17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 13751-13800 of 17874 CVEs Page 276 of 358
CVE-2025-41074
7.5
LimeSurvey Multiple Products

Vulnerability in LimeSurvey 6

2025-11-22
CVE-2025-41068
7.5
Reachable Assertion Multiple Products

Reachable Assertion vulnerability in Open5GS up to version 2

2025-10-28
CVE-2025-41067
7.5
Reachable Assertion Multiple Products

Reachable Assertion vulnerability in Open5GS up to version 2

2025-10-28
CVE-2025-41034
Analyzed
9.8
Unknown Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41033
Analyzed
9.8
Intel Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41032
Analyzed
9.8
Intel Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41015
7.5
Unknown Multiple Products

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304

2025-12-03
CVE-2025-41014
7.5
Unknown Multiple Products

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304

2025-12-03
CVE-2025-41013
Analyzed
9.8
Unknown Multiple Products

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databa...

2025-12-04
CVE-2025-40949
Analyzed
9.1
Unknown Multiple Products

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX R...

2026-05-13
CVE-2025-40946
Analyzed
8.3
SUSE them to

A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6

2026-05-13
CVE-2025-40943
Analyzed
9.6
Unknown Multiple Products

Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering a legitimate...

2026-03-11
CVE-2025-40942
8.8
TeleControl Multiple Products

A vulnerability has been identified in TeleControl Server Basic (All versions < V3

2026-01-14
CVE-2025-40938
8.1
SIMATIC Multiple Products

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4

2025-12-10
CVE-2025-40937
8.3
SIMATIC Multiple Products

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4

2025-12-10
CVE-2025-40936
7.8
Unknown Multiple Products

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29

2025-11-18
CVE-2025-40933
7.5
Apache Multiple Products

Apache::AuthAny::Cookie v0

2025-09-17
CVE-2025-40932
8.2
Apache Multiple Products

Apache::SessionX versions through 2

2026-02-28
CVE-2025-40930
Analyzed
7.5
Unknown Multiple Products

JSON::SIMD before version 1

2025-09-08
CVE-2025-40928
Analyzed
7.5
Unknown Multiple Products

JSON::XS before version 4

2025-09-08
CVE-2025-40927
Analyzed
7.3
Unknown Multiple Products

CGI::Simple versions before 1

2025-08-29
CVE-2025-40926
Analyzed
9.8
Perl (CPAN) Plack::Middleware::Session::Simple

Plack::Middleware::Session::Simple for Perl generates session IDs insecurely using predictable seeds. This allows attackers to guess session IDs and h...

2026-03-06
CVE-2025-40923
7.3
Unknown Multiple Products

Plack-Middleware-Session before version 0

2025-07-16
CVE-2025-40920
8.6
HTTP Multiple Products

Catalyst::Authentication::Credential::HTTP versions 1

2025-08-11
CVE-2025-40899
8.9
Infor Multiple Products

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter

2026-04-16
CVE-2025-40898
8.1
Unknown Multiple Products

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file

2025-12-20
CVE-2025-40897
Analyzed
8.1
Intel Multiple Products

An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforc...

2026-04-16
CVE-2025-40892
8.9
Stored Multiple Products

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter

2025-12-19
CVE-2025-40890
7.9
Stored Multiple Products

A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter

2025-11-26
CVE-2025-40889
8.1
Unknown Multiple Products

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters

2025-10-07
CVE-2025-40886
7.5
Unknown Multiple Products

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter

2025-10-07
CVE-2025-40829
7.8
Unknown Multiple Products

A vulnerability has been identified in Simcenter Femap (All versions < V2512)

2025-12-13
CVE-2025-40827
7.8
Unknown Multiple Products

A vulnerability has been identified in Siemens Software Center (All versions < V3

2025-11-13
CVE-2025-40820
7.5
Unknown Multiple Products

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range

2025-12-11
CVE-2025-40816
7.6
Unknown Multiple Products

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO!...

2025-11-13
CVE-2025-40812
7.8
Unknown Multiple Products

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224

2025-10-14
CVE-2025-40811
7.8
Unknown Multiple Products

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224

2025-10-14
CVE-2025-40810
7.8
Unknown Multiple Products

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224

2025-10-14
CVE-2025-40809
7.8
Unknown Multiple Products

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224

2025-10-14
CVE-2025-40805
Analyzed
10
Unknown Multiple Products

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to ci...

2026-01-14
CVE-2025-40804
Analyzed
9.1
Unknown Multiple Products

A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share w...

2025-09-09
CVE-2025-40801
8.1
Unknown Multiple Products

A vulnerability has been identified in COMOS V10

2025-12-10
CVE-2025-40798
7.5
Unknown Multiple Products

A vulnerability has been identified in SIMATIC PCS neo V4

2025-09-09
CVE-2025-40797
7.5
Unknown Multiple Products

A vulnerability has been identified in SIMATIC PCS neo V4

2025-09-09
CVE-2025-40796
7.5
Unknown Multiple Products

A vulnerability has been identified in SIMATIC PCS neo V4

2025-09-09
CVE-2025-40795
Analyzed
9.8
Unknown Multiple Products

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), User Management Component (UMC) (All...

2025-09-09
CVE-2025-40780
8.6
Unknown Multiple Products

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the...

2025-10-22
CVE-2025-40779
7.5
Unknown Multiple Products

If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process wil...

2025-08-27
CVE-2025-40778
8.6
Under Multiple Products

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache

2025-10-22
CVE-2025-40777
7.5
Unknown Multiple Products

If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable val...

2025-07-16