18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 15001-15050 of 18466 CVEs Page 301 of 370
CVE-2025-25009
8.7
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload

2025-10-07
CVE-2025-24999
8.8
Unknown Multiple Products

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network

2025-08-12
CVE-2025-24990
KEV Analyzed
7.8
Microsoft Multiple Products

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems

2025-10-14
CVE-2025-24975
7.1
Unknown Multiple Products

Firebird is a relational database

2025-08-17
CVE-2025-24893
KEV
9.5
XWiki Platform

XWiki Platform Eval Injection Vulnerability - Active in CISA KEV catalog.

2025-10-30
CVE-2025-24857
7.6
Unknown Multiple Products

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017

2025-12-11
CVE-2025-24853
Analyzed
7.5
Intel Multiple Products

A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the vi...

2025-07-31
CVE-2025-24838
8.8
Intel Multiple Products

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2

2025-11-13
CVE-2025-24818
8
Arch application

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in L...

2026-04-08
CVE-2025-24817
8
Nokia Multiple Products

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in S...

2026-04-09
CVE-2025-24815
Analyzed
7.8
Nokia MantaRay NM

Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation

2026-07-01
CVE-2025-24780
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designe...

2025-07-06
CVE-2025-24779
8.8
Deserialization Multiple Products

Deserialization of Untrusted Data vulnerability in NooTheme Yogi allows Object Injection

2025-07-16
CVE-2025-24777
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection

2025-07-16
CVE-2025-24775
Analyzed
9.9
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms allows Upload a Web Shell to a Web Server. This issue affects Forms:...

2025-08-14
CVE-2025-24766
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Royal Themes News Magazine...

2025-08-14
CVE-2025-24759
Analyzed
9.3
WordPress Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugins...

2025-07-16
CVE-2025-24748
8.5
LambertGroup Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup All In One Slider Responsive allows...

2025-07-05
CVE-2025-24528
7.1
MIT Multiple Products

In MIT Kerberos 5 (aka krb5) before 1

2026-01-18
CVE-2025-24525
Analyzed
7.5
Keysight Multiple Products

Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the dev...

2025-10-01
CVE-2025-24496
7.5
Tenda Multiple Products

An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5

2025-08-20
CVE-2025-24486
7.8
Intel Multiple Products

Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2

2025-08-12
CVE-2025-24484
7.8
Intel Multiple Products

Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1

2025-08-12
CVE-2025-24404
8.8
Apache Multiple Products

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat

2025-09-10
CVE-2025-24325
8.8
Intel Multiple Products

Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1

2025-08-12
CVE-2025-24322
8.1
Tenda Multiple Products

An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5

2025-08-20
CVE-2025-24303
7.8
Intel Multiple Products

Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1

2025-08-12
CVE-2025-24299
8.8
Intel Multiple Products

Improper input validation for some Intel(R) CIP software before version WIN_DCA_2

2025-11-13
CVE-2025-24298
8.4
OpenHarmony Multiple Products

in OpenHarmony v5

2025-08-11
CVE-2025-24290
9.9
Unknown Multiple Products

Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor with low pr...

2025-07-06
CVE-2025-24289
7.5
Unknown Multiple Products

A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1

2025-07-06
CVE-2025-24285
Analyzed
9.8
Unknown Multiple Products

Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network ac...

2025-08-21
CVE-2025-24284
Analyzed
8.8
Apple macOS

This issue was addressed with improved checks to prevent unauthorized actions

2026-06-12
CVE-2025-24224
7.5
Unknown Multiple Products

The issue was addressed with improved checks

2025-07-30
CVE-2025-2417
Analyzed
8.6
Unknown Multiple Products

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication Bypass

2025-09-04
CVE-2025-2416
Analyzed
8.6
Akinsoft LimonDesk Multiple Products

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypass

2025-09-03
CVE-2025-2415
Analyzed
8.6
Akinsoft MyRezzta Multiple Products

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass

2025-09-03
CVE-2025-2414
8.6
Akinsoft OctoCloud Multiple Products

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypass

2025-09-02
CVE-2025-2413
8.6
Akinsoft ProKuafor Multiple Products

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypass

2025-09-02
CVE-2025-2412
Analyzed
8.6
Akinsoft QR Menu Multiple Products

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass

2025-09-02
CVE-2025-24119
7.8
Unknown Multiple Products

This issue was addressed through improved state management

2025-07-30
CVE-2025-2411
Analyzed
8.6
Akinsoft TaskPano Multiple Products

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass

2025-09-04
CVE-2025-24088
7.5
Unknown Multiple Products

The issue was addressed by adding additional logic

2025-09-16
CVE-2025-2406
Analyzed
7.6
Verisay Communication Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Tec...

2025-12-26
CVE-2025-24052
7.8
Microsoft Multiple Products

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems

2025-10-14
CVE-2025-2405
Analyzed
7.6
Verisay Communication Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Tec...

2025-12-26
CVE-2025-24006
7.8
Unknown Multiple Products

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root

2025-07-10
CVE-2025-24005
7.8
Unknown Multiple Products

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation

2025-07-10
CVE-2025-24003
8.2
Unknown Multiple Products

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, r...

2025-07-08
CVE-2025-24000
Analyzed
8.8
Unknown Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in WPExperts Post SMTP allows Authentication Bypass

2025-08-07