17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 10501-10550 of 17874 CVEs Page 211 of 358
CVE-2025-64127
Analyzed
10
Unknown Multiple Products

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are la...

2025-11-27
CVE-2025-64126
Analyzed
10
Unknown Multiple Products

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without...

2025-11-27
CVE-2025-64112
8
Statmatic Multiple Products

Statmatic is a Laravel and Git powered content management system (CMS)

2025-10-30
CVE-2025-64109
8.8
Cursor Multiple Products

Cursor is a code editor built for programming with AI

2025-11-06
CVE-2025-64104
Analyzed
7.3
LangGraph Multiple Products

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite)

2025-10-29
CVE-2025-64101
8.1
Zitadel Multiple Products

Zitadel is open-source identity infrastructure software

2025-10-29
CVE-2025-64096
Analyzed
8.8
CryptoLib Multiple Products

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2025-10-30
CVE-2025-64095
Analyzed
10
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor...

2025-10-28
CVE-2025-64093
Analyzed
10
Unknown Multiple Products

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

2026-01-10
CVE-2025-64092
Analyzed
7.5
Unknown Multiple Products

This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database

2026-01-10
CVE-2025-64091
8.6
Unknown Multiple Products

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device

2026-01-10
CVE-2025-64090
Analyzed
10
Unknown Multiple Products

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

2026-01-10
CVE-2025-64081
Analyzed
9.8
HP Multiple Products

SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to ex...

2025-12-09
CVE-2025-64076
7.5
Unknown Multiple Products

Multiple vulnerabilities exist in cbor2 through version 5

2025-11-19
CVE-2025-64075
Analyzed
10
Unknown WE2001

A path traversal vulnerability in the check_token function of ZBT WE2001 (23.09.27) allows remote attackers to bypass authentication and perform admin...

2026-02-12
CVE-2025-64066
Analyzed
8.6
Primakon Multiple Products

Primakon Pi Portal 1

2025-11-26
CVE-2025-64065
Analyzed
8.8
Primakon Multiple Products

The Primakon Pi Portal 1

2025-11-27
CVE-2025-64064
Analyzed
8.8
Primakon Multiple Products

Primakon Pi Portal 1

2025-11-26
CVE-2025-64062
Analyzed
8.8
Primakon Multiple Products

The Primakon Pi Portal 1

2025-11-27
CVE-2025-64057
8.3
Unknown Multiple Products

Directory traversal vulnerability in Fanvil x210 V2 2

2025-12-06
CVE-2025-64053
8.2
Unknown Multiple Products

A Buffer overflow vulnerability on Fanvil x210 2

2025-12-06
CVE-2025-64050
Analyzed
7.2
HP Multiple Products

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5

2025-11-26
CVE-2025-6397
Analyzed
8.6
Ankara Hosting Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Hosting Website Design Website Sof...

2026-02-04
CVE-2025-63958
Analyzed
9.8
Unknown Multiple Products

MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication...

2025-11-25
CVE-2025-63955
7.5
Unknown Multiple Products

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students

2025-11-19
CVE-2025-63951
7.5
Unknown Multiple Products

An insecure deserialization vulnerability exists in the rss-mp3

2025-12-20
CVE-2025-63950
7.5
Unknown Multiple Products

An insecure deserialization vulnerability exists in the download

2025-12-20
CVE-2025-63946
7.4
Tencent PC Multiple Products

A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17

2026-02-24
CVE-2025-63945
7.4
Tencent iOA app Multiple Products

A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210

2026-02-24
CVE-2025-63939
Analyzed
9.8
HP Multiple Products

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sit...

2026-04-15
CVE-2025-63932
Analyzed
7.3
D-Link Multiple Products

D-Link Router DIR-868L A1 FW106KRb01

2025-11-20
CVE-2025-63929
7.5
Unknown Multiple Products

A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08)

2025-11-14
CVE-2025-63917
7.1
PDFPatcher Multiple Products

PDFPatcher thru 1

2025-11-18
CVE-2025-63916
8.1
MyScreenTools Multiple Products

MyScreenTools v2

2025-11-18
CVE-2025-63912
7.5
Appliance Multiple Products

Cohesity TranZman Migration Appliance Release 4

2026-03-05
CVE-2025-63911
7.2
Appliance Multiple Products

Cohesity TranZman Migration Appliance Release 4

2026-03-04
CVE-2025-63910
7.2
Cohesity TranZman Multiple Products

An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4

2026-03-04
CVE-2025-63909
7.2
Appliance Multiple Products

Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4

2026-03-04
CVE-2025-63895
Analyzed
7.5
Google Multiple Products

An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12

2025-12-12
CVE-2025-63891
Analyzed
7.5
Unknown Multiple Products

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to dis...

2025-11-15
CVE-2025-6389
Analyzed
9.8
WordPress Multiple Products

The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pag...

2025-11-26
CVE-2025-63889
Analyzed
7.5
HP Multiple Products

The fetch function in file thinkphp\library\think\Template

2025-11-20
CVE-2025-6388
Analyzed
9.8
WordPress Multiple Products

The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.2.14. This is due to the cust...

2025-10-03
CVE-2025-63811
7.5
Unknown Multiple Products

An issue was discovered in dvsekhvalnov jose2go 1

2025-11-14
CVE-2025-63807
7.5
Unknown Multiple Products

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13)

2025-11-20
CVE-2025-63800
7.5
Unknown Multiple Products

The password change endpoint in Open Source Point of Sale 3

2025-11-19
CVE-2025-6380
Analyzed
9.8
WordPress Multiple Products

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in ve...

2025-07-25
CVE-2025-63757
7.5
Unknown Multiple Products

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output

2025-12-20
CVE-2025-63748
8.8
QaTraq Multiple Products

QaTraq 6

2025-11-18
CVE-2025-63747
Analyzed
9.8
QaTraq Multiple Products

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web applicati...

2025-11-18