17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 11601-11650 of 17874 CVEs Page 233 of 358
CVE-2025-58756
8.8
MONAI Multiple Products

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging

2025-09-09
CVE-2025-58755
8.8
MONAI Multiple Products

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging

2025-09-09
CVE-2025-58754
Analyzed
7.5
HTTP Multiple Products

Axios is a promise based HTTP client for the browser and Node

2025-09-12
CVE-2025-58750
8.2
Unknown Multiple Products

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server

2025-09-09
CVE-2025-58746
Analyzed
9
Unknown Multiple Products

The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdo...

2025-09-08
CVE-2025-58745
Analyzed
9.9
HP Multiple Products

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. Th...

2025-09-08
CVE-2025-58728
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58724
7.8
Microsoft Multiple Products

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58722
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58720
7.8
Microsoft Multiple Products

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information l...

2025-10-14
CVE-2025-58718
8.8
Unknown Multiple Products

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2025-10-14
CVE-2025-58716
8.8
Microsoft Multiple Products

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58715
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58714
7.8
Microsoft Multiple Products

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58710
8.6
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation

2025-12-19
CVE-2025-58692
8.8
Fortinet Multiple Products

An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] in Fortinet FortiVoice 7

2025-11-19
CVE-2025-58690
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect allows Stored XSS

2025-09-22
CVE-2025-58688
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support allows Stored XSS

2025-09-22
CVE-2025-58687
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin allows Stored XSS

2025-09-22
CVE-2025-58686
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows...

2025-09-22
CVE-2025-58677
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews allows Stored XSS

2025-09-22
CVE-2025-58676
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER allows Stored XSS

2025-09-22
CVE-2025-58671
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auction Feed allows Stored XSS

2025-09-22
CVE-2025-58670
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection allows Stored XSS

2025-09-22
CVE-2025-58662
7.2
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object Injection

2025-09-22
CVE-2025-58657
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in EdwardBock Grid allows Stored XSS

2025-09-22
CVE-2025-58642
Analyzed
7.2
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition allows Object Injection

2025-09-04
CVE-2025-58637
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart all...

2025-09-03
CVE-2025-58628
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous allows Blind SQL Injecti...

2025-09-05
CVE-2025-58619
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection

2025-11-08
CVE-2025-58608
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuddyDev MediaPress allows PH...

2025-09-03
CVE-2025-58604
Analyzed
7.6
WPFunnels Mail Mint Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint allows SQL Injection

2025-09-03
CVE-2025-58592
8.1
Cozmoslabs Multiple Products

Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection

2025-11-08
CVE-2025-58482
7.3
Unknown Multiple Products

Improper access control in MPLocalService of MotionPhoto prior to version 4

2025-12-03
CVE-2025-58481
7.3
Unknown Multiple Products

Improper access control in MPRemoteService of MotionPhoto prior to version 4

2025-12-03
CVE-2025-58462
Analyzed
9.8
HP Multiple Products

OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacke...

2025-09-09
CVE-2025-58448
Analyzed
9.1
Unknown Multiple Products

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL I...

2025-09-09
CVE-2025-58447
Analyzed
9.8
F5 Multiple Products

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-...

2025-09-09
CVE-2025-58439
Analyzed
8.1
Intel Multiple Products

ERP is a free and open source Enterprise Resource Planning tool

2025-09-07
CVE-2025-58437
Analyzed
8.1
Intel Multiple Products

Coder allows organizations to provision remote development environments via Terraform

2025-09-07
CVE-2025-58434
Analyzed
9.8
Unknown Multiple Products

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint...

2025-09-12
CVE-2025-58429
7.5
Unknown Multiple Products

A relative path traversal vulnerability was discovered in Productivity Suite software version 4

2025-10-24
CVE-2025-58428
Analyzed
9.9
Unknown Multiple Products

The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote...

2025-10-23
CVE-2025-58423
8.8
Unknown Multiple Products

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse dir...

2025-11-06
CVE-2025-58413
Analyzed
7.5
Apple Multiple Products

A stack-based buffer overflow in Fortinet FortiOS 7

2025-11-19
CVE-2025-58411
8.8
Software Multiple Products

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creat...

2026-01-15
CVE-2025-58410
7.5
Software Multiple Products

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read...

2025-11-18
CVE-2025-58407
Analyzed
7.4
Intel Multiple Products

Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read...

2025-11-18
CVE-2025-58386
Analyzed
9.8
Unknown Multiple Products

In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks....

2025-12-04
CVE-2025-58385
7.1
WATCHDOC Multiple Products

In DOXENSE WATCHDOC before 6

2025-09-26