21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 13951-14000 of 21553 CVEs Page 280 of 432
CVE-2025-65021
Analyzed
9.1
Unknown Multiple Products

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists in...

2025-11-21
CVE-2025-65018
7.1
LIBPNG Multiple Products

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files

2025-11-26
CVE-2025-65002
7.5
Fujitsu Multiple Products

Fujitsu iRMC S6 on M5 before 1

2025-11-14
CVE-2025-65001
8.2
Fujitsu Multiple Products

Fujitsu fbiosdrv

2025-11-13
CVE-2025-64989
7.2
Unknown Multiple Products

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndH...

2025-12-12
CVE-2025-64988
7.2
Unknown Multiple Products

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction...

2025-12-12
CVE-2025-64987
7.2
Unknown Multiple Products

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC ins...

2025-12-12
CVE-2025-64986
7.2
Unknown Multiple Products

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOn...

2025-12-12
CVE-2025-64983
Analyzed
8
Unknown Multiple Products

Smart Video Doorbell firmware versions prior to 2

2025-11-27
CVE-2025-6495
Analyzed
7.5
WordPress Multiple Products

The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1

2025-07-29
CVE-2025-64899
7.8
Adobe Multiple Products

Acrobat Reader versions 24

2025-12-11
CVE-2025-64785
7.8
Adobe Multiple Products

Acrobat Reader versions 24

2025-12-11
CVE-2025-64783
7.8
SDK Multiple Products

DNG SDK versions 1

2025-12-11
CVE-2025-64778
7.3
Unknown Multiple Products

NMIS/BioDose software V22

2025-12-03
CVE-2025-64775
Analyzed
7.5
Apache Multiple Products

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion

2025-12-02
CVE-2025-64772
7.8
INZONE Multiple Products

The installer of INZONE Hub 1

2025-12-02
CVE-2025-64767
Analyzed
9.1
HP Multiple Products

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal()...

2025-11-22
CVE-2025-64764
7.1
Astro Multiple Products

Astro is a web framework

2025-11-20
CVE-2025-64759
8.1
Homarr Multiple Products

Homarr is an open-source dashboard

2025-11-20
CVE-2025-64756
7.5
Glob Multiple Products

Glob matches files using patterns the shell uses

2025-11-18
CVE-2025-64741
Analyzed
8.1
Google Multiple Products

Improper authorization handling in Zoom Workplace for Android before version 6

2025-11-14
CVE-2025-64740
Analyzed
7.5
Microsoft Multiple Products

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct...

2025-11-14
CVE-2025-64729
8.1
Unknown Multiple Products

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed...

2026-01-16
CVE-2025-64720
7.1
LIBPNG Multiple Products

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files

2025-11-26
CVE-2025-64712
Analyzed
9.8
Unknown Unstructured (Library)

A path traversal vulnerability in the Unstructured library's partition_msg function allows attackers to write or overwrite arbitrary files when proces...

2026-02-05
CVE-2025-64709
Analyzed
9.6
Kubernetes Multiple Products

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook bloc...

2025-11-14
CVE-2025-64701
7.8
QND Multiple Products

QND Premium/Advance/Standard Ver

2025-12-12
CVE-2025-64695
Analyzed
7.8
Microsoft Multiple Products

Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows)

2025-11-22
CVE-2025-64693
Analyzed
9.8
Microsoft Multiple Products

Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Content-Length. Receiving a speci...

2025-11-26
CVE-2025-64691
8.8
Unknown Multiple Products

The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges...

2026-01-16
CVE-2025-64689
Analyzed
9.6
Intel Multiple Products

In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token

2025-11-11
CVE-2025-64688
7.4
YouTrack Multiple Products

In JetBrains YouTrack before 2025

2025-11-11
CVE-2025-64685
8.1
YouTrack Multiple Products

In JetBrains YouTrack before 2025

2025-11-11
CVE-2025-64680
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally

2025-12-11
CVE-2025-64679
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally

2025-12-11
CVE-2025-64678
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-12-10
CVE-2025-64677
Analyzed
8.2
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker t...

2025-12-19
CVE-2025-64676
7.2
Unknown Multiple Products

'

2025-12-20
CVE-2025-64675
Analyzed
8.3
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spo...

2025-12-19
CVE-2025-64673
7.8
Unknown Multiple Products

Improper access control in Storvsp

2025-12-10
CVE-2025-64672
8.8
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to p...

2025-12-10
CVE-2025-64671
8.4
Unknown Multiple Products

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-64669
Analyzed
7.8
Microsoft Multiple Products

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally

2025-12-12
CVE-2025-64663
Analyzed
9.9
Unknown Multiple Products

Custom Question Answering Elevation of Privilege Vulnerability

2025-12-19
CVE-2025-64661
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate...

2025-12-10
CVE-2025-64657
Analyzed
9.8
Microsoft Multiple Products

Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

2025-11-27
CVE-2025-64656
Analyzed
9.4
Unknown Multiple Products

Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

2025-11-27
CVE-2025-64655
8.8
Unknown Multiple Products

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network

2025-11-20
CVE-2025-64645
Analyzed
7.7
IBM Multiple Products

IBM Concert 1

2025-12-27
CVE-2025-64642
8
Unknown Multiple Products

NMIS/BioDose V22

2025-12-03