18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 14701-14750 of 18466 CVEs Page 295 of 370
CVE-2025-32300
7.1
Zoom Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Ref...

2026-01-08
CVE-2025-32297
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory allows SQL In...

2025-07-06
CVE-2025-32288
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensio...

2025-08-14
CVE-2025-32283
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection

2025-10-23
CVE-2025-32096
7.5
Pexip Multiple Products

Pexip Infinity 33

2025-12-26
CVE-2025-32095
7.5
Infinity Multiple Products

Pexip Infinity before 37

2025-12-26
CVE-2025-32091
8.2
Intel Multiple Products

Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privile...

2025-11-13
CVE-2025-32089
Analyzed
8.8
Dell Multiple Products

A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5

2025-11-18
CVE-2025-32062
Analyzed
8.8
Bosch Infotainment ECU (Alps Alpine Bluetooth stack)

The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch

2026-02-16
CVE-2025-32061
Analyzed
8.8
Bosch Infotainment ECU (Alps Alpine Bluetooth stack)

The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch

2026-02-16
CVE-2025-32059
Analyzed
8.8
Bosch Infotainment ECU (Alps Alpine Bluetooth stack)

The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch

2026-02-16
CVE-2025-32058
Analyzed
9.3
Bosch uses

A vulnerability in the Bosch Infotainment ECU's custom protocol allows an attacker with SoC code execution to execute code on the RH850 module and sen...

2026-02-16
CVE-2025-32010
8.1
Tenda Multiple Products

A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5

2025-08-20
CVE-2025-32008
Analyzed
8.6
Intel AMT and Standard Manageability

Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of se...

2026-02-11
CVE-2025-31965
Analyzed
8.2
Control Multiple Products

Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10

2025-07-29
CVE-2025-31955
7.6
HCL Multiple Products

HCL iAutomate is affected by a sensitive data exposure vulnerability

2025-07-25
CVE-2025-31953
7.1
HCL Multiple Products

HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized pa...

2025-07-25
CVE-2025-31952
7.1
HCL Multiple Products

HCL iAutomate is affected by an insufficient session expiration

2025-07-25
CVE-2025-31951
Analyzed
8.8
HCL BigFix RunBookAI

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability

2026-05-06
CVE-2025-31718
Analyzed
9.8
Unknown Multiple Products

In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of privilege with no additional exec...

2025-10-12
CVE-2025-31717
Analyzed
9.8
Unknown Multiple Products

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution...

2025-10-12
CVE-2025-31715
Analyzed
9.8
Unknown Multiple Products

In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no a...

2025-08-18
CVE-2025-31713
Analyzed
8.4
Unknown Multiple Products

In engineer mode service, there is a possible command injection due to improper input validation

2025-08-18
CVE-2025-31701
8.1
Unknown Multiple Products

A vulnerability has been found in Dahua products

2025-07-23
CVE-2025-31700
8.1
Unknown Multiple Products

A vulnerability has been found in Dahua products

2025-07-23
CVE-2025-31649
Analyzed
8.7
Dell Multiple Products

A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5

2025-11-18
CVE-2025-31643
8.8
Dasinfomedia WPCHURCH Multiple Products

Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation

2026-01-08
CVE-2025-31642
7.1
Dasinfomedia WPCHURCH Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHURCH allows Reflected XSS

2026-01-07
CVE-2025-31634
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection

2025-10-23
CVE-2025-31512
7.3
AlertEnterprise Multiple Products

An issue was discovered in AlertEnterprise Guardian 4

2025-07-23
CVE-2025-31511
7.3
AlertEnterprise Multiple Products

An issue was discovered in AlertEnterprise Guardian 4

2025-07-23
CVE-2025-31510
7.2
Unknown Multiple Products

In the portal in LemonLDAP::NG before 2

2026-01-18
CVE-2025-31427
Analyzed
7.1
WordPress Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Invico - WordPress Consulting Busin...

2025-07-16
CVE-2025-31425
7.5
Unknown Multiple Products

Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages allows Exploiting Incorrectly Configured Access Control Security Levels

2025-08-14
CVE-2025-31422
Analyzed
8.8
WordPress Multiple Products

Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme allows Object Injection

2025-07-16
CVE-2025-31361
Analyzed
8.7
Dell Multiple Products

A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5

2025-11-18
CVE-2025-31355
7.2
Tenda Multiple Products

A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5

2025-08-20
CVE-2025-31281
Analyzed
9.1
Apple Multiple Products

An input validation issue was addressed with improved memory handling. This issue is fixed in visionOS 2.6, tvOS 18.6, macOS Sequoia 15.6, iOS 18.6 an...

2025-07-31
CVE-2025-31280
7.8
Unknown Multiple Products

A memory corruption issue was addressed with improved validation

2025-07-31
CVE-2025-3128
Analyzed
9.8
Unknown Multiple Products

A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete in...

2025-08-21
CVE-2025-31279
Analyzed
9.8
Apple Multiple Products

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, iPadOS 17.7.9, macOS Sonoma 14.7.7, macOS V...

2025-07-31
CVE-2025-31278
8.8
Unknown Multiple Products

The issue was addressed with improved memory handling

2025-07-31
CVE-2025-31277
KEV
8.8
Unknown Multiple Products

The issue was addressed with improved memory handling

2025-07-31
CVE-2025-31273
8.8
Unknown Multiple Products

The issue was addressed with improved memory handling

2025-07-31
CVE-2025-31271
7.5
Unknown Multiple Products

This issue was addressed through improved state management

2025-09-16
CVE-2025-31243
7.8
Unknown Multiple Products

A permissions issue was addressed with additional restrictions

2025-07-31
CVE-2025-31229
Analyzed
9.1
Apple Multiple Products

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver.

2025-07-31
CVE-2025-31125
KEV
9.5
Vite Vitejs

Vite Vitejs Improper Access Control Vulnerability - Active in CISA KEV catalog.

2026-01-23
CVE-2025-31072
Analyzed
7.1
WordPress Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Ofiz - WordPress Business Consultin...

2025-07-16
CVE-2025-31070
7.5
LambertGroup Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builde...

2025-07-16