17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 10151-10200 of 17874 CVEs Page 204 of 358
CVE-2025-66561
7.3
Unknown Multiple Products

SysReptor is a fully customizable pentest reporting platform

2025-12-05
CVE-2025-66533
7.8
StellarWP GiveWP give Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection

2025-12-10
CVE-2025-66506
7.5
Unknown Multiple Products

Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity

2025-12-05
CVE-2025-66499
Analyzed
7.8
Unknown Multiple Products

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data

2025-12-20
CVE-2025-66495
Analyzed
7.8
Microsoft Multiple Products

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025

2025-12-20
CVE-2025-66494
Analyzed
7.8
Reader Multiple Products

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025

2025-12-20
CVE-2025-66493
Analyzed
7.8
Editor Multiple Products

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025

2025-12-20
CVE-2025-66492
8.2
Masa Multiple Products

Masa CMS is an open source Enterprise Content Management platform

2025-12-13
CVE-2025-66481
Analyzed
9.6
Intel Multiple Products

DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improp...

2025-12-10
CVE-2025-66480
Analyzed
9.8
Intel Multiple Products

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component rel...

2026-02-03
CVE-2025-66476
7.8
Vim Multiple Products

Vim is an open source, command line text editor

2025-12-03
CVE-2025-66468
7.6
Aimeos Multiple Products

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components

2025-12-03
CVE-2025-66467
8
Apache CloudStack allows

Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned

2026-05-09
CVE-2025-66449
Analyzed
8.8
ConvertXis Multiple Products

ConvertXis a self-hosted online file converter

2025-12-16
CVE-2025-66448
7.1
Unknown Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2025-12-02
CVE-2025-66446
8.8
MaxKB Multiple Products

MaxKB is an open-source AI assistant for enterprise

2025-12-12
CVE-2025-66444
8.2
Hitachi Multiple Products

Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hita...

2025-12-24
CVE-2025-66443
7.5
Pexip Multiple Products

Pexip Infinity 35

2025-12-26
CVE-2025-66437
8.8
ERPNext Multiple Products

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15

2025-12-17
CVE-2025-66431
7.8
Plesk Multiple Products

WebPros Plesk before 18

2025-12-03
CVE-2025-66430
Analyzed
9.1
Apache Multiple Products

Plesk 18.0 has Incorrect Access Control.

2025-12-13
CVE-2025-66429
8.8
Unknown Multiple Products

An issue was discovered in cPanel 110 through 132

2025-12-13
CVE-2025-66428
Analyzed
8.8
WordPress Multiple Products

An issue with WordPress directory names in WebPros WordPress Toolkit before 6

2026-01-24
CVE-2025-66423
Analyzed
7.1
Intel Multiple Products

Tryton trytond 6

2025-12-01
CVE-2025-66419
8.8
MaxKB Multiple Products

MaxKB is an open-source AI assistant for enterprise

2025-12-12
CVE-2025-66417
7.5
GLPI Multiple Products

GLPI is a free asset and IT management software package

2026-01-16
CVE-2025-66411
Analyzed
7.8
Coder Multiple Products

Coder allows organizations to provision remote development environments via Terraform

2025-12-03
CVE-2025-66401
Analyzed
9.8
GitHub Multiple Products

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical...

2025-12-02
CVE-2025-66398
Analyzed
9.6
Unknown Multiple Products

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the int...

2026-01-02
CVE-2025-66397
8.3
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-18
CVE-2025-66396
7.2
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-18
CVE-2025-66395
8.8
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-18
CVE-2025-66391
Analyzed
8.8
Citrix Cloud

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e

2026-06-18
CVE-2025-66389
Analyzed
7.5
GitHub Copilot

GitHub Copilot 1

2026-06-23
CVE-2025-66384
Analyzed
8.2
Apache Multiple Products

app/Controller/EventsController

2025-11-29
CVE-2025-66379
7.5
Infinity Multiple Products

Pexip Infinity before 39

2025-12-26
CVE-2025-66377
7.5
Infinity Multiple Products

Pexip Infinity before 39

2025-12-26
CVE-2025-66376
KEV
7.2
Zimbra Multiple Products

Zimbra Collaboration (ZCS) 10 before 10

2026-01-06
CVE-2025-66374
Analyzed
7.8
Privilege Endpoint Privilege Manager (EPM) Agent

CyberArk Endpoint Privilege Manager Agent through 25

2026-02-05
CVE-2025-6637
7.8
Unknown Multiple Products

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability

2025-07-29
CVE-2025-66363
7.5
Samsung Mobile Processor

An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200

2026-03-05
CVE-2025-6636
7.8
Unknown Multiple Products

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability

2025-07-29
CVE-2025-66359
Analyzed
8.5
Logpoint Multiple Products

An issue was discovered in Logpoint before 7

2025-11-28
CVE-2025-6635
7.8
Unknown Multiple Products

A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability

2025-07-29
CVE-2025-66342
7.8
Unknown Multiple Products

A type confusion vulnerability exists in the EMF functionality of Canva Affinity

2026-03-18
CVE-2025-6634
7.8
Unknown Multiple Products

A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability

2025-08-07
CVE-2025-66336
Analyzed
8.1
Apache Doris MCP Server

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path

2026-06-23
CVE-2025-6633
8.3
Unknown Multiple Products

A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability

2025-08-07
CVE-2025-66328
8.4
Unknown Multiple Products

Multi-thread race condition vulnerability in the network management module

2025-12-09
CVE-2025-66327
7.1
Unknown Multiple Products

Race condition vulnerability in the network module

2025-12-09