17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 11401-11450 of 17874 CVEs Page 229 of 358
CVE-2025-59538
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59537
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59534
Analyzed
7.3
CryptoLib Multiple Products

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2025-09-23
CVE-2025-59531
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59530
7.5
Unknown Multiple Products

quic-go is an implementation of the QUIC protocol in Go

2025-10-10
CVE-2025-5953
Analyzed
8.8
WordPress Multiple Products

The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee()...

2025-07-05
CVE-2025-59528
Analyzed
10
Unknown Multiple Products

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execut...

2025-09-22
CVE-2025-59527
7.5
Unknown Multiple Products

Flowise is a drag & drop user interface to build a customized large language model flow

2025-09-22
CVE-2025-59518
8
Unknown Multiple Products

In LemonLDAP::NG before 2

2025-09-17
CVE-2025-59517
7.8
Microsoft Multiple Products

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-59516
7.8
Microsoft Multiple Products

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-59514
7.8
Microsoft Multiple Products

Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59512
7.8
Unknown Multiple Products

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59511
7.8
Microsoft Multiple Products

External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59505
7.8
Microsoft Multiple Products

Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59503
Analyzed
9.9
Microsoft Multiple Products

Server-side request forgery (ssrf) in Azure Compute Gallery allows an authorized attacker to elevate privileges over a network.

2025-10-23
CVE-2025-59500
Analyzed
7.7
Microsoft Multiple Products

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network

2025-10-23
CVE-2025-59499
8.8
Unknown Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-11-13
CVE-2025-5949
Analyzed
8.8
WordPress Multiple Products

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6

2025-11-01
CVE-2025-59489
Analyzed
7.4
Apple Multiple Products

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an uni...

2025-10-03
CVE-2025-59484
8.3
Unknown Multiple Products

The use of a broken or risky cryptographic algorithm was discovered in firmware version 3

2025-09-23
CVE-2025-59481
8.7
Unknown Multiple Products

A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least res...

2025-10-15
CVE-2025-5948
Analyzed
9.8
WordPress Multiple Products

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0....

2025-09-19
CVE-2025-59478
7.5
Unknown Multiple Products

When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management...

2025-10-16
CVE-2025-5947
Analyzed
9.8
WordPress Multiple Products

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including,...

2025-08-01
CVE-2025-59467
7.5
UCRM Argentina Multiple Products

A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1

2026-01-06
CVE-2025-59465
7.5
HP Multiple Products

A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node

2026-01-21
CVE-2025-59461
Analyzed
7.6
Unknown Multiple Products

A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services

2025-10-27
CVE-2025-59460
7.5
Unknown Multiple Products

The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access

2025-10-27
CVE-2025-59458
8.3
Junie Multiple Products

In JetBrains Junie before 252

2025-09-17
CVE-2025-59457
7.7
TeamCity Multiple Products

In JetBrains TeamCity before 2025

2025-09-17
CVE-2025-59439
Analyzed
7.5
Samsung Mobile Processor

An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and Modem 5123

2026-02-05
CVE-2025-59434
Analyzed
9.6
Unknown Multiple Products

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated v...

2025-09-22
CVE-2025-59430
8.2
Unknown Multiple Products

Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect

2025-09-22
CVE-2025-59425
7.5
Unknown Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2025-10-07
CVE-2025-59424
7.3
LinkAce Multiple Products

LinkAce is a self-hosted archive to collect website links

2025-09-18
CVE-2025-59420
Analyzed
7.5
Unknown Multiple Products

Authlib is a Python library which builds OAuth and OpenID Connect servers

2025-09-22
CVE-2025-59409
Analyzed
7.5
Flock Multiple Products

Flock Safety Falcon and Sparrow License Plate Readers OPM1

2025-10-02
CVE-2025-59408
7.3
Flock Multiple Products

Flock Safety Bravo Edge AI Compute Device BRAVO_00

2025-09-26
CVE-2025-59407
Analyzed
9.8
Google Multiple Products

The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Re...

2025-10-02
CVE-2025-59405
7.5
Flock Multiple Products

The Flock Safety Peripheral com

2025-10-02
CVE-2025-59404
7.5
Flock Multiple Products

Flock Safety Bravo Edge AI Compute Device BRAVO_00

2025-09-26
CVE-2025-59390
Analyzed
9.8
Apache Multiple Products

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is...

2025-11-27
CVE-2025-59379
7.5
DwyerOmega Multiple Products

DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1

2026-01-07
CVE-2025-59375
Analyzed
7.5
Expat Multiple Products

libexpat in Expat before 2

2025-09-15
CVE-2025-59374
KEV
9.5
Asus Live Update

ASUS Live Update Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.

2025-12-18
CVE-2025-59363
Analyzed
7.7
Intel Multiple Products

In One Identity OneLogin before 2025

2025-09-14
CVE-2025-59362
8.2
Squid Multiple Products

Squid through 7

2025-09-26
CVE-2025-59361
Analyzed
9.8
Kubernetes Multiple Products

The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthen...

2025-09-15
CVE-2025-59360
Analyzed
9.8
Kubernetes Multiple Products

The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthen...

2025-09-15