8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1851-1900 of 8341 CVEs Page 38 of 167
CVE-2025-66533
7.8
StellarWP GiveWP give Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection

2025-12-10
CVE-2025-66506
7.5
Unknown Multiple Products

Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity

2025-12-05
CVE-2025-66499
Analyzed
7.8
Unknown Multiple Products

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data

2025-12-20
CVE-2025-66495
Analyzed
7.8
Microsoft Multiple Products

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025

2025-12-20
CVE-2025-66494
Analyzed
7.8
Reader Multiple Products

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025

2025-12-20
CVE-2025-66493
Analyzed
7.8
Editor Multiple Products

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025

2025-12-20
CVE-2025-66492
8.2
Masa Multiple Products

Masa CMS is an open source Enterprise Content Management platform

2025-12-13
CVE-2025-66481
Analyzed
9.6
Intel Multiple Products

DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improp...

2025-12-10
CVE-2025-66480
Analyzed
9.8
Intel Multiple Products

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component rel...

2026-02-03
CVE-2025-66476
7.8
Vim Multiple Products

Vim is an open source, command line text editor

2025-12-03
CVE-2025-66468
7.6
Aimeos Multiple Products

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components

2025-12-03
CVE-2025-66449
Analyzed
8.8
ConvertXis Multiple Products

ConvertXis a self-hosted online file converter

2025-12-16
CVE-2025-66448
7.1
Unknown Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2025-12-02
CVE-2025-66446
8.8
MaxKB Multiple Products

MaxKB is an open-source AI assistant for enterprise

2025-12-12
CVE-2025-66444
8.2
Hitachi Multiple Products

Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hita...

2025-12-24
CVE-2025-66443
7.5
Pexip Multiple Products

Pexip Infinity 35

2025-12-26
CVE-2025-66437
8.8
ERPNext Multiple Products

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15

2025-12-17
CVE-2025-66431
7.8
Plesk Multiple Products

WebPros Plesk before 18

2025-12-03
CVE-2025-66430
Analyzed
9.1
Apache Multiple Products

Plesk 18.0 has Incorrect Access Control.

2025-12-13
CVE-2025-66429
8.8
Unknown Multiple Products

An issue was discovered in cPanel 110 through 132

2025-12-13
CVE-2025-66428
Analyzed
8.8
WordPress Multiple Products

An issue with WordPress directory names in WebPros WordPress Toolkit before 6

2026-01-24
CVE-2025-66423
Analyzed
7.1
Intel Multiple Products

Tryton trytond 6

2025-12-01
CVE-2025-66419
8.8
MaxKB Multiple Products

MaxKB is an open-source AI assistant for enterprise

2025-12-12
CVE-2025-66417
7.5
GLPI Multiple Products

GLPI is a free asset and IT management software package

2026-01-16
CVE-2025-66411
7.8
Coder Multiple Products

Coder allows organizations to provision remote development environments via Terraform

2025-12-03
CVE-2025-66401
Analyzed
9.8
GitHub Multiple Products

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical...

2025-12-02
CVE-2025-66398
Analyzed
9.6
Unknown Multiple Products

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the int...

2026-01-02
CVE-2025-66397
8.3
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-18
CVE-2025-66396
7.2
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-18
CVE-2025-66395
8.8
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-18
CVE-2025-66384
Analyzed
8.2
Apache Multiple Products

app/Controller/EventsController

2025-11-29
CVE-2025-66379
7.5
Infinity Multiple Products

Pexip Infinity before 39

2025-12-26
CVE-2025-66377
7.5
Infinity Multiple Products

Pexip Infinity before 39

2025-12-26
CVE-2025-66376
7.2
Zimbra Multiple Products

Zimbra Collaboration (ZCS) 10 before 10

2026-01-06
CVE-2025-6637
7.8
Unknown Multiple Products

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability

2025-07-29
CVE-2025-6636
7.8
Unknown Multiple Products

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability

2025-07-29
CVE-2025-66359
Analyzed
8.5
Logpoint Multiple Products

An issue was discovered in Logpoint before 7

2025-11-28
CVE-2025-6635
7.8
Unknown Multiple Products

A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability

2025-07-29
CVE-2025-6634
7.8
Unknown Multiple Products

A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability

2025-08-07
CVE-2025-6633
8.3
Unknown Multiple Products

A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability

2025-08-07
CVE-2025-66328
8.4
Unknown Multiple Products

Multi-thread race condition vulnerability in the network management module

2025-12-09
CVE-2025-66327
7.1
Unknown Multiple Products

Race condition vulnerability in the network module

2025-12-09
CVE-2025-66324
8.4
Unknown Multiple Products

Input verification vulnerability in the compression and decompression module

2025-12-09
CVE-2025-66314
Analyzed
7.5
Linux Multiple Products

Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs

2025-11-28
CVE-2025-6631
7.8
Unknown Multiple Products

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability

2025-07-29
CVE-2025-66300
8.5
Grav Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-66299
Analyzed
8.8
HP Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-66296
Analyzed
8.8
Apache Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-66295
Analyzed
8.8
Grav Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-66293
7.1
LIBPNG Multiple Products

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files

2025-12-03