Analyzed
7.8
Intel Multiple Products

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12

2025-08-19
CVE-2025-41390
Analyzed
7.8
Unknown Multiple Products

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co

2025-10-20
CVE-2025-41253
Analyzed
7.5
Cloud Multiple Products

The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties t...

2025-10-16
CVE-2025-41252
Analyzed
7.5
VMware Multiple Products

Description: VMware NSX contains a username enumeration vulnerability

2025-09-29
CVE-2025-41251
Analyzed
8.1
VMware Multiple Products

VMware NSX contains a weak password recovery mechanism vulnerability

2025-09-29
CVE-2025-41250
Analyzed
8.5
VMware Multiple Products

VMware vCenter contains an SMTP header injection vulnerability

2025-09-29
CVE-2025-41249
7.5
Spring Multiple Products

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized supe...

2025-09-16
CVE-2025-41248
7.5
Spring Multiple Products

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super...

2025-09-16
CVE-2025-41246
Analyzed
7.6
Microsoft Multiple Products

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls

2025-09-29
CVE-2025-41244
KEV Analyzed
7.8
VMware Multiple Products

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability

2025-09-29
CVE-2025-41243
Analyzed
10
Intel Multiple Products

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable whe...

2025-09-16
CVE-2025-41240
Analyzed
10
Kubernetes Multiple Products

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document ro...

2025-07-25
CVE-2025-41239
7.1
VMware Multiple Products

VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSo...

2025-07-15
CVE-2025-41238
Analyzed
9.3
VMware Multiple Products

VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bou...

2025-07-15
CVE-2025-41237
Analyzed
9.3
VMware Multiple Products

VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds wri...

2025-07-15
CVE-2025-41236
Analyzed
9.3
VMware Multiple Products

VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local ad...

2025-07-15
CVE-2025-41224
8.8
Unknown Multiple Products

A vulnerability has been identified in RUGGEDCOM RMC8388 V5

2025-07-10
CVE-2025-41115
Analyzed
10
Unknown Multiple Products

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by in...

2025-11-22
CVE-2025-41075
7.5
LimeSurvey Multiple Products

Vulnerability in LimeSurvey 6

2025-11-22
CVE-2025-41074
7.5
LimeSurvey Multiple Products

Vulnerability in LimeSurvey 6

2025-11-22
CVE-2025-41068
7.5
Reachable Assertion Multiple Products

Reachable Assertion vulnerability in Open5GS up to version 2

2025-10-28
CVE-2025-41067
7.5
Reachable Assertion Multiple Products

Reachable Assertion vulnerability in Open5GS up to version 2

2025-10-28
CVE-2025-41034
Analyzed
9.8
Unknown Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41033
Analyzed
9.8
Intel Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41032
Analyzed
9.8
Intel Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41015
7.5
Unknown Multiple Products

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304

2025-12-03
CVE-2025-41014
7.5
Unknown Multiple Products

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304

2025-12-03
CVE-2025-41013
9.8
Unknown Multiple Products

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databa...

2025-12-04
CVE-2025-40942
8.8
TeleControl Multiple Products

A vulnerability has been identified in TeleControl Server Basic (All versions < V3

2026-01-14
CVE-2025-40938
8.1
SIMATIC Multiple Products

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4

2025-12-10
CVE-2025-40937
8.3
SIMATIC Multiple Products

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4

2025-12-10
CVE-2025-40936
7.8
Unknown Multiple Products

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29

2025-11-18
CVE-2025-40933
7.5
Apache Multiple Products

Apache::AuthAny::Cookie v0

2025-09-17