17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 12001-12050 of 17874 CVEs Page 241 of 358
CVE-2025-55498
7.5
Tenda Multiple Products

Tenda AC6 V15

2025-08-20
CVE-2025-55483
7.5
Tenda Multiple Products

Tenda AC6 V15

2025-08-20
CVE-2025-55482
7.5
Tenda Multiple Products

Tenda AC6 V15

2025-08-20
CVE-2025-55444
Analyzed
9.8
HP Multiple Products

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote att...

2025-08-21
CVE-2025-55443
Analyzed
9.1
Google Multiple Products

Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in pl...

2025-08-27
CVE-2025-55422
8.8
FoxCMS Multiple Products

In FoxCMS 1

2025-08-27
CVE-2025-55420
8.8
Reflected Multiple Products

A Reflected Cross Site Scripting (XSS) vulnerability was found in /index

2025-08-21
CVE-2025-55409
8.8
FoxCMS Multiple Products

FoxCMS 1

2025-08-25
CVE-2025-55383
8.6
Moss Multiple Products

Moss before v0

2025-08-21
CVE-2025-55370
8.8
Unknown Multiple Products

Incorrect access control in the component \controller\ResourceController

2025-08-21
CVE-2025-55368
8.8
Unknown Multiple Products

Incorrect access control in the component \controller\RoleController

2025-08-21
CVE-2025-55346
Analyzed
9.8
Unknown Multiple Products

User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS...

2025-08-14
CVE-2025-55345
Analyzed
8.8
Using Multiple Products

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remot...

2025-08-13
CVE-2025-55339
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-55328
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevat...

2025-10-14
CVE-2025-55322
7.3
GitHub Multiple Products

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network

2025-09-24
CVE-2025-55321
Analyzed
8.7
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an authorized attacker to perform spoofin...

2025-10-09
CVE-2025-55319
8.8
Unknown Multiple Products

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network

2025-09-12
CVE-2025-55317
7.8
Microsoft Multiple Products

Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges local...

2025-09-09
CVE-2025-55316
7.8
Microsoft Multiple Products

External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-55315
Analyzed
9.9
Unknown Multiple Products

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security fe...

2025-10-14
CVE-2025-55314
Analyzed
7.8
Apple Multiple Products

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13

2025-12-12
CVE-2025-55313
Analyzed
7.8
Apple Multiple Products

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13

2025-12-12
CVE-2025-55312
Analyzed
7.8
Microsoft Multiple Products

An issue was discovered in Foxit PDF and Editor for Windows before 13

2025-12-12
CVE-2025-55310
Analyzed
7.3
Apple Multiple Products

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13

2025-12-12
CVE-2025-55306
Analyzed
9.8
Unknown Multiple Products

GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and a...

2025-08-19
CVE-2025-55299
Analyzed
9.4
Unknown Multiple Products

VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty...

2025-08-19
CVE-2025-55298
7.5
ImageMagick Multiple Products

ImageMagick is free and open-source software used for editing and manipulating digital images

2025-08-26
CVE-2025-55294
Analyzed
9.8
Unknown Multiple Products

screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is...

2025-08-19
CVE-2025-55293
Analyzed
9.4
Unknown Multiple Products

Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it...

2025-08-19
CVE-2025-55292
8.2
Meshtastic Multiple Products

Meshtastic is an open source mesh networking solution

2026-01-28
CVE-2025-55291
7.1
Unknown Multiple Products

Shaarli is a minimalist bookmark manager and link sharing service

2025-08-19
CVE-2025-55289
8.8
Chamilo Multiple Products

Chamilo is a learning management system

2026-03-06
CVE-2025-55287
Analyzed
8
HP Multiple Products

Genealogy is a family tree PHP application

2025-08-19
CVE-2025-55283
Analyzed
9.1
Unknown Multiple Products

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superuser...

2025-08-19
CVE-2025-55282
Analyzed
9.1
Intel Multiple Products

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to s...

2025-08-19
CVE-2025-55278
Analyzed
8.1
Intel Multiple Products

Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation...

2025-11-06
CVE-2025-55262
8.3
Infor Multiple Products

HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the databa...

2026-03-27
CVE-2025-55261
8.1
Unknown Multiple Products

HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the...

2026-03-28
CVE-2025-55245
7.8
Unknown Multiple Products

Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-55244
Analyzed
9
Microsoft Multiple Products

Azure Bot Service Elevation of Privilege Vulnerability

2025-09-05
CVE-2025-55241
Analyzed
9
Microsoft Multiple Products

Azure Entra Elevation of Privilege Vulnerability

2025-09-05
CVE-2025-55238
7.5
Dynamics Multiple Products

Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

2025-09-05
CVE-2025-55234
8.8
SMB Multiple Products

SMB Server might be susceptible to relay attacks depending on the configuration

2025-09-09
CVE-2025-55233
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-55232
Analyzed
9.8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.

2025-09-09
CVE-2025-55231
Analyzed
7.5
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to exec...

2025-08-21
CVE-2025-55230
Analyzed
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally

2025-08-21
CVE-2025-55228
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to...

2025-09-09
CVE-2025-55227
8.8
Unknown Multiple Products

Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-09-09