21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 12801-12850 of 21553 CVEs Page 257 of 432
CVE-2025-8105
Analyzed
7.3
WordPress Multiple Products

The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8

2025-08-17
CVE-2025-8099
7.5
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10

2026-02-13
CVE-2025-8098
Analyzed
7.8
Unknown Multiple Products

An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges

2025-08-19
CVE-2025-8092
7.6
Drupal Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-S...

2025-08-15
CVE-2025-8088
KEV
9.5
RARLAB WinRAR

RARLAB WinRAR Path Traversal Vulnerability - Active in CISA KEV catalog.

2025-08-12
CVE-2025-8085
Analyzed
8.6
WordPress Multiple Products

The Ditty WordPress plugin before 3

2025-09-08
CVE-2025-8083
8.6
Preset Multiple Products

The Preset configuration https://v2

2025-12-13
CVE-2025-8078
7.2
Zyxel Multiple Products

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4

2025-10-21
CVE-2025-8077
Analyzed
9.8
Unknown Multiple Products

A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin`...

2025-09-17
CVE-2025-8076
7.2
Supermicro BMC Multiple Products

There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F

2025-11-19
CVE-2025-8069
Analyzed
7.8
Microsoft Multiple Products

During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ss...

2025-07-23
CVE-2025-8067
Analyzed
8.5
Unknown Multiple Products

A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system

2025-08-28
CVE-2025-8061
7
Lenovo Multiple Products

A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3

2025-09-12
CVE-2025-8060
8.8
Tenda Multiple Products

A vulnerability has been found in Tenda AC23 16

2025-07-23
CVE-2025-8059
Analyzed
9.8
WordPress Multiple Products

The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_reg...

2025-08-12
CVE-2025-8047
Analyzed
9.8
WordPress Multiple Products

The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which...

2025-08-14
CVE-2025-8044
Analyzed
9.8
Unknown Multiple Products

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough...

2025-07-24
CVE-2025-8043
Analyzed
9.8
Unknown Multiple Products

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability affects Firefox < 141 and Thunderbird < 141.

2025-07-24
CVE-2025-8042
Analyzed
9.8
Google Multiple Products

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.

2025-08-20
CVE-2025-8040
Analyzed
8.8
Mozilla Multiple Products

Memory safety bugs present in Firefox ESR 140

2025-07-23
CVE-2025-8039
8.1
Unknown Multiple Products

In some cases search terms persisted in the URL bar even after navigating away from the search page

2025-07-23
CVE-2025-8038
Analyzed
9.8
Unknown Multiple Products

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunder...

2025-07-24
CVE-2025-8037
Analyzed
9.1
Unknown Multiple Products

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cook...

2025-07-24
CVE-2025-8036
8.1
Thunderbird Multiple Products

Thunderbird cached CORS preflight responses across IP address changes

2025-07-23
CVE-2025-8035
Analyzed
8.8
Mozilla Multiple Products

Memory safety bugs present in Firefox ESR 128

2025-07-23
CVE-2025-8034
Analyzed
8.8
Mozilla Multiple Products

Memory safety bugs present in Firefox ESR 115

2025-07-23
CVE-2025-8032
8.1
XSLT Multiple Products

XSLT document loading did not correctly propagate the source document which bypassed its CSP

2025-07-23
CVE-2025-8031
Analyzed
9.8
Unknown Multiple Products

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulne...

2025-07-24
CVE-2025-8030
8.1
Insufficient Multiple Products

Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code

2025-07-23
CVE-2025-8029
8.1
Thunderbird Multiple Products

Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags

2025-07-23
CVE-2025-8028
Analyzed
9.8
On Multiple Products

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorr...

2025-07-24
CVE-2025-8025
Analyzed
9.8
Dinosoft Business Dinosoft ERP

Dinosoft ERP contains a critical vulnerability due to missing authentication and improper access control, allowing unauthenticated attackers to access...

2026-02-12
CVE-2025-8022
8.8
All Multiple Products

All versions of the package bun are vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the $...

2025-07-23
CVE-2025-8021
7.5
All Multiple Products

All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files...

2025-07-23
CVE-2025-8020
8.2
All Multiple Products

All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that resol...

2025-07-23
CVE-2025-8019
8.8
Unknown Multiple Products

A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2

2025-07-23
CVE-2025-8017
8.8
Tenda Multiple Products

A vulnerability was found in Tenda AC7 15

2025-07-23
CVE-2025-8014
Analyzed
7.5
GitLab Multiple Products

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11

2025-09-28
CVE-2025-8011
8.8
Google Multiple Products

Type Confusion in V8 in Google Chrome prior to 138

2025-07-23
CVE-2025-8010
8.8
Google Multiple Products

Type Confusion in V8 in Google Chrome prior to 138

2025-07-23
CVE-2025-8006
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

2025-09-17
CVE-2025-8005
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability

2025-09-17
CVE-2025-8004
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

2025-09-17
CVE-2025-8003
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

2025-09-17
CVE-2025-8002
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability

2025-09-17
CVE-2025-8001
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt CO File Parsing Memory Corruption Remote Code Execution Vulnerability

2025-09-17
CVE-2025-8000
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt LI File Parsing Type Confusion Remote Code Execution Vulnerability

2025-09-17
CVE-2025-7999
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution Vulnerability

2025-09-17
CVE-2025-7998
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

2025-09-17
CVE-2025-7997
7.8
Unknown Multiple Products

Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

2025-09-17