21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 13251-13300 of 21553 CVEs Page 266 of 432
CVE-2025-70082
Analyzed
9.8
Infor Multiple Products

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

2026-03-12
CVE-2025-7008
Analyzed
7.8
Microsoft Avast Antivirus

Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file with

2026-06-14
CVE-2025-7007
Analyzed
7.5
Microsoft Multiple Products

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the anti...

2025-12-02
CVE-2025-70069
7.5
Unknown Multiple Products

An issue in Assimp v

2026-05-05
CVE-2025-70064
8.8
HP Multiple Products

PHPGurukul Hospital Management System v4

2026-02-19
CVE-2025-70047
7.5
Cisco Multiple Products

An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3

2026-03-10
CVE-2025-70045
Analyzed
7.4
JXcore JXM

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master

2026-02-24
CVE-2025-70043
Analyzed
9.1
Ayms node-To master

The Ayms node-To master application disables TLS/SSL certificate validation by setting 'rejectUnauthorized' to false, facilitating Man-in-the-Middle (...

2026-02-24
CVE-2025-7004
Analyzed
7.8
Microsoft Avast Antivirus

Heap buffer out-of-bounds write vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial...

2026-06-14
CVE-2025-7003
Analyzed
7.8
Linux Antivirus

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-...

2026-06-14
CVE-2025-70029
7.5
Infor Multiple Products

An issue in Sunbird-Ed SunbirdEd-portal v1

2026-02-13
CVE-2025-7002
Analyzed
7.8
Linux Antivirus

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-...

2026-06-14
CVE-2025-69986
Analyzed
7.2
LSC Indoor Camera V7

A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7

2026-03-29
CVE-2025-69969
Analyzed
9.6
SRK Powertech Pvt Ltd Pebble Prism Ultra

A lack of authentication in the BLE protocol of Pebble Prism Ultra v2.9.2 allows adjacent attackers to execute arbitrary commands, intercept data, and...

2026-03-05
CVE-2025-6996
8.4
Endpoint Multiple Products

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated...

2025-07-10
CVE-2025-6995
8.4
Endpoint Multiple Products

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated...

2025-07-10
CVE-2025-6994
Analyzed
9.8
WordPress Multiple Products

The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to t...

2025-08-07
CVE-2025-6993
Analyzed
7.5
WordPress Multiple Products

The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX...

2025-07-16
CVE-2025-6991
Analyzed
7.5
WordPress Multiple Products

The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4

2025-07-28
CVE-2025-69908
Analyzed
7.5
Unknown Multiple Products

An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly acce...

2026-01-24
CVE-2025-69907
Analyzed
7.5
Unknown Multiple Products

An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/Ge...

2026-01-24
CVE-2025-69906
8.8
Files Multiple Products

Monstra CMS v3

2026-02-07
CVE-2025-6990
Analyzed
8.8
WordPress Multiple Products

The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4

2025-11-01
CVE-2025-6989
Analyzed
8.1
WordPress Multiple Products

The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in a...

2025-07-28
CVE-2025-69875
Analyzed
7.8
Total Total Security

A vulnerability exists in Quick Heal Total Security 23

2026-02-05
CVE-2025-69873
7.5
Unknown Multiple Products

ajv (Another JSON Schema Validator) through version 8

2026-02-13
CVE-2025-69871
8.1
Unknown Multiple Products

A race condition vulnerability exists in MedusaJS Medusa v2

2026-02-13
CVE-2025-6985
7.5
Unknown Multiple Products

The HTMLSectionSplitter class in langchain-text-splitters version 0

2025-10-06
CVE-2025-6984
Analyzed
7.5
Unknown Multiple Products

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML...

2025-09-04
CVE-2025-69828
Analyzed
10
Unknown Multiple Products

File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via...

2026-01-23
CVE-2025-69822
7.4
Unknown Multiple Products

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1

2026-01-24
CVE-2025-69821
7.4
Unknown Multiple Products

An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service via the BLE connection

2026-01-24
CVE-2025-69809
Analyzed
9.8
Unknown Bareiron

A write-what-where condition in p2r3 Bareiron allows unauthenticated attackers to execute arbitrary code by sending a crafted packet that writes arbit...

2026-03-17
CVE-2025-69808
Analyzed
9.1
Infor Multiple Products

An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denia...

2026-03-17
CVE-2025-69807
7.5
Unknown Multiple Products

p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause a denial of service via a pac...

2026-02-14
CVE-2025-6980
7.5
Captive Multiple Products

Captive Portal can expose sensitive information

2025-10-23
CVE-2025-6979
8.8
Captive Multiple Products

Captive Portal can allow authentication bypass

2025-10-23
CVE-2025-69784
8.8
Unknown Multiple Products

A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2

2026-03-17
CVE-2025-69783
7.8
Unknown Multiple Products

A local attacker can bypass OpenEDR's 2

2026-03-18
CVE-2025-6978
7.2
Diagnostics Multiple Products

Diagnostics command injection vulnerability

2025-10-24
CVE-2025-69770
Analyzed
10
Unknown MojoPortal CMS

MojoPortal CMS is vulnerable to a "Zip Slip" exploit in the SkinList.aspx endpoint, allowing attackers to execute arbitrary commands via a specially c...

2026-02-14
CVE-2025-69768
7.5
HP component

SQL Injection vulnerability in Chyrp v

2026-03-17
CVE-2025-69765
7.5
Tenda AX3 firmware

Tenda AX3 firmware v16

2026-03-04
CVE-2025-69764
Analyzed
9.8
Tenda Multiple Products

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffe...

2026-01-23
CVE-2025-6974
7.8
SOLIDWORKS Multiple Products

Use of Uninitialized Variable vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-6973
7.8
SOLIDWORKS Multiple Products

Use After Free vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-6972
7.8
SOLIDWORKS Multiple Products

Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-6971
7.8
SOLIDWORKS Multiple Products

Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-69700
7.5
Tenda FH1203 V2

Tenda FH1203 V2

2026-02-24
CVE-2025-6970
Analyzed
7.5
WordPress Multiple Products

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter...

2025-07-11