8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1901-1950 of 8341 CVEs Page 39 of 167
CVE-2025-66292
8.1
Unknown Multiple Products

DPanel is an open source server management panel written in Go

2026-01-16
CVE-2025-66287
8.8
Unknown Multiple Products

A flaw was found in WebKitGTK

2025-12-05
CVE-2025-6625
Analyzed
7.5
Unknown Multiple Products

CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device

2025-08-19
CVE-2025-66238
7.2
Unknown Multiple Products

DCIM dcTrack allows an attacker to misuse certain remote access features

2025-12-05
CVE-2025-66222
Analyzed
9.6
Intel Multiple Products

DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Me...

2025-12-03
CVE-2025-66205
Analyzed
7.1
Frappe Multiple Products

Frappe is a full-stack web application framework

2025-12-02
CVE-2025-66203
Analyzed
9.9
Unknown Multiple Products

StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault...

2025-12-27
CVE-2025-66177
Analyzed
8.8
Hikvision Multiple Products

There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models

2026-01-13
CVE-2025-66176
Analyzed
8.8
Hikvision Multiple Products

There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products

2026-01-13
CVE-2025-66131
Analyzed
9.1
HP Multiple Products

Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc allows Exploiting Incorrectly Con...

2025-12-17
CVE-2025-66078
Analyzed
9.1
WordPress Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote C...

2025-12-19
CVE-2025-66055
7.2
Icegram Email Multiple Products

Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection

2025-11-22
CVE-2025-66048
Analyzed
9.8
Several Multiple Products

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafte...

2025-12-12
CVE-2025-66047
Analyzed
9.8
Several Multiple Products

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafte...

2025-12-12
CVE-2025-66046
Analyzed
9.8
Several Multiple Products

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafte...

2025-12-12
CVE-2025-66045
Analyzed
9.8
Several Multiple Products

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafte...

2025-12-12
CVE-2025-66044
Analyzed
9.8
Several Multiple Products

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafte...

2025-12-12
CVE-2025-66043
Analyzed
9.8
Several Multiple Products

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafte...

2025-12-12
CVE-2025-66029
Analyzed
7.6
HP Multiple Products

Open OnDemand provides remote web access to supercomputers

2025-12-18
CVE-2025-66022
Analyzed
9.6
Unknown Multiple Products

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fram...

2025-11-27
CVE-2025-66020
Analyzed
7.5
Valibot Multiple Products

Valibot helps validate data using a schema

2025-11-27
CVE-2025-66001
8.8
NeuVector Multiple Products

NeuVector supports login authentication through OpenID Connect

2026-01-09
CVE-2025-65998
Analyzed
7.5
Apache Multiple Products

Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option

2025-11-25
CVE-2025-65959
8.7
Intel Multiple Products

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2025-12-05
CVE-2025-65958
8.5
Intel Multiple Products

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2025-12-05
CVE-2025-65951
Analyzed
8.7
Unknown Multiple Products

Inside Track / Entropy Derby is a research-grade horse-racing betting engine

2025-11-26
CVE-2025-65946
8.1
Roo Multiple Products

Roo Code is an AI-powered autonomous coding agent that lives in users' editors

2025-11-22
CVE-2025-65945
7.5
Unknown Multiple Products

auth0/node-jws is a JSON Web Signature implementation for Node

2025-12-05
CVE-2025-65897
8.8
Unknown Multiple Products

zdh_web is a data collection, processing, monitoring, scheduling, and management platform

2025-12-06
CVE-2025-65896
9.8
Unknown Multiple Products

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

2025-12-04
CVE-2025-65891
7.5
GPU Multiple Products

A GPU device-ID validation flaw in OneFlow v0

2026-01-30
CVE-2025-65890
7.5
Unknown Multiple Products

A device-ID validation flaw in OneFlow v0

2026-01-30
CVE-2025-65889
7.5
Unknown Multiple Products

A type validation flaw in the flow

2026-01-30
CVE-2025-65888
7.5
Unknown Multiple Products

A dimension validation flaw in the flow

2026-01-30
CVE-2025-65886
7.5
Unknown Multiple Products

A shape mismatch vulnerability in OneFlow v0

2026-01-30
CVE-2025-65879
8.1
Unknown Multiple Products

Warehouse Management System 1

2025-12-06
CVE-2025-65878
7.5
Unknown Multiple Products

The warehouse management system version 1

2025-12-06
CVE-2025-65875
8.8
HP file

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1

2026-02-04
CVE-2025-65865
7.5
Unknown Multiple Products

An integer overflow in eProsima Fast-DDS v3

2025-12-24
CVE-2025-65857
7.5
Unknown Multiple Products

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5

2025-12-23
CVE-2025-65856
Analyzed
9.8
Unknown Multiple Products

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remo...

2025-12-23
CVE-2025-65854
Analyzed
9.8
Unknown Multiple Products

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeov...

2025-12-13
CVE-2025-6585
8.1
WordPress Multiple Products

The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7

2025-07-23
CVE-2025-65844
7.5
EverShop Multiple Products

EverShop 2

2025-12-03
CVE-2025-65843
7.7
Aquarius Multiple Products

Aquarius Desktop 3

2025-12-03
CVE-2025-65831
7.5
Unknown Multiple Products

The application uses an insecure hashing algorithm (MD5) to hash passwords

2025-12-12
CVE-2025-65824
8.8
Unknown Multiple Products

An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Lo...

2025-12-12
CVE-2025-65821
Analyzed
7.5
Intel Multiple Products

As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sens...

2025-12-12
CVE-2025-65817
Analyzed
8.8
LSC Multiple Products

LSC Smart Connect Indoor IP Camera 1

2025-12-23
CVE-2025-65807
Analyzed
9.8
Unknown Multiple Products

An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.

2025-12-11