18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 14401-14450 of 18466 CVEs Page 289 of 370
CVE-2025-40691
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-40690
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-40689
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-40687
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-40602
KEV
9.5
SonicWall SMA1000 appliance

SonicWall SMA1000 Missing Authorization Vulnerability - Active in CISA KEV catalog.

2025-12-18
CVE-2025-40601
Analyzed
7.5
SonicWall Multiple Products

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), w...

2025-11-20
CVE-2025-40600
Analyzed
9.8
Unknown Multiple Products

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service di...

2025-07-30
CVE-2025-40599
Analyzed
9.1
Unknown Multiple Products

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative priv...

2025-07-23
CVE-2025-40597
Analyzed
7.5
Unknown Multiple Products

A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS)...

2025-07-23
CVE-2025-40596
7.3
Unknown Multiple Products

A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS...

2025-07-23
CVE-2025-40587
7.6
Unknown Multiple Products

A vulnerability has been identified in Polarion V2404 (All versions < V2404

2026-02-11
CVE-2025-40554
Analyzed
9.8
Unknown Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke s...

2026-01-28
CVE-2025-40553
Analyzed
9.8
Unknown Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic...

2026-01-28
CVE-2025-40552
Analyzed
9.8
Unknown Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to exe...

2026-01-28
CVE-2025-40551
KEV Analyzed
9.8
Unknown Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic...

2026-01-28
CVE-2025-40549
Analyzed
9.1
Microsoft Multiple Products

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to...

2025-11-19
CVE-2025-40548
Analyzed
9.1
Microsoft Multiple Products

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code....

2025-11-19
CVE-2025-40547
Analyzed
9.1
Microsoft Multiple Products

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute cod...

2025-11-19
CVE-2025-40541
Analyzed
9.1
SolarWinds Serv-U

An Insecure Direct Object Reference (IDOR) vulnerability in Serv-U allows authenticated administrators to execute native code as a privileged account...

2026-02-24
CVE-2025-40540
Analyzed
9.1
SolarWinds Serv-U

A critical type confusion vulnerability in Serv-U allows an authenticated administrative user to execute arbitrary native code, potentially compromisi...

2026-02-24
CVE-2025-40539
Analyzed
9.1
SolarWinds Serv-U

A type confusion vulnerability in Serv-U enables authenticated administrative users to execute arbitrary native code with the privileges of the servic...

2026-02-24
CVE-2025-40538
Analyzed
9.1
SolarWinds Serv-U

A broken access control vulnerability in Serv-U allows domain or group administrators to escalate privileges, create system admin users, and execute a...

2026-02-24
CVE-2025-40537
7.5
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to ad...

2026-01-28
CVE-2025-40536
KEV
8.1
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated atta...

2026-01-28
CVE-2025-4046
Analyzed
8.5
Intel Multiple Products

A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization

2025-08-19
CVE-2025-4044
Analyzed
8.2
Microsoft Multiple Products

Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information...

2025-08-19
CVE-2025-4008
KEV
9.5
Smartbedded Meteobridge

Smartbedded Meteobridge Command Injection Vulnerability - Active in CISA KEV catalog.

2025-10-02
CVE-2025-39510
8.5
ValvePress Pinterest Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin allows SQL In...

2025-08-14
CVE-2025-39496
Analyzed
9.3
WordPress Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Injec...

2025-08-28
CVE-2025-39484
Analyzed
9.3
Intel Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue a...

2026-01-06
CVE-2025-39477
Analyzed
9.8
Unknown Multiple Products

Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff...

2026-01-07
CVE-2025-3947
8.2
Unknown Multiple Products

The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA)

2025-07-11
CVE-2025-3946
8.2
Unknown Multiple Products

The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Control Data Access (CDA...

2025-07-11
CVE-2025-39247
Analyzed
8.6
Unknown Multiple Products

There is an Access Control Vulnerability in some HikCentral Professional versions

2025-08-29
CVE-2025-38747
7.8
Dell Multiple Products

Dell SupportAssist OS Recovery, versions prior to 5

2025-08-07
CVE-2025-38743
Analyzed
7.8
Dell Multiple Products

Dell iDRAC Service Module (iSM), versions prior to 6

2025-08-21
CVE-2025-38741
Analyzed
7.5
Dell Multiple Products

Dell Enterprise SONiC OS, version 4

2025-08-05
CVE-2025-38739
Analyzed
7.2
Dell Multiple Products

Dell Digital Delivery, versions prior to 5

2025-08-05
CVE-2025-3848
Analyzed
8.8
WordPress Multiple Products

The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to privilege escalation via account takeover i...

2025-07-05
CVE-2025-3839
8
Unknown Multiple Products

A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction

2026-01-23
CVE-2025-38352
KEV
9.5
Linux Kernel

Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability - Active in CISA KEV catalog.

2025-09-04
CVE-2025-3831
8.1
Log Multiple Products

Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties

2025-08-12
CVE-2025-38250
Analyzed
7.8
Linux Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix use-after-free in vhci_flush() syzbot reported use-afte...

2026-06-21
CVE-2025-38129
Analyzed
7.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix use-after-free in page_pool_recycle_in_ring syzbot reported a uaf...

2026-06-21
CVE-2025-37736
Analyzed
8.8
Unknown Multiple Products

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be...

2025-11-08
CVE-2025-37735
Analyzed
7
Microsoft Multiple Products

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service...

2025-11-06
CVE-2025-37729
Analyzed
9.1
Unknown Multiple Products

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin acces...

2025-10-13
CVE-2025-3770
Analyzed
7
Unknown Multiple Products

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access

2025-08-07
CVE-2025-3753
7.8
Unknown Multiple Products

A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and...

2025-07-17
CVE-2025-3719
8.1
Unknown Multiple Products

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users wit...

2025-10-07