21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 13851-13900 of 21553 CVEs Page 278 of 432
CVE-2025-65878
7.5
Unknown Multiple Products

The warehouse management system version 1

2025-12-06
CVE-2025-65875
Analyzed
8.8
HP file

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1

2026-02-04
CVE-2025-65865
7.5
Unknown Multiple Products

An integer overflow in eProsima Fast-DDS v3

2025-12-24
CVE-2025-65857
7.5
Unknown Multiple Products

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5

2025-12-23
CVE-2025-65856
Analyzed
9.8
Unknown Multiple Products

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remo...

2025-12-23
CVE-2025-65854
Analyzed
9.8
Unknown Multiple Products

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeov...

2025-12-13
CVE-2025-6585
8.1
WordPress Multiple Products

The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7

2025-07-23
CVE-2025-65844
7.5
EverShop Multiple Products

EverShop 2

2025-12-03
CVE-2025-65843
7.7
Aquarius Multiple Products

Aquarius Desktop 3

2025-12-03
CVE-2025-65831
7.5
Unknown Multiple Products

The application uses an insecure hashing algorithm (MD5) to hash passwords

2025-12-12
CVE-2025-65824
8.8
Unknown Multiple Products

An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Lo...

2025-12-12
CVE-2025-65821
Analyzed
7.5
Intel Multiple Products

As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sens...

2025-12-12
CVE-2025-65817
Analyzed
8.8
LSC Multiple Products

LSC Smart Connect Indoor IP Camera 1

2025-12-23
CVE-2025-65807
Analyzed
9.8
Unknown Multiple Products

An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.

2025-12-11
CVE-2025-65805
7.5
OpenAirInterface Multiple Products

OpenAirInterface CN5G AMF<=v2

2026-01-08
CVE-2025-65795
Analyzed
7.5
Unknown Multiple Products

Incorrect access control in the /api/v1/user endpoint of usememos memos v0

2025-12-09
CVE-2025-65791
Analyzed
9.8
HP ZoneMinder

ZoneMinder is vulnerable to remote command injection because user-supplied input is passed unsanitized to the exec() function in the image.php view.

2026-02-19
CVE-2025-65781
8.2
Unknown Multiple Products

An issue was discovered in Wekan The Open Source kanban board system up to version 18

2025-12-17
CVE-2025-65778
8.1
Unknown Multiple Products

An issue was discovered in Wekan The Open Source kanban board system up to version 18

2025-12-17
CVE-2025-6577
Analyzed
9.8
Unknown Multiple Products

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E...

2026-05-13
CVE-2025-65753
Analyzed
9
Guardian Gryphon

A flaw in the TLS certification mechanism of Guardian Gryphon allows remote attackers to execute arbitrary commands with root-level privileges.

2026-02-18
CVE-2025-65742
8.2
Newgen OmniDocs Multiple Products

An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11

2025-12-16
CVE-2025-6574
Analyzed
8.8
WordPress Multiple Products

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6

2025-11-01
CVE-2025-65720
Analyzed
9.8
GPT Researcher GPT Researcher

GPT Researcher v3.3.7 is vulnerable to remote code execution when an unauthenticated user interacts with a crafted HTML page to supply a malicious Mod...

2026-07-20
CVE-2025-65716
8.8
Unknown Multiple Products

An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0

2026-02-18
CVE-2025-65656
Analyzed
9.8
HP Multiple Products

dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

2025-12-04
CVE-2025-65637
7.5
GitHub Multiple Products

A denial-of-service vulnerability exists in github

2025-12-06
CVE-2025-65594
8.1
OpenSIS Multiple Products

OpenSIS 9

2025-12-11
CVE-2025-65593
8.8
Unknown Multiple Products

nopCommerce 4

2025-12-18
CVE-2025-6558
KEV Analyzed
8.8
Google Multiple Products

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138

2025-07-15
CVE-2025-65568
7.5
Unknown Multiple Products

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2

2025-12-20
CVE-2025-65567
7.5
Unknown Multiple Products

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2

2025-12-20
CVE-2025-65566
7.5
Unknown Multiple Products

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2

2025-12-20
CVE-2025-65565
7.5
Unknown Multiple Products

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2

2025-12-20
CVE-2025-65564
7.5
Unknown Multiple Products

A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2

2025-12-20
CVE-2025-65563
7.5
Unknown Multiple Products

A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2

2025-12-20
CVE-2025-65562
7.5
Unknown Multiple Products

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests

2025-12-20
CVE-2025-65561
7.5
Unknown Multiple Products

An issue was discovered in function LocalNode

2025-12-20
CVE-2025-65559
7.5
Unknown Multiple Products

An issue was discovered in Open5GS 2

2025-12-20
CVE-2025-6554
KEV Analyzed
8.1
Google Multiple Products

Type confusion in V8 in Google Chrome prior to 138

2025-07-05
CVE-2025-65530
Analyzed
8.8
Linux Multiple Products

An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32

2025-12-13
CVE-2025-6553
Analyzed
9.8
WordPress Multiple Products

The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout()...

2025-10-12
CVE-2025-65518
7.5
Obsidian Multiple Products

Plesk Obsidian versions 8

2026-01-09
CVE-2025-65512
7.5
Unknown Multiple Products

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0

2025-12-12
CVE-2025-65503
Analyzed
7.5
Unknown Multiple Products

Use after free in endpoint destructors in Redboltz async_mqtt 10

2025-11-25
CVE-2025-65495
Analyzed
7.5
Integer Multiple Products

Integer signedness error in tls_verify_call_back() in src/coap_openssl

2025-11-25
CVE-2025-65494
Analyzed
7.5
Unknown Multiple Products

NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl

2025-11-25
CVE-2025-65493
Analyzed
7.5
Unknown Multiple Products

NULL pointer dereference in src/coap_openssl

2025-11-25
CVE-2025-65480
8.8
Unison Multiple Products

An issue was discovered in Pacom Unison Client 5

2026-02-13
CVE-2025-65473
Analyzed
9.1
HP Multiple Products

An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privil...

2025-12-12