21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 13151-13200 of 21553 CVEs Page 264 of 432
CVE-2025-71278
8.8
XenForo Multiple Products

XenForo before 2

2026-04-01
CVE-2025-71275
Analyzed
9.8
Zimbra Collaboration Multiple Products

Zimbra Collaboration Suite (ZCS) PostJournal service version 8.8.15 contains a command injection vulnerability that allows unauthenticated attackers t...

2026-03-25
CVE-2025-71263
7.4
Unknown Edition

In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 byte...

2026-03-15
CVE-2025-71261
Analyzed
8.6
SUSE Harvester

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1

2026-06-17
CVE-2025-71260
8.8
ITSM Multiple Products

BMC FootPrints ITSM versions 20

2026-03-20
CVE-2025-71257
7.3
ITSM Multiple Products

BMC FootPrints ITSM versions 20

2026-03-20
CVE-2025-71256
Analyzed
7.5
Unknown Multiple Products

In nr modem, there is a possible improper input validation

2026-05-06
CVE-2025-71255
Analyzed
7.5
Unknown Multiple Products

In Modem IMS, there is a possible improper input validation

2026-05-06
CVE-2025-71254
Analyzed
7.5
Unknown Multiple Products

In Modem IMS, there is a possible improper input validation

2026-05-06
CVE-2025-71253
Analyzed
7.5
Unknown Multiple Products

In Modem IMS, there is a possible improper input validation

2026-05-06
CVE-2025-71252
Analyzed
7.5
Unknown Modem IMS

In Modem IMS, there is a possible improper input validation

2026-05-06
CVE-2025-71251
Analyzed
7.5
Unknown IMS (IP Multimedia Subsystem)

In IMS, there is a possible system crash due to improper input validation

2026-05-06
CVE-2025-71243
Analyzed
9.8
HP Saisies pour formulaire (Saisies) plugin

The 'Saisies' plugin for SPIP contains a critical Remote Code Execution (RCE) vulnerability that allows attackers to run arbitrary code on the host se...

2026-02-20
CVE-2025-71217
Analyzed
7.8
Trend Micro Apex One

An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate pr...

2026-05-22
CVE-2025-71216
Analyzed
7.8
Trend Micro Apex One

A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges...

2026-05-22
CVE-2025-71215
Analyzed
7
Trend Micro Apex One

A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to...

2026-05-23
CVE-2025-71214
Analyzed
7.8
Trend Micro Apex One

An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on...

2026-05-22
CVE-2025-71213
Analyzed
7.8
Trend Micro Apex One

An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2025-71212
Analyzed
7.8
Trend Micro Apex One

A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2025-71211
Analyzed
9.8
Trend Micro Apex One Management Console

A secondary vulnerability in the Trend Micro Apex One management console allows remote attackers to upload malicious code and execute commands.

2026-05-22
CVE-2025-71210
Analyzed
9.8
Trend Micro Apex One Management Console

A vulnerability in the Trend Micro Apex One management console allows remote attackers to upload malicious code and execute commands on affected syste...

2026-05-22
CVE-2025-71063
Analyzed
8.2
Errands Multiple Products

Errands before 46

2026-01-13
CVE-2025-71057
8.2
D-Link Wireless

Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1

2026-02-27
CVE-2025-71031
7.5
Melon Multiple Products

Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service

2026-02-06
CVE-2025-71021
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-16
CVE-2025-71019
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-16
CVE-2025-71007
7.5
Unknown Multiple Products

An input validation vulnerability in the oneflow

2026-01-30
CVE-2025-71003
7.5
Unknown Multiple Products

An input validation vulnerability in the flow

2026-01-30
CVE-2025-71000
7.5
Unknown Multiple Products

An issue in the flow

2026-01-30
CVE-2025-70999
7.5
GPU Multiple Products

A GPU device-ID validation flaw in the flow

2026-01-30
CVE-2025-70998
Analyzed
9.8
UTT HiPER 810 / nv810v4 router firmware

Insecure default credentials in the Telnet service of UTT HiPER routers allow remote attackers to gain root access via automated scripts.

2026-02-19
CVE-2025-70995
8.8
ASDK Multiple Products

An issue in Aranda Service Desk Web Edition (ASDK API 8

2026-03-07
CVE-2025-70994
7.3
Signal forgery after

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system

2026-04-24
CVE-2025-70986
7.5
Unknown Multiple Products

Incorrect access control in the selectDept function of RuoYi v4

2026-01-24
CVE-2025-70985
Analyzed
9.1
Unknown Multiple Products

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

2026-01-24
CVE-2025-70983
Analyzed
9.9
Unknown Multiple Products

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

2026-01-24
CVE-2025-70982
Analyzed
9.9
Intel Multiple Products

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive u...

2026-01-27
CVE-2025-70981
Analyzed
9.8
CordysCRM CordysCRM

CordysCRM 1.4.1 contains an SQL Injection vulnerability in the employee list query interface (/user/list) via the 'departmentIds' parameter.

2026-02-13
CVE-2025-70974
Analyzed
10
Fastjson before Multiple Products

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, th...

2026-01-09
CVE-2025-70968
Analyzed
9.8
FreeImage Multiple Products

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().

2026-01-15
CVE-2025-70963
7.6
Gophish Multiple Products

Gophish <=0

2026-02-07
CVE-2025-70950
Analyzed
7.3
Unknown Multiple Products

An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request

2026-05-20
CVE-2025-70949
7.5
Infor Multiple Products

An observable timing discrepancy in @perfood/couch-auth v0

2026-03-07
CVE-2025-70893
Analyzed
8.8
HP Multiple Products

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1

2026-01-16
CVE-2025-70892
Analyzed
9.8
HP Multiple Products

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly v...

2026-01-16
CVE-2025-70886
7.5
Unknown Multiple Products

An issue in halo v

2026-02-14
CVE-2025-70841
Analyzed
10
Apache Multi-Tenancy Based eCommerce Platform SaaS

Dokans SaaS platform allows unauthenticated attackers to download the `.env` file, exposing encryption keys, database credentials, and API keys, leadi...

2026-02-04
CVE-2025-70830
Analyzed
9.9
Unknown Datart (using Freemarker engine)

Datart v1.0.0-rc.3 is vulnerable to Server-Side Template Injection (SSTI) in its Freemarker engine, allowing authenticated attackers to execute arbitr...

2026-02-18
CVE-2025-70828
8.8
Unknown Multiple Products

An issue in Datart v1

2026-02-18
CVE-2025-7077
8.8
Unknown Multiple Products

A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2

2025-07-06