17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 12351-12400 of 17874 CVEs Page 248 of 358
CVE-2025-54244
7.8
Viewer Multiple Products

Substance3D - Viewer versions 0

2025-09-09
CVE-2025-54243
7.8
Viewer Multiple Products

Substance3D - Viewer versions 0

2025-09-09
CVE-2025-54242
7.8
Pro Multiple Products

Premiere Pro versions 25

2025-09-09
CVE-2025-54236
KEV Analyzed
9.1
Adobe Multiple Products

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vul...

2025-09-09
CVE-2025-54160
7.8
Synology Multiple Products

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1

2025-12-05
CVE-2025-54159
7.5
Synology Multiple Products

Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1

2025-12-05
CVE-2025-54158
7.8
Synology Multiple Products

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1

2025-12-05
CVE-2025-54156
7.4
PACS Multiple Products

The Sante PACS Server Web Portal sends credential information without encryption

2025-08-19
CVE-2025-54145
Analyzed
9.1
Apple Multiple Products

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL...

2025-08-20
CVE-2025-54143
Analyzed
9.8
Apple Multiple Products

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page...

2025-08-20
CVE-2025-54141
7.5
ViewVC Multiple Products

ViewVC is a browser interface for CVS and Subversion version control repositories

2025-07-23
CVE-2025-54140
7.5
Download Multiple Products

pyLoad is a free and open-source Download Manager written in pure Python

2025-07-23
CVE-2025-54138
Analyzed
7.5
HP Multiple Products

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating syst...

2025-07-23
CVE-2025-54137
7.3
HAX Multiple Products

HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend

2025-07-23
CVE-2025-54136
7.2
Unknown Multiple Products

Cursor is a code editor built for programming with AI

2025-08-04
CVE-2025-54135
8.5
Cursor Multiple Products

Cursor is a code editor built for programming with AI

2025-08-05
CVE-2025-54130
7.5
Cursor Multiple Products

Cursor is a code editor built for programming with AI

2025-08-05
CVE-2025-54123
Analyzed
9.8
Unknown Multiple Products

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command inject...

2025-09-10
CVE-2025-54122
Analyzed
10
Unknown Multiple Products

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified i...

2025-07-22
CVE-2025-54119
Analyzed
10
HP Multiple Products

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper...

2025-08-05
CVE-2025-54117
Analyzed
9
Unknown Multiple Products

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2...

2025-08-19
CVE-2025-54113
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-09-09
CVE-2025-54111
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54110
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54106
Analyzed
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-09-09
CVE-2025-54102
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54100
7.8
Microsoft Multiple Products

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute c...

2025-12-10
CVE-2025-54098
7.8
Microsoft Multiple Products

Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54092
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevat...

2025-09-09
CVE-2025-54091
7.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54072
7.5
Unknown Multiple Products

yt-dlp is a feature-rich command-line audio/video downloader

2025-07-23
CVE-2025-54068
KEV
9.5
Laravel Livewire

Laravel Livewire Code Injection Vulnerability - Active in CISA KEV catalog.

2026-03-21
CVE-2025-54065
7.9
Doom Multiple Products

GZDoom is a feature centric port for all Doom engine games

2025-12-03
CVE-2025-54063
8
Unknown Multiple Products

Cherry Studio is a desktop client that supports for multiple LLM providers

2025-08-11
CVE-2025-54052
7.5
HP Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin allows PHP Local File Inclusion

2025-08-20
CVE-2025-54049
Analyzed
9.9
WordPress Multiple Products

Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP allows Privilege Escalation. This issue affects Custom API for WP: from n...

2025-08-20
CVE-2025-54048
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP allows SQL Injectio...

2025-08-20
CVE-2025-54043
7.6
YayCommerce SMTP Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for Amazon SES allows SQL Injec...

2025-07-16
CVE-2025-54034
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Tribulant Software Newsletter...

2025-08-20
CVE-2025-54031
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board allows...

2025-08-20
CVE-2025-54029
Analyzed
7.7
Unknown Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce csv import export allows Path Tr...

2025-08-28
CVE-2025-54028
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Saleswonder Team Tobias CF7 W...

2025-08-20
CVE-2025-54026
8.5
QuanticaLabs GymBase Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBase Theme Classes allows SQL In...

2025-07-16
CVE-2025-54021
7.5
Mitchell Bennis Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List allows Path Traversal

2025-08-20
CVE-2025-54017
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscr...

2025-08-20
CVE-2025-54014
Analyzed
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic allows Object Injection. This issue affects MediCen...

2025-08-20
CVE-2025-54012
7.2
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in nanbu Welcart e-Commerce allows Object Injection

2025-08-20
CVE-2025-54010
Analyzed
9.6
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets allows Cross Site Request Forgery. This issue affects FluentSnippets...

2025-07-16
CVE-2025-54007
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Object Injection

2025-08-20
CVE-2025-54001
Analyzed
9.8
ThemeREX Classter Multiple Products

Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <=...

2026-03-06