21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 14701-14750 of 21553 CVEs Page 295 of 432
CVE-2025-60962
8.2
Time Multiple Products

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4

2025-10-06
CVE-2025-60960
8.2
Time Multiple Products

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4

2025-10-06
CVE-2025-60959
8.2
Time Multiple Products

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4

2025-10-06
CVE-2025-60958
7.3
Time Multiple Products

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4

2025-10-06
CVE-2025-60957
Analyzed
9.9
Unknown Multiple Products

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute...

2025-10-06
CVE-2025-60956
8
Time Multiple Products

Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4

2025-10-06
CVE-2025-60954
8.3
Microweber Multiple Products

Microweber CMS 2

2025-10-24
CVE-2025-60949
Analyzed
9.1
HP CSWeb

Census CSWeb 8.0.1 exposes the "app/config" directory via HTTP, allowing unauthenticated attackers to download configuration files and obtain sensitiv...

2026-03-24
CVE-2025-60947
8.8
Census Multiple Products

Census CSWeb 8

2026-03-24
CVE-2025-60946
8.8
Census Multiple Products

Census CSWeb 8

2026-03-24
CVE-2025-60938
7.5
Emoncms Multiple Products

Emoncms 11

2025-10-24
CVE-2025-60915
8.1
Unknown Multiple Products

An issue in the size query parameter (/views/file

2025-11-25
CVE-2025-6091
Analyzed
8.8
H3C GR-3000AX

A vulnerability was found in H3C GR-3000AX V100R007L50

2026-06-19
CVE-2025-6090
Analyzed
8.8
H3C GR-5400AX

A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical

2026-06-19
CVE-2025-60880
8.3
Unknown Multiple Products

An authenticated stored XSS vulnerability exists in the Bagisto 2

2025-10-10
CVE-2025-60869
7.3
Publii Multiple Products

Publii CMS v0

2025-10-10
CVE-2025-60865
Analyzed
7.8
Unknown Driver Updater

Insecure Permissions vulnerability in avanquest Driver Updater v

2026-02-05
CVE-2025-60858
7.5
Reolink Multiple Products

Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing...

2025-10-29
CVE-2025-60854
Analyzed
9.8
D-Link Multiple Products

A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in...

2025-12-04
CVE-2025-60835
Analyzed
7.8
IZArc IZArc

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

2026-08-01
CVE-2025-60805
7.5
Unknown Multiple Products

An issue was discovered in BESSystem BES Application Server thru 9

2025-10-29
CVE-2025-60803
Analyzed
9.8
Antabot Multiple Products

Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /api...

2025-10-24
CVE-2025-60801
Analyzed
8.2
Unknown Multiple Products

jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function

2025-10-24
CVE-2025-60800
7.5
Unknown Multiple Products

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a...

2025-10-29
CVE-2025-6080
Analyzed
8.8
WordPress Multiple Products

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and inclu...

2025-08-17
CVE-2025-6079
Analyzed
8.8
WordPress Multiple Products

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hom...

2025-08-17
CVE-2025-60787
7.2
MotionEye Multiple Products

MotionEye v0

2025-10-03
CVE-2025-60786
Analyzed
8.8
HP Multiple Products

A Zip Slip vulnerability in the import a Project component of iceScrum v7

2025-12-16
CVE-2025-60785
Analyzed
8.8
Intel Multiple Products

A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7

2025-11-04
CVE-2025-60772
Analyzed
9.8
Unknown Multiple Products

Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate p...

2025-10-22
CVE-2025-60751
7.5
GeographicLib Multiple Products

GeographicLib 2

2025-10-21
CVE-2025-60749
7.8
Trimble SketchUp Multiple Products

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef

2025-10-31
CVE-2025-60739
Analyzed
9.6
Unknown Multiple Products

Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 a...

2025-11-26
CVE-2025-60738
7.5
Unknown Multiple Products

An issue in Ilevia EVE X1 Server Firmware Version v4

2025-11-20
CVE-2025-60736
Analyzed
9.8
HP Multiple Products

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

2025-12-04
CVE-2025-60735
7.6
PerfreeBlog Multiple Products

PerfreeBlog v4

2025-10-24
CVE-2025-60731
7.6
PerfreeBlog Multiple Products

PerfreeBlog v4

2025-10-24
CVE-2025-60730
7.6
PerfreeBlog Multiple Products

PerfreeBlog v4

2025-10-24
CVE-2025-6073
7.5
Unknown Multiple Products

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE

2025-07-06
CVE-2025-60727
7.8
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-60721
7.8
Microsoft Multiple Products

Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60720
7.8
Microsoft Multiple Products

Buffer over-read in Windows TDX

2025-11-13
CVE-2025-6072
7.5
Unknown Multiple Products

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE

2025-07-06
CVE-2025-60718
7.8
Microsoft Multiple Products

Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60715
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-11-13
CVE-2025-60714
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-60713
Analyzed
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60710
KEV
7.8
Microsoft Multiple Products

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges l...

2025-11-13
CVE-2025-60709
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60707
7.8
Unknown Multiple Products

Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally

2025-11-13