18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 14301-14350 of 18466 CVEs Page 287 of 370
CVE-2025-41660
8.8
Unknown Multiple Products

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code executi...

2026-03-24
CVE-2025-41659
Analyzed
8.3
Unknown Multiple Products

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys

2025-08-05
CVE-2025-41656
Analyzed
10
Pilz GmbH & Co. KG IndustrialPI 4 with Firmware Bullseye

An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED...

2025-07-06
CVE-2025-41648
Analyzed
9.8
Unknown Multiple Products

An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all ava...

2025-07-06
CVE-2025-41459
7.8
Studio Multiple Products

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5

2025-07-22
CVE-2025-41430
7.5
Unknown Multiple Products

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate

2025-10-16
CVE-2025-41425
8.1
DuraComm Multiple Products

DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack

2025-07-23
CVE-2025-41420
Analyzed
9.6
Unknown Multiple Products

A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954f...

2025-07-25
CVE-2025-41392
Analyzed
7.8
Intel Multiple Products

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12

2025-08-19
CVE-2025-41390
Analyzed
7.8
Unknown Multiple Products

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co

2025-10-20
CVE-2025-41368
8.1
HTTP Multiple Products

Problem in the Small HTTP Server v3

2026-03-28
CVE-2025-41359
7.8
HTTP Multiple Products

Vulnerability related to an unquoted service path in Small HTTP Server 3

2026-03-28
CVE-2025-41258
8
LibreChat Multiple Products

LibreChat version 0

2026-03-19
CVE-2025-41253
Analyzed
7.5
Cloud Multiple Products

The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties t...

2025-10-16
CVE-2025-41252
Analyzed
7.5
VMware Multiple Products

Description: VMware NSX contains a username enumeration vulnerability

2025-09-29
CVE-2025-41251
Analyzed
8.1
VMware Multiple Products

VMware NSX contains a weak password recovery mechanism vulnerability

2025-09-29
CVE-2025-41250
Analyzed
8.5
VMware Multiple Products

VMware vCenter contains an SMTP header injection vulnerability

2025-09-29
CVE-2025-41249
7.5
Spring Multiple Products

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized supe...

2025-09-16
CVE-2025-41248
7.5
Spring Multiple Products

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super...

2025-09-16
CVE-2025-41246
Analyzed
7.6
Microsoft Multiple Products

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls

2025-09-29
CVE-2025-41244
KEV Analyzed
7.8
VMware Multiple Products

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability

2025-09-29
CVE-2025-41243
Analyzed
10
Intel Multiple Products

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable whe...

2025-09-16
CVE-2025-41240
Analyzed
10
Kubernetes Multiple Products

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document ro...

2025-07-25
CVE-2025-41239
7.1
VMware Multiple Products

VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSo...

2025-07-15
CVE-2025-41238
Analyzed
9.3
VMware Multiple Products

VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bou...

2025-07-15
CVE-2025-41237
Analyzed
9.3
VMware Multiple Products

VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds wri...

2025-07-15
CVE-2025-41236
Analyzed
9.3
VMware Multiple Products

VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local ad...

2025-07-15
CVE-2025-41224
8.8
Unknown Multiple Products

A vulnerability has been identified in RUGGEDCOM RMC8388 V5

2025-07-10
CVE-2025-41118
Analyzed
9.1
Unknown Multiple Products

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS...

2026-04-16
CVE-2025-41115
Analyzed
10
Unknown Multiple Products

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by in...

2025-11-22
CVE-2025-41075
7.5
LimeSurvey Multiple Products

Vulnerability in LimeSurvey 6

2025-11-22
CVE-2025-41074
7.5
LimeSurvey Multiple Products

Vulnerability in LimeSurvey 6

2025-11-22
CVE-2025-41068
7.5
Reachable Assertion Multiple Products

Reachable Assertion vulnerability in Open5GS up to version 2

2025-10-28
CVE-2025-41067
7.5
Reachable Assertion Multiple Products

Reachable Assertion vulnerability in Open5GS up to version 2

2025-10-28
CVE-2025-41034
Analyzed
9.8
Unknown Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41033
Analyzed
9.8
Intel Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41032
Analyzed
9.8
Intel Multiple Products

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the...

2025-09-04
CVE-2025-41015
7.5
Unknown Multiple Products

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304

2025-12-03
CVE-2025-41014
7.5
Unknown Multiple Products

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304

2025-12-03
CVE-2025-41013
Analyzed
9.8
Unknown Multiple Products

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databa...

2025-12-04
CVE-2025-40949
Analyzed
9.1
Unknown Multiple Products

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX R...

2026-05-13
CVE-2025-40946
Analyzed
8.3
SUSE them to

A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6

2026-05-13
CVE-2025-40943
Analyzed
9.6
Unknown Multiple Products

Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering a legitimate...

2026-03-11
CVE-2025-40942
8.8
TeleControl Multiple Products

A vulnerability has been identified in TeleControl Server Basic (All versions < V3

2026-01-14
CVE-2025-40938
8.1
SIMATIC Multiple Products

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4

2025-12-10
CVE-2025-40937
8.3
SIMATIC Multiple Products

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4

2025-12-10
CVE-2025-40936
7.8
Unknown Multiple Products

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29

2025-11-18
CVE-2025-40933
7.5
Apache Multiple Products

Apache::AuthAny::Cookie v0

2025-09-17
CVE-2025-40932
8.2
Apache Multiple Products

Apache::SessionX versions through 2

2026-02-28
CVE-2025-40930
Analyzed
7.5
Unknown Multiple Products

JSON::SIMD before version 1

2025-09-08