18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 13051-13100 of 18466 CVEs Page 262 of 370
CVE-2025-53734
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53733
8.4
Microsoft Multiple Products

Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53732
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53731
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53730
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53729
7.8
Microsoft Multiple Products

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53727
8.8
Unknown Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12
CVE-2025-53726
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53725
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53724
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53723
7.8
Microsoft Multiple Products

Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53720
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-53710
7.5
Unknown Multiple Products

Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each othe...

2025-12-20
CVE-2025-53705
Analyzed
7.8
Intel Multiple Products

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12

2025-08-19
CVE-2025-53704
7.5
Unknown Multiple Products

The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account

2025-12-05
CVE-2025-53703
7.5
DuraComm Multiple Products

DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers

2025-07-23
CVE-2025-53694
Analyzed
7.5
Experience Multiple Products

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (X...

2025-09-03
CVE-2025-53693
Analyzed
9.8
Unknown Multiple Products

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecor...

2025-09-03
CVE-2025-53692
Analyzed
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM)...

2025-09-22
CVE-2025-53691
Analyzed
8.8
Intel Multiple Products

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (R...

2025-09-03
CVE-2025-53690
KEV Analyzed
9
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issu...

2025-09-03
CVE-2025-53689
Analyzed
8.8
Apache Multiple Products

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2

2025-07-14
CVE-2025-53652
Analyzed
8.2
Jenkins Multiple Products

Jenkins Git Parameter Plugin 439

2025-07-10
CVE-2025-53650
Analyzed
7.3
Jenkins Multiple Products

Jenkins Credentials Binding Plugin 687

2025-07-11
CVE-2025-53645
7.5
Zimbra Multiple Products

Zimbra Collaboration Suite (ZCS) before 9

2025-07-11
CVE-2025-53629
7.5
Unknown Multiple Products

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library

2025-07-11
CVE-2025-53624
Analyzed
10
GitHub Multiple Products

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists ver...

2025-07-10
CVE-2025-53619
7.4
Grassroot Multiple Products

An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3

2025-12-17
CVE-2025-53618
7.4
Grassroot Multiple Products

An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3

2025-12-17
CVE-2025-53606
Analyzed
9.8
Apache Multiple Products

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomme...

2025-08-08
CVE-2025-53603
7.5
Unknown Multiple Products

In Alinto SOPE SOGo 2

2025-07-06
CVE-2025-53599
Analyzed
9.8
Apple Multiple Products

Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.

2025-07-08
CVE-2025-53588
Analyzed
7.7
Dmitry Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V

2025-08-28
CVE-2025-53587
8.8
ApusTheme Findgo Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo allows Cross Site Request Forgery

2025-08-14
CVE-2025-53585
7.1
NooTheme WeMusic Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme WeMusic noo-wemusic allows Reflected XS...

2025-11-08
CVE-2025-53584
Analyzed
8.1
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System allows Object Injection

2025-08-28
CVE-2025-53583
Analyzed
8.1
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight allows Object Injection

2025-08-28
CVE-2025-53580
Analyzed
9.8
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Busi...

2025-08-20
CVE-2025-53579
Analyzed
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captcha

2025-08-28
CVE-2025-53578
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso allows PHP Local...

2025-08-28
CVE-2025-53577
Analyzed
10
HP Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS allows Remote Code Inclusion. This issue affects Global DN...

2025-08-20
CVE-2025-53576
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ovatheme Events allo...

2025-08-28
CVE-2025-53573
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme Epic Review epic-review allows Reflecte...

2025-11-08
CVE-2025-53572
Analyzed
8.1
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact allows Object Injection

2025-08-28
CVE-2025-53567
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Ghost Kit allows PHP Local...

2025-08-20
CVE-2025-53565
Analyzed
8.1
Google Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Widget for Google...

2025-08-20
CVE-2025-53560
8.8
Deserialization Multiple Products

Deserialization of Untrusted Data vulnerability in rascals Noisa allows Object Injection

2025-08-20
CVE-2025-53559
7.1
LambertGroup Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for...

2025-08-20
CVE-2025-53558
8.8
ZTE Multiple Products

ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K

2025-07-31
CVE-2025-53557
Analyzed
9.8
Intel Multiple Products

A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa)...

2025-08-25