23478 Total CVEs
23383 AI Analyzed
328 CISA KEV
5343 Critical
All Vendors
Showing 18801-18850 of 23478 CVEs Page 377 of 470
CVE-2025-47998
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-47987
Analyzed
7.8
Microsoft Windows 10 Version 1507

Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47986
Analyzed
8.8
Microsoft Windows 10 Version 1507

Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally

2025-07-08
CVE-2025-47985
Analyzed
7.8
Microsoft Windows 10 Version 1507

Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47982
Analyzed
7.8
Microsoft Windows 10 Version 1607

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47981
Analyzed
9.8
Microsoft Windows 10 Version 1507

Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

2025-07-08
CVE-2025-47976
Analyzed
7.8
Microsoft Windows 10 Version 1507

Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47973
Analyzed
7.8
Microsoft Windows 10 Version 1507

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47972
Analyzed
8
Microsoft Windows 10 Version 1507

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorize...

2025-07-10
CVE-2025-47971
Analyzed
7.8
Microsoft Windows 10 Version 1507

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally

2025-07-10
CVE-2025-4796
Analyzed
8.8
Arraytics

The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4

2025-08-08
CVE-2025-47954
Analyzed
8.8
Microsoft Microsoft SQL Server 2022 (CU 20)

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12
CVE-2025-47932
Analyzed
8.8
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-47917
Analyzed
8.9
Mbed mbedtls

Mbed TLS before 3

2025-07-21
CVE-2025-47913
Analyzed
7.5
golang.org/x/crypto golang.org/x/crypto/ssh/agent

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process

2025-11-14
CVE-2025-47909
Analyzed
7.3
github.com/gorilla/csrf github.com/gorilla/csrf

Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks

2025-08-29
CVE-2025-47908
Analyzed
7.5
github.com/rs/cors github.com/rs/cors

Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers...

2025-08-07
CVE-2025-47907
Analyzed
7
Go standard library database/sql

Cancelling a query (e

2025-08-07
CVE-2025-47855
Analyzed
9.8
Fortinet FortiFone

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 thro...

2026-01-14
CVE-2025-4784
Analyzed
9.8
Moderec Tourtella

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This issu...

2025-07-25
CVE-2025-47827
KEV Analyzed
9.5
IGEL IGEL OS

IGEL OS Use of a Key Past its Expiration Date Vulnerability - Active in CISA KEV catalog.

2025-10-14
CVE-2025-47813
KEV Analyzed
9.5
wftpserver Wing FTP Server

Wing FTP Server Information Disclosure Vulnerability - Active in CISA KEV catalog.

2026-03-17
CVE-2025-47812
KEV Analyzed
10
wftpserver Wing FTP Server

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user...

2025-07-11
CVE-2025-4779
Analyzed
9.1
lunary-ai lunary-ai/lunary

lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attacker can inject malicious JavaSc...

2025-07-07
CVE-2025-47773
Analyzed
8.8
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-47761
Analyzed
7.8
Fortinet FortiClientWindows

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] in Fortinet FortiClientWindows 7

2025-11-19
CVE-2025-47699
Analyzed
9.9
Gallagher Command Centre Server

Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated...

2025-10-23
CVE-2025-47698
Analyzed
8
Cognex In-Sight 2000 series

An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials

2025-09-18
CVE-2025-47652
Analyzed
7.1
infility Infility Global

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global allows Reflected XSS

2025-07-16
CVE-2025-47645
Analyzed
8.5
ELEXtensions

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit...

2025-07-16
CVE-2025-4764
Analyzed
8
Aida Computer Information Technology Hotel Guest Hotspot

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc

2026-01-23
CVE-2025-47627
Analyzed
7.5
LCweb PrivateContent - Mail Actions

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail A...

2025-07-06
CVE-2025-47579
Analyzed
9
ThemeGoods Photography

Deserialization of Untrusted Data vulnerability in ThemeGoods Photography. This issue affects Photography: from n/a through 7.5.2.

2025-09-09
CVE-2025-47571
Analyzed
7.5
highwarden Super Store Finder

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder

2025-09-09
CVE-2025-47569
Analyzed
9.3
wpswings WooCommerce Ultimate Gift Card

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card - Create...

2025-09-09
CVE-2025-47566
Analyzed
7.1
ZoomSounds ZoomSounds

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows Reflected XSS

2026-01-01
CVE-2025-47554
Analyzed
7.1
QuanticaLabs CSS3 Compare Pricing Tables for WordPress

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for Wor...

2025-07-16
CVE-2025-47553
Analyzed
8.8
Digital zoom studio DZS Video Gallery

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection

2026-01-07
CVE-2025-47552
Analyzed
9.8
Digital zoom studio DZS Video Gallery

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery:...

2026-01-08
CVE-2025-47408
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption when another driver calls an IOCTL with invalid input/output buffer

2026-05-05
CVE-2025-47407
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level

2026-05-05
CVE-2025-47405
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption when processing camera sensor input/output control codes with invalid output buffers

2026-05-05
CVE-2025-47399
Analyzed
7.8
Qualcomm Snapdragon

Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters

2026-02-03
CVE-2025-47398
Analyzed
7.8
Qualcomm Snapdragon

Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers

2026-02-03
CVE-2025-47397
Analyzed
7.8
Qualcomm Snapdragon

Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors

2026-02-03
CVE-2025-47396
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption occurs when a secure application is launched on a device with insufficient memory

2026-01-08
CVE-2025-47394
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations

2026-01-08
CVE-2025-47393
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption when accessing resources in kernel driver

2026-01-08
CVE-2025-47392
Analyzed
8.8
Qualcomm Snapdragon

Memory corruption when decoding corrupted satellite data files with invalid signature offsets

2026-04-07
CVE-2025-47391
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while processing a frame request from user

2026-04-07